2025-10-14T07:57:04Z INFO This program will set up FreeIPA client. 2025-10-14T07:57:04Z INFO Version 4.10.1 2025-10-14T07:57:04Z INFO 2025-10-14T07:57:04Z DEBUG Starting external process 2025-10-14T07:57:04Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:04Z DEBUG Process finished, return code=0 2025-10-14T07:57:04Z DEBUG stdout= 2025-10-14T07:57:04Z DEBUG stderr= 2025-10-14T07:57:04Z DEBUG Starting external process 2025-10-14T07:57:04Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2025-10-14T07:57:04Z DEBUG Process finished, return code=1 2025-10-14T07:57:04Z DEBUG stdout= 2025-10-14T07:57:04Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2025-10-14T07:57:04Z DEBUG Starting external process 2025-10-14T07:57:04Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2025-10-14T07:57:04Z DEBUG Process finished, return code=3 2025-10-14T07:57:04Z DEBUG stdout=inactive 2025-10-14T07:57:04Z DEBUG stderr= 2025-10-14T07:57:04Z DEBUG Starting external process 2025-10-14T07:57:04Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2025-10-14T07:57:04Z DEBUG Process finished, return code=1 2025-10-14T07:57:04Z DEBUG stdout= 2025-10-14T07:57:04Z DEBUG stderr=Failed to get unit file state for systemd-timesyncd.service: No such file or directory 2025-10-14T07:57:04Z DEBUG Starting external process 2025-10-14T07:57:04Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2025-10-14T07:57:04Z DEBUG Process finished, return code=3 2025-10-14T07:57:04Z DEBUG stdout=inactive 2025-10-14T07:57:04Z DEBUG stderr= 2025-10-14T07:57:04Z DEBUG Deleting invalid keytab: '/etc/krb5.keytab'. 2025-10-14T07:57:04Z DEBUG [IPA Discovery] 2025-10-14T07:57:04Z DEBUG Starting IPA discovery with domain=ooo.test, servers=['ipa.ooo.test'], hostname=np0005486751.ooo.test 2025-10-14T07:57:04Z DEBUG Server and domain forced 2025-10-14T07:57:04Z DEBUG [Kerberos realm search] 2025-10-14T07:57:04Z DEBUG Search DNS for TXT record of _kerberos.ooo.test 2025-10-14T07:57:04Z DEBUG DNS record found: "OOO.TEST" 2025-10-14T07:57:04Z DEBUG [LDAP server check] 2025-10-14T07:57:04Z DEBUG Verifying that ipa.ooo.test (realm OOO.TEST) is an IPA server 2025-10-14T07:57:04Z DEBUG Init LDAP connection to: ldap://ipa.ooo.test:389 2025-10-14T07:57:04Z DEBUG Search LDAP server for IPA base DN 2025-10-14T07:57:04Z DEBUG Check if naming context 'dc=ooo,dc=test' is for IPA 2025-10-14T07:57:04Z DEBUG Naming context 'dc=ooo,dc=test' is a valid IPA context 2025-10-14T07:57:04Z DEBUG Search for (objectClass=krbRealmContainer) in dc=ooo,dc=test (sub) 2025-10-14T07:57:04Z DEBUG Found: cn=OOO.TEST,cn=kerberos,dc=ooo,dc=test 2025-10-14T07:57:04Z DEBUG Discovery result: Success; server=ipa.ooo.test, domain=ooo.test, kdc=ipa.ooo.test, basedn=dc=ooo,dc=test 2025-10-14T07:57:04Z DEBUG Validated servers: ipa.ooo.test 2025-10-14T07:57:04Z DEBUG will use discovered domain: ooo.test 2025-10-14T07:57:04Z DEBUG Using servers from command line, disabling DNS discovery 2025-10-14T07:57:04Z DEBUG will use provided server: ipa.ooo.test 2025-10-14T07:57:04Z DEBUG will use discovered realm: OOO.TEST 2025-10-14T07:57:04Z DEBUG will use discovered basedn: dc=ooo,dc=test 2025-10-14T07:57:04Z INFO Client hostname: np0005486751.ooo.test 2025-10-14T07:57:04Z DEBUG Hostname source: Provided as option 2025-10-14T07:57:04Z INFO Realm: OOO.TEST 2025-10-14T07:57:04Z DEBUG Realm source: Discovered from LDAP DNS records in ipa.ooo.test 2025-10-14T07:57:04Z INFO DNS Domain: ooo.test 2025-10-14T07:57:04Z DEBUG DNS Domain source: Forced 2025-10-14T07:57:04Z INFO IPA Server: ipa.ooo.test 2025-10-14T07:57:04Z DEBUG IPA Server source: Provided as option 2025-10-14T07:57:04Z INFO BaseDN: dc=ooo,dc=test 2025-10-14T07:57:04Z DEBUG BaseDN source: From IPA server ldap://ipa.ooo.test:389 2025-10-14T07:57:06Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:06Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=1 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=3 2025-10-14T07:57:06Z DEBUG stdout=inactive 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=1 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr=Failed to get unit file state for systemd-timesyncd.service: No such file or directory 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=3 2025-10-14T07:57:06Z DEBUG stdout=inactive 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z INFO Synchronizing time 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-enabled', 'chronyd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout=enabled 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:06Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:06Z DEBUG Configuring chrony 2025-10-14T07:57:06Z DEBUG Setting time servers: 2025-10-14T07:57:06Z DEBUG '' 2025-10-14T07:57:06Z DEBUG Backing up '/etc/chrony.conf' 2025-10-14T07:57:06Z DEBUG Backing up system configuration file '/etc/chrony.conf' 2025-10-14T07:57:06Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:06Z DEBUG Writing configuration to '/etc/chrony.conf' 2025-10-14T07:57:06Z ERROR Augeas failed to configure file /etc/chrony.conf 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/sbin/restorecon', '/etc/chrony.conf'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout= 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2025-10-14T07:57:06Z DEBUG Process finished, return code=0 2025-10-14T07:57:06Z DEBUG stdout=active 2025-10-14T07:57:06Z DEBUG stderr= 2025-10-14T07:57:06Z DEBUG Restart of chronyd.service complete 2025-10-14T07:57:06Z INFO Attempting to sync time with chronyc. 2025-10-14T07:57:06Z DEBUG Starting external process 2025-10-14T07:57:06Z DEBUG args=['/usr/bin/chronyc', '-d', 'waitsync', '4', '0', '0', '3'] 2025-10-14T07:57:12Z DEBUG Process finished, return code=0 2025-10-14T07:57:12Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 2, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 3, refid: A7A0BBB3, correction: 0.000000051, skew: 0.041 2025-10-14T07:57:12Z DEBUG stderr=Resolved 127.0.0.1 to 127.0.0.1 Resolved ::1 to ::1 Could not remove /run/chrony/chronyc.37756.sock : No such file or directory Opened Unix socket fd=3 remote=/run/chrony/chronyd.sock local=/run/chrony/chronyc.37756.sock Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 2025-10-14T07:57:12Z INFO Time synchronization was successful. 2025-10-14T07:57:13Z DEBUG Initializing principal host/np0005486751.ooo.test@OOO.TEST using keytab /etc/krb5.keytab 2025-10-14T07:57:13Z DEBUG using ccache /etc/ipa/.dns_ccache 2025-10-14T07:57:13Z DEBUG Starting external process 2025-10-14T07:57:13Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:13Z DEBUG Process finished, return code=0 2025-10-14T07:57:13Z DEBUG stdout= 2025-10-14T07:57:13Z DEBUG stderr= 2025-10-14T07:57:13Z DEBUG Starting external process 2025-10-14T07:57:13Z DEBUG args=['/sbin/restorecon', '/etc/krb5.conf.d/freeipa'] 2025-10-14T07:57:13Z DEBUG Process finished, return code=0 2025-10-14T07:57:13Z DEBUG stdout= 2025-10-14T07:57:13Z DEBUG stderr= 2025-10-14T07:57:13Z DEBUG Starting external process 2025-10-14T07:57:13Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2025-10-14T07:57:13Z DEBUG Process finished, return code=0 2025-10-14T07:57:13Z DEBUG stdout=867487207 2025-10-14T07:57:13Z DEBUG stderr= 2025-10-14T07:57:13Z DEBUG Enabling persistent keyring CCACHE 2025-10-14T07:57:13Z DEBUG Writing Kerberos configuration to /tmp/tmp0m0zn2lr: 2025-10-14T07:57:13Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:13Z DEBUG Writing configuration file /tmp/tmp0m0zn2lr 2025-10-14T07:57:13Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:13Z DEBUG Initializing principal host/np0005486751.ooo.test@OOO.TEST using keytab /etc/krb5.keytab 2025-10-14T07:57:13Z DEBUG using ccache /etc/ipa/.dns_ccache 2025-10-14T07:57:15Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:15Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:15Z DEBUG Backing up system configuration file '/etc/hostname' 2025-10-14T07:57:15Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:15Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:15Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:15Z DEBUG Starting external process 2025-10-14T07:57:15Z DEBUG args=['/bin/hostnamectl', 'set-hostname', 'np0005486751.ooo.test'] 2025-10-14T07:57:15Z DEBUG Process finished, return code=0 2025-10-14T07:57:15Z DEBUG stdout= 2025-10-14T07:57:15Z DEBUG stderr= 2025-10-14T07:57:16Z DEBUG Starting external process 2025-10-14T07:57:16Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:16Z DEBUG Process finished, return code=0 2025-10-14T07:57:16Z DEBUG stdout= 2025-10-14T07:57:16Z DEBUG stderr= 2025-10-14T07:57:16Z DEBUG Starting external process 2025-10-14T07:57:16Z DEBUG args=['/sbin/restorecon', '/etc/krb5.conf.d/freeipa'] 2025-10-14T07:57:16Z DEBUG Process finished, return code=0 2025-10-14T07:57:16Z DEBUG stdout= 2025-10-14T07:57:16Z DEBUG stderr= 2025-10-14T07:57:16Z DEBUG Starting external process 2025-10-14T07:57:16Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2025-10-14T07:57:16Z DEBUG Process finished, return code=0 2025-10-14T07:57:16Z DEBUG stdout=867487207 2025-10-14T07:57:16Z DEBUG stderr= 2025-10-14T07:57:16Z DEBUG Enabling persistent keyring CCACHE 2025-10-14T07:57:16Z DEBUG Writing Kerberos configuration to /tmp/tmpz8qi47em: 2025-10-14T07:57:16Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:16Z DEBUG Writing configuration file /tmp/tmpz8qi47em 2025-10-14T07:57:16Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:17Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:17Z WARNING Downloading the CA certificate via HTTP, this is INSECURE 2025-10-14T07:57:17Z DEBUG trying to retrieve CA cert via HTTP from http://ipa.ooo.test/ipa/config/ca.crt 2025-10-14T07:57:17Z DEBUG Starting external process 2025-10-14T07:57:17Z DEBUG args=['/usr/bin/curl', '-o', '-', 'http://ipa.ooo.test/ipa/config/ca.crt'] 2025-10-14T07:57:17Z DEBUG Process finished, return code=0 2025-10-14T07:57:17Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIERDCCAqygAwIBAgIBATANBgkqhkiG9w0BAQsFADAzMREwDwYDVQQKDAhPT08u VEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTI1MTAxNDA3 NDA0NVoXDTQ1MTAxNDA3NDA0NVowMzERMA8GA1UECgwIT09PLlRFU1QxHjAcBgNV BAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCAaIwDQYJKoZIhvcNAQEBBQADggGP ADCCAYoCggGBAO8mzZvFUeVtj5cIde+vqpZazmypoBg11shy6NlUNP8GBXaRIxee YRthjd5jERfr99RwRaFrBUz2F5bp0v2/zSrBPCC4oaRt3reNVhIIrZR2FrV4nI3l j4m+NbIlpzBoJzpvzvLqqgVpnY5FdnYFB81hj5nUq/nzGBskGdd/EH8NJ6/YFQ4F e0U/tCV9dl1IeTqGwfzN8JFUkuQ84GcrQewTKWlGPd6Sroy5f6Xk6ih4KVsCiN97 KRQMIKL1u40Bronk/4jj6kql58W/Gjik6pyvFHeByxhQOcEKKZEDR75ngwZQYkHS cNW7bfrj0ien3G5rFiR8v0+NBdWDPIMvCoks16tyoVunFDW16YefLQISRNnpIn2z EreDsmfrXvctjiv/XiIQd0luJXWeLlLvalbn+y96dAhiXE1JQBy6r9sMEy1VMEIh fwgfrG3xBMMC/SgOL1T2CrPdOphvTTTw4Ggrq4XcYEHIG9Hp+Ge1KJLYqn9IJdRV Jz/RgsNlns73ywIDAQABo2MwYTAdBgNVHQ4EFgQUzP/yMPmsGUy+hSRan30v6q7h 7OIwHwYDVR0jBBgwFoAUzP/yMPmsGUy+hSRan30v6q7h7OIwDwYDVR0TAQH/BAUw AwEB/zAOBgNVHQ8BAf8EBAMCAcYwDQYJKoZIhvcNAQELBQADggGBAN6stRdLcAjZ bsvqGARsR6qfH9Z2PwxduiXQueoXe3gKh6Vnfqa7kMuI9LCgLNM5oybYSm8WJTmg 2gb0lSPvCoqVHd8drSDhAewe8ugZw/Lm1USNXmeZ2bZ3fn5Nr4z0ef7B1sGL98eu baWjowylGuaBzIgpsJw5zatLU2oSSPLmeSDLYUydvMBK+o/UfP2MrcCFiaEXZPdJ dD53RvGNlbcpkYAL9AccoHSub2nXCReWy+Y+2KoeeUoP5hPnJSPypZkWMdcU8ADw VRBiy1Vz/X/5wJUSFUgIYICQFI5nrJGdy1lw/5lhnQ5JbO3R9nZE5LCQsRuaj9p9 tnmgxDQjK6zh8TfXiDkUwtrR46uUurG/lr4hR07edrQM2vKKdtDKB48JZ5ddwsNd cq9Xn0fpweI2anvFsvs2HHPLKCVyRblq9jYBafCWwxD3ZCS4wR2YeFdSErGsfgiX WqhYCoMWZ74uW7QgjWrzZJ4lO2I4LjNyvV/X8aN5c9bbPObHFL1n8g== -----END CERTIFICATE----- 2025-10-14T07:57:17Z DEBUG stderr= % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 100 1541 100 1541 0 0 501k 0 --:--:-- --:--:-- --:--:-- 501k 2025-10-14T07:57:17Z INFO Successfully retrieved CA cert Subject: CN=Certificate Authority,O=OOO.TEST Issuer: CN=Certificate Authority,O=OOO.TEST Valid From: 2025-10-14 07:40:45 Valid Until: 2045-10-14 07:40:45 2025-10-14T07:57:17Z DEBUG Starting external process 2025-10-14T07:57:17Z DEBUG args=['/usr/sbin/ipa-join', '-s', 'ipa.ooo.test', '-b', 'dc=ooo,dc=test', '-h', 'np0005486751.ooo.test', '-w', XXXXXXXX] 2025-10-14T07:57:17Z DEBUG Process finished, return code=0 2025-10-14T07:57:17Z DEBUG stdout= 2025-10-14T07:57:17Z DEBUG stderr=Keytab successfully retrieved and stored in: /etc/krb5.keytab 2025-10-14T07:57:17Z DEBUG Initializing principal host/np0005486751.ooo.test@OOO.TEST using keytab /etc/krb5.keytab 2025-10-14T07:57:17Z DEBUG using ccache /etc/ipa/.dns_ccache 2025-10-14T07:57:17Z DEBUG Attempt 1/5: success 2025-10-14T07:57:18Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:18Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2025-10-14T07:57:18Z DEBUG -> Not backing up - '/etc/ipa/default.conf' doesn't exist 2025-10-14T07:57:18Z DEBUG Writing configuration file /etc/ipa/default.conf 2025-10-14T07:57:18Z DEBUG #File modified by ipa-client-install [global] basedn = dc=ooo,dc=test realm = OOO.TEST domain = ooo.test server = ipa.ooo.test host = np0005486751.ooo.test xmlrpc_uri = https://ipa.ooo.test/ipa/xml enable_ra = True 2025-10-14T07:57:19Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:19Z DEBUG New SSSD config will be created 2025-10-14T07:57:19Z INFO Configured /etc/sssd/sssd.conf 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/bin/certutil', '-d', '/tmp/tmp91dx302n', '-N', '-f', '/tmp/tmp91dx302n/pwdfile.txt', '-@', '/tmp/tmp91dx302n/pwdfile.txt'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/sbin/restorecon', '-F', '/tmp/tmp91dx302n'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout=Warning no default label for /tmp/tmp91dx302n 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/sbin/restorecon', '-F', '/tmp/tmp91dx302n/cert9.db'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout=Warning no default label for /tmp/tmp91dx302n/cert9.db 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/sbin/restorecon', '-F', '/tmp/tmp91dx302n/key4.db'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout=Warning no default label for /tmp/tmp91dx302n/key4.db 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/sbin/restorecon', '-F', '/tmp/tmp91dx302n/pkcs11.txt'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout=Warning no default label for /tmp/tmp91dx302n/pkcs11.txt 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/sbin/restorecon', '-F', '/tmp/tmp91dx302n/pwdfile.txt'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout=Warning no default label for /tmp/tmp91dx302n/pwdfile.txt 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG Starting external process 2025-10-14T07:57:20Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/tmp/tmp91dx302n', '-A', '-n', 'CA certificate 1', '-t', 'C,,', '-a', '-f', '/tmp/tmp91dx302n/pwdfile.txt'] 2025-10-14T07:57:20Z DEBUG Process finished, return code=0 2025-10-14T07:57:20Z DEBUG stdout= 2025-10-14T07:57:20Z DEBUG stderr= 2025-10-14T07:57:20Z DEBUG failed to find session_cookie in persistent storage for principal 'host/np0005486751.ooo.test@OOO.TEST' 2025-10-14T07:57:20Z DEBUG trying https://ipa.ooo.test/ipa/json 2025-10-14T07:57:20Z DEBUG Created connection context.rpcclient_140182388178800 2025-10-14T07:57:20Z DEBUG [try 1]: Forwarding 'schema' to json server 'https://ipa.ooo.test/ipa/json' 2025-10-14T07:57:20Z DEBUG New HTTP connection (ipa.ooo.test) 2025-10-14T07:57:20Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d;path=/ipa;httponly;secure;']' 2025-10-14T07:57:20Z DEBUG storing cookie 'ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d;' for principal host/np0005486751.ooo.test@OOO.TEST 2025-10-14T07:57:20Z DEBUG Destroyed connection context.rpcclient_140182388178800 2025-10-14T07:57:20Z DEBUG importing all plugin modules in ipaclient.remote_plugins.schema$e1d6c890... 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.remote_plugins.schema$e1d6c890.plugins 2025-10-14T07:57:20Z DEBUG importing all plugin modules in ipaclient.plugins... 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.automember 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.automount 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.ca 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.cert 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.certmap 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.certprofile 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.dns 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.hbacrule 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.hbactest 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.host 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.idrange 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.internal 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.location 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.migration 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.misc 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.otptoken 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.otptoken_yubikey 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.passwd 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.permission 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.rpcclient 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.server 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.service 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.sudorule 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.topology 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.trust 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.user 2025-10-14T07:57:20Z DEBUG importing plugin module ipaclient.plugins.vault 2025-10-14T07:57:21Z DEBUG found session_cookie in persistent storage for principal 'host/np0005486751.ooo.test@OOO.TEST', cookie: 'ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d' 2025-10-14T07:57:21Z DEBUG setting session_cookie into context 'ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d;' 2025-10-14T07:57:21Z DEBUG trying https://ipa.ooo.test/ipa/session/json 2025-10-14T07:57:21Z DEBUG Created connection context.rpcclient_140182372184016 2025-10-14T07:57:21Z DEBUG [try 1]: Forwarding 'ping' to json server 'https://ipa.ooo.test/ipa/session/json' 2025-10-14T07:57:21Z DEBUG New HTTP connection (ipa.ooo.test) 2025-10-14T07:57:21Z DEBUG [try 1]: Forwarding 'ca_is_enabled' to json server 'https://ipa.ooo.test/ipa/session/json' 2025-10-14T07:57:21Z DEBUG HTTP connection keep-alive (ipa.ooo.test) 2025-10-14T07:57:21Z DEBUG raw: config_show(version='2.251') 2025-10-14T07:57:21Z DEBUG config_show(version='2.251') 2025-10-14T07:57:21Z DEBUG [try 1]: Forwarding 'config_show/1' to json server 'https://ipa.ooo.test/ipa/session/json' 2025-10-14T07:57:21Z DEBUG HTTP connection keep-alive (ipa.ooo.test) 2025-10-14T07:57:22Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:22Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:22Z DEBUG importing all plugin modules in ipaclient.remote_plugins.schema$e1d6c890... 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.remote_plugins.schema$e1d6c890.plugins 2025-10-14T07:57:22Z DEBUG importing all plugin modules in ipaclient.plugins... 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.automember 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.automount 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.ca 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.cert 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.certmap 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.certprofile 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.dns 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.hbacrule 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.hbactest 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.host 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.idrange 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.internal 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.location 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.migration 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.misc 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.otptoken 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.otptoken_yubikey 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.passwd 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.permission 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.rpcclient 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.server 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.service 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.sudorule 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.topology 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.trust 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.user 2025-10-14T07:57:22Z DEBUG importing plugin module ipaclient.plugins.vault 2025-10-14T07:57:23Z DEBUG found session_cookie in persistent storage for principal 'host/np0005486751.ooo.test@OOO.TEST', cookie: 'ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d' 2025-10-14T07:57:23Z DEBUG setting session_cookie into context 'ipa_session=MagBearerToken=yN6B2uZbDx0T3uXGtOeBG9HlztPVJQHudF%2bbBLvBxZlUn8vf4bYzrdHXrb3iN%2bpKSUizaxwA8V34oVIJWJraGq155NJ55uAGdQ9ucuu%2b7kBBzAGfJwJRMHE5hdelJwyPJKJ%2fMsGuBMCiDh6h%2b0nQO%2flpCEf%2bONf%2fuV2%2fXix75U%2bkMujA3rAeoSqi1oHBNutmng1MvTG0zQeyCPVuDEmNiaDcrdUs02H%2bZ2VCYfYfU3ahMXoabhNjklDLbI8lM9AVlGY%2bZzb7gfPnzYFlkIMPkQ%3d%3d;' 2025-10-14T07:57:23Z DEBUG trying https://ipa.ooo.test/ipa/session/json 2025-10-14T07:57:23Z DEBUG Created connection context.rpcclient_140624901845680 2025-10-14T07:57:23Z DEBUG [try 1]: Forwarding 'ping' to json server 'https://ipa.ooo.test/ipa/session/json' 2025-10-14T07:57:23Z DEBUG New HTTP connection (ipa.ooo.test) 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/bin/certutil', '-d', '/etc/ipa/nssdb', '-N', '-f', '/etc/ipa/nssdb/pwdfile.txt', '-@', '/etc/ipa/nssdb/pwdfile.txt'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/sbin/restorecon', '-F', '/etc/ipa/nssdb'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/sbin/restorecon', '-F', '/etc/ipa/nssdb/cert9.db'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/sbin/restorecon', '-F', '/etc/ipa/nssdb/key4.db'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/sbin/restorecon', '-F', '/etc/ipa/nssdb/pkcs11.txt'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG Starting external process 2025-10-14T07:57:23Z DEBUG args=['/sbin/restorecon', '-F', '/etc/ipa/nssdb/pwdfile.txt'] 2025-10-14T07:57:23Z DEBUG Process finished, return code=0 2025-10-14T07:57:23Z DEBUG stdout= 2025-10-14T07:57:23Z DEBUG stderr= 2025-10-14T07:57:23Z DEBUG retrieving schema for SchemaCache url=ldap://ipa.ooo.test:389 conn= 2025-10-14T07:57:24Z DEBUG Adding CA certificates to the IPA NSS database. 2025-10-14T07:57:24Z DEBUG Starting external process 2025-10-14T07:57:24Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/ipa/nssdb', '-A', '-n', 'OOO.TEST IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/ipa/nssdb/pwdfile.txt'] 2025-10-14T07:57:24Z DEBUG Process finished, return code=0 2025-10-14T07:57:24Z DEBUG stdout= 2025-10-14T07:57:24Z DEBUG stderr= 2025-10-14T07:57:24Z DEBUG Starting external process 2025-10-14T07:57:24Z DEBUG args=['/usr/bin/update-ca-trust'] 2025-10-14T07:57:25Z DEBUG Process finished, return code=0 2025-10-14T07:57:25Z DEBUG stdout= 2025-10-14T07:57:25Z DEBUG stderr= 2025-10-14T07:57:25Z INFO Systemwide CA database updated. 2025-10-14T07:57:25Z DEBUG The DNS query name does not exist: np0005486751.ooo.test. 2025-10-14T07:57:25Z WARNING Hostname (np0005486751.ooo.test) does not have A/AAAA record. 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use loopback IP address 127.0.0.1 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use loopback IP address ::1 2025-10-14T07:57:25Z DEBUG IP check successful: 38.102.83.130 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::f816:3eff:fe8a:e498%eth0 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::f816:3eff:feca:7770%eth1 2025-10-14T07:57:25Z DEBUG IP check successful: 192.168.122.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::f816:3eff:feca:7770%br-ex 2025-10-14T07:57:25Z DEBUG IP check successful: 172.18.0.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::6041:b6ff:fe99:8f82%vlan21 2025-10-14T07:57:25Z DEBUG IP check successful: 172.20.0.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::b0ea:d5ff:fe87:c53e%vlan23 2025-10-14T07:57:25Z DEBUG IP check successful: 172.21.0.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::c4d9:8dff:fe05:6509%vlan44 2025-10-14T07:57:25Z DEBUG IP check successful: 172.17.0.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::d091:38ff:fe3a:51bc%vlan20 2025-10-14T07:57:25Z DEBUG IP check successful: 172.19.0.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::84c7:50ff:fef8:5161%vlan22 2025-10-14T07:57:25Z DEBUG IP check successful: 192.168.122.107 2025-10-14T07:57:25Z DEBUG IP check failed: cannot use link-local IP address fe80::f816:3eff:feca:7770%br-ex 2025-10-14T07:57:25Z DEBUG Searching for an interface of IP address: 192.168.122.107 2025-10-14T07:57:25Z DEBUG Testing local IP address: 127.0.0.1/255.0.0.0 (interface: lo) 2025-10-14T07:57:25Z DEBUG Testing local IP address: 38.102.83.130/255.255.255.0 (interface: eth0) 2025-10-14T07:57:25Z DEBUG Testing local IP address: 192.168.122.107/255.255.255.0 (interface: br-ex) 2025-10-14T07:57:25Z DEBUG Writing nsupdate commands to /etc/ipa/.dns_update.txt: 2025-10-14T07:57:25Z DEBUG debug update delete np0005486751.ooo.test. IN A show send update delete np0005486751.ooo.test. IN AAAA show send update add np0005486751.ooo.test. 1200 IN A 192.168.122.107 show send 2025-10-14T07:57:25Z DEBUG Starting external process 2025-10-14T07:57:25Z DEBUG args=['/usr/bin/nsupdate', '-g', '/etc/ipa/.dns_update.txt'] 2025-10-14T07:57:25Z DEBUG Process finished, return code=0 2025-10-14T07:57:25Z DEBUG stdout=Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY A Outgoing update query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20000 ;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;614287913.sig-ipa.ooo.test. ANY TKEY ;; ADDITIONAL SECTION: 614287913.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760428645 3 NOERROR 1775 YIIG6wYGKwYBBQUCoIIG3zCCBtugDTALBgkqhkiG9xIBAgKiggbIBIIG xGCCBsAGCSqGSIb3EgECAgEAboIGrzCCBqugAwIBBaEDAgEOogcDBQAg AAAAo4IFsGGCBawwggWooAMCAQWhChsIT09PLlRFU1SiHjAcoAMCAQGh FTATGwNETlMbDGlwYS5vb28udGVzdKOCBXMwggVvoAMCARqhAwIBAqKC BWEEggVdXrQexUAAEHD+LeIPX00fgwkc4GU9DLful3HZeBhhapO3iPHO vltL5Oz39jTwIfSltx7T9njPyodYuXMTJAH9IFnQgdXoyA1o7wtIo3G9 7m3GEBKUXkLEREDY8SZb/K6GxgpqyoEHGCJOv2sDXaXjvrXA9yqAJlk8 37EQcBUYyY6oOg6qJzLysIcSEwow5O9MRkZfjI2KVglYu8OmKfOlcV6J i+AK9PDww3UO4DOrhqKGVakkqr137w5mKuSx5HrZEW2vaJRPEcmnFuw3 Od0r5lSqR5xk1/Cq7a4XbL0MdY5nWHdbYwHNmi4U611+5BlpPmFalQ7A 21wlX6xcZJ9fA5/TRddCl6WHXrFYBek4PQ52tCnbqu8Mapxd2zBm4jxv 8WjsOczCz+APFZ1nJ9Z0JGRBRifKAEeUiaAbKbM1XlAKKM1PWsfBrSpx oXU8aeO4Ek/l2mlcmvUfL7WnuwviFIBmVVwsPp5qA19pSR38khKtl13l MnRqKh+KvapLMVN8HBImsZHuOo0KKVaiTuurv46xG8oiKfWfzMp0bXkl pY3VeVHVhjRjAYymUkXzXNu367gqmcBigjmQ4EnBS5aB4fLLN14HYvZ5 VkM7BtOYo3FeyJQ4/WK9ZrhHOzQkssq4ZRhMGevk+uF/0cLg54ns1Nzs WU78kul7Of4u/A5g/sLqEVYg8J44K1FUAblMtDSkABe+byNVmqEiKSGM iCy8maeSmT12dGcrel3EDsbVaLmyO9eveSjywnkXUphalRO3WlsLSfyZ JRDGJdUinNzD5/rEITJQbtaAbn3/MfcuCAlV6c9CfaaG2mnixQO4wfTX pT72XiV8dTyAyCEnS5H1Q4vnMrHHwjqH70OJtD+AYBJW6VFF3pAkLnvK eXOxhGrwVx8pzsDLEgG3sM/wtL6ezQnoabRFkkFVkAqVZhHb8f4LRWoD oXOe40xbEoIo9Dv7ue4QT7RDIlRfUy1s5kHclhffCGk6TMCr4DdcxkEK UEoGii6SIWsHTQ/hTUrsVxOvC82fE2TIfvg/VASqRU6XS7LweNnZYzP9 sbYsZeaRDXsZxKvZQRE2i3dBd+rOIdBRfKjXKbtcCdJi/YzsbGRuv1jJ vRuRRP5tjJtmJPnT/11dTr7W1aY+lTAPClwKOBueid9RE0NTUOo0giWH FPy/YGeWbyojttJBYhSnoYupzhljEg9KjzjSN8SKKt+kCwS66cvOI9km cVSSe46rKpRc7hOvyvPXF973eziKxckR3rMugsFolIX+GRRch0v8Xr2v jInkgJv/46+hZe0t5RKCLySCd/bGvCnHTCxVygmwJk1tVBGGglQluPR8 9r3HQiGH2LPK09y0ktEuVRZYuImVkxsOZUIONSYXph5p2ygbOhSFeAoB YuYY+LYaZMjqUxb+abNcibmlu71b7TUX83g4uAVN6ag9Snn0N2CvrA2D ykrGrp58qUhdMYvVdrFq/wH6c1pqkr4CmLZKGuE10QGwyg5L+DhGiXO7 cTCVWespe9l6qdLkKXo+DGmJt3yRGeHISHzkjol760HEH/Wr+Tn0R6qU E7hq97kCJ3Vltne0Zhq1YgEsmjXlg0LpV6/2xg3ANXjUH4xlcmfiu31v 4UOVVEnso3HnWWZ6Ha6XFcHB7X5tMPBQrNzLbkDpq7lWKPI7cjDb5IPJ W6YV0eS5fM0GVSedCizy/+G/0yfPv7mDG5yr84bE/rMgywtDkL4BYf21 BVeQA2vLMxUbXHVw28B3NIS2FsmkT8Um2qnurHY5UgJ4+OrnO2VkPD1G w+sv/c7Gr3dIPvgenUhP8yvSXTeufDTYp5pqvycnXCnrBCOkgeEwgd6g AwIBEqKB1gSB007VUsVsu2i425keAUUn4fX8bgSGo2kqD8D27Ewbc5AN Fy0iijgxRgx4IuE7W7thX1q9G0VWcwGGjnyQjyZKy5YKwWkoVw1nscXS XO8Cscolrr26aiNVfCx31Wijfznb9AWkBrEFKIFUBRO5pXKRu/qNPu8O EsvlVux1h8gNf1dREBICgKMORlVVexkIvyEymWSKH8y0u9xLX7u+WTPA oAHz6kk7OIQLU0R+qhzC6pxemUiBneHqnm9VWPHPQeWHAegoJSB1tyZt A552mp6PSyxQDVM= 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 42750 ;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY A ;; TSIG PSEUDOSECTION: 614287913.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQE//////8AAAAAPdHz74zQ4zjkKP/jkiST1w== 42750 NOERROR 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY AAAA Outgoing update query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54028 ;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3206267260.sig-ipa.ooo.test. ANY TKEY ;; ADDITIONAL SECTION: 3206267260.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760428645 3 NOERROR 1775 YIIG6wYGKwYBBQUCoIIG3zCCBtugDTALBgkqhkiG9xIBAgKiggbIBIIG xGCCBsAGCSqGSIb3EgECAgEAboIGrzCCBqugAwIBBaEDAgEOogcDBQAg AAAAo4IFsGGCBawwggWooAMCAQWhChsIT09PLlRFU1SiHjAcoAMCAQGh FTATGwNETlMbDGlwYS5vb28udGVzdKOCBXMwggVvoAMCARqhAwIBAqKC BWEEggVdXrQexUAAEHD+LeIPX00fgwkc4GU9DLful3HZeBhhapO3iPHO vltL5Oz39jTwIfSltx7T9njPyodYuXMTJAH9IFnQgdXoyA1o7wtIo3G9 7m3GEBKUXkLEREDY8SZb/K6GxgpqyoEHGCJOv2sDXaXjvrXA9yqAJlk8 37EQcBUYyY6oOg6qJzLysIcSEwow5O9MRkZfjI2KVglYu8OmKfOlcV6J i+AK9PDww3UO4DOrhqKGVakkqr137w5mKuSx5HrZEW2vaJRPEcmnFuw3 Od0r5lSqR5xk1/Cq7a4XbL0MdY5nWHdbYwHNmi4U611+5BlpPmFalQ7A 21wlX6xcZJ9fA5/TRddCl6WHXrFYBek4PQ52tCnbqu8Mapxd2zBm4jxv 8WjsOczCz+APFZ1nJ9Z0JGRBRifKAEeUiaAbKbM1XlAKKM1PWsfBrSpx oXU8aeO4Ek/l2mlcmvUfL7WnuwviFIBmVVwsPp5qA19pSR38khKtl13l MnRqKh+KvapLMVN8HBImsZHuOo0KKVaiTuurv46xG8oiKfWfzMp0bXkl pY3VeVHVhjRjAYymUkXzXNu367gqmcBigjmQ4EnBS5aB4fLLN14HYvZ5 VkM7BtOYo3FeyJQ4/WK9ZrhHOzQkssq4ZRhMGevk+uF/0cLg54ns1Nzs WU78kul7Of4u/A5g/sLqEVYg8J44K1FUAblMtDSkABe+byNVmqEiKSGM iCy8maeSmT12dGcrel3EDsbVaLmyO9eveSjywnkXUphalRO3WlsLSfyZ JRDGJdUinNzD5/rEITJQbtaAbn3/MfcuCAlV6c9CfaaG2mnixQO4wfTX pT72XiV8dTyAyCEnS5H1Q4vnMrHHwjqH70OJtD+AYBJW6VFF3pAkLnvK eXOxhGrwVx8pzsDLEgG3sM/wtL6ezQnoabRFkkFVkAqVZhHb8f4LRWoD oXOe40xbEoIo9Dv7ue4QT7RDIlRfUy1s5kHclhffCGk6TMCr4DdcxkEK UEoGii6SIWsHTQ/hTUrsVxOvC82fE2TIfvg/VASqRU6XS7LweNnZYzP9 sbYsZeaRDXsZxKvZQRE2i3dBd+rOIdBRfKjXKbtcCdJi/YzsbGRuv1jJ vRuRRP5tjJtmJPnT/11dTr7W1aY+lTAPClwKOBueid9RE0NTUOo0giWH FPy/YGeWbyojttJBYhSnoYupzhljEg9KjzjSN8SKKt+kCwS66cvOI9km cVSSe46rKpRc7hOvyvPXF973eziKxckR3rMugsFolIX+GRRch0v8Xr2v jInkgJv/46+hZe0t5RKCLySCd/bGvCnHTCxVygmwJk1tVBGGglQluPR8 9r3HQiGH2LPK09y0ktEuVRZYuImVkxsOZUIONSYXph5p2ygbOhSFeAoB YuYY+LYaZMjqUxb+abNcibmlu71b7TUX83g4uAVN6ag9Snn0N2CvrA2D ykrGrp58qUhdMYvVdrFq/wH6c1pqkr4CmLZKGuE10QGwyg5L+DhGiXO7 cTCVWespe9l6qdLkKXo+DGmJt3yRGeHISHzkjol760HEH/Wr+Tn0R6qU E7hq97kCJ3Vltne0Zhq1YgEsmjXlg0LpV6/2xg3ANXjUH4xlcmfiu31v 4UOVVEnso3HnWWZ6Ha6XFcHB7X5tMPBQrNzLbkDpq7lWKPI7cjDb5IPJ W6YV0eS5fM0GVSedCizy/+G/0yfPv7mDG5yr84bE/rMgywtDkL4BYf21 BVeQA2vLMxUbXHVw28B3NIS2FsmkT8Um2qnurHY5UgJ4+OrnO2VkPD1G w+sv/c7Gr3dIPvgenUhP8yvSXTeufDTYp5pqvycnXCnrBCOkgeEwgd6g AwIBEqKB1gSB02KNPgMSbIM7MSjhX7y34tXFgDqbyY3OhXNl6fVzdEZG 2jtPTrJqt8fh0QSauFWD0D+0MSqbjGptnZYJZFOYgSytxqZn81fjNwfB HZ6mC1su1XUB6U5Z12AXquDjvlJRVrIpLFEiAoKSXpszGKw3583FVHch 8neD7YqEeqC6Rc1WVc1RoRN7hL1cveQhAelUvcHX7HzzahDFJ/ece00d /loHiONIv9DjSfHT5EF1L4geJrw2jSknvbvxGW0vkroprWbljVkDGzN2 P7zM60d2LybmrSc= 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 381 ;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY AAAA ;; TSIG PSEUDOSECTION: 3206267260.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQE//////8AAAAAMdSgnZC/6uCe9Klai2B1jQ== 381 NOERROR 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: np0005486751.ooo.test. 1200 IN A 192.168.122.107 Outgoing update query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46844 ;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3549838202.sig-ipa.ooo.test. ANY TKEY ;; ADDITIONAL SECTION: 3549838202.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760428645 3 NOERROR 1774 YIIG6gYGKwYBBQUCoIIG3jCCBtqgDTALBgkqhkiG9xIBAgKiggbHBIIG w2CCBr8GCSqGSIb3EgECAgEAboIGrjCCBqqgAwIBBaEDAgEOogcDBQAg AAAAo4IFsGGCBawwggWooAMCAQWhChsIT09PLlRFU1SiHjAcoAMCAQGh FTATGwNETlMbDGlwYS5vb28udGVzdKOCBXMwggVvoAMCARqhAwIBAqKC BWEEggVdXrQexUAAEHD+LeIPX00fgwkc4GU9DLful3HZeBhhapO3iPHO vltL5Oz39jTwIfSltx7T9njPyodYuXMTJAH9IFnQgdXoyA1o7wtIo3G9 7m3GEBKUXkLEREDY8SZb/K6GxgpqyoEHGCJOv2sDXaXjvrXA9yqAJlk8 37EQcBUYyY6oOg6qJzLysIcSEwow5O9MRkZfjI2KVglYu8OmKfOlcV6J i+AK9PDww3UO4DOrhqKGVakkqr137w5mKuSx5HrZEW2vaJRPEcmnFuw3 Od0r5lSqR5xk1/Cq7a4XbL0MdY5nWHdbYwHNmi4U611+5BlpPmFalQ7A 21wlX6xcZJ9fA5/TRddCl6WHXrFYBek4PQ52tCnbqu8Mapxd2zBm4jxv 8WjsOczCz+APFZ1nJ9Z0JGRBRifKAEeUiaAbKbM1XlAKKM1PWsfBrSpx oXU8aeO4Ek/l2mlcmvUfL7WnuwviFIBmVVwsPp5qA19pSR38khKtl13l MnRqKh+KvapLMVN8HBImsZHuOo0KKVaiTuurv46xG8oiKfWfzMp0bXkl pY3VeVHVhjRjAYymUkXzXNu367gqmcBigjmQ4EnBS5aB4fLLN14HYvZ5 VkM7BtOYo3FeyJQ4/WK9ZrhHOzQkssq4ZRhMGevk+uF/0cLg54ns1Nzs WU78kul7Of4u/A5g/sLqEVYg8J44K1FUAblMtDSkABe+byNVmqEiKSGM iCy8maeSmT12dGcrel3EDsbVaLmyO9eveSjywnkXUphalRO3WlsLSfyZ JRDGJdUinNzD5/rEITJQbtaAbn3/MfcuCAlV6c9CfaaG2mnixQO4wfTX pT72XiV8dTyAyCEnS5H1Q4vnMrHHwjqH70OJtD+AYBJW6VFF3pAkLnvK eXOxhGrwVx8pzsDLEgG3sM/wtL6ezQnoabRFkkFVkAqVZhHb8f4LRWoD oXOe40xbEoIo9Dv7ue4QT7RDIlRfUy1s5kHclhffCGk6TMCr4DdcxkEK UEoGii6SIWsHTQ/hTUrsVxOvC82fE2TIfvg/VASqRU6XS7LweNnZYzP9 sbYsZeaRDXsZxKvZQRE2i3dBd+rOIdBRfKjXKbtcCdJi/YzsbGRuv1jJ vRuRRP5tjJtmJPnT/11dTr7W1aY+lTAPClwKOBueid9RE0NTUOo0giWH FPy/YGeWbyojttJBYhSnoYupzhljEg9KjzjSN8SKKt+kCwS66cvOI9km cVSSe46rKpRc7hOvyvPXF973eziKxckR3rMugsFolIX+GRRch0v8Xr2v jInkgJv/46+hZe0t5RKCLySCd/bGvCnHTCxVygmwJk1tVBGGglQluPR8 9r3HQiGH2LPK09y0ktEuVRZYuImVkxsOZUIONSYXph5p2ygbOhSFeAoB YuYY+LYaZMjqUxb+abNcibmlu71b7TUX83g4uAVN6ag9Snn0N2CvrA2D ykrGrp58qUhdMYvVdrFq/wH6c1pqkr4CmLZKGuE10QGwyg5L+DhGiXO7 cTCVWespe9l6qdLkKXo+DGmJt3yRGeHISHzkjol760HEH/Wr+Tn0R6qU E7hq97kCJ3Vltne0Zhq1YgEsmjXlg0LpV6/2xg3ANXjUH4xlcmfiu31v 4UOVVEnso3HnWWZ6Ha6XFcHB7X5tMPBQrNzLbkDpq7lWKPI7cjDb5IPJ W6YV0eS5fM0GVSedCizy/+G/0yfPv7mDG5yr84bE/rMgywtDkL4BYf21 BVeQA2vLMxUbXHVw28B3NIS2FsmkT8Um2qnurHY5UgJ4+OrnO2VkPD1G w+sv/c7Gr3dIPvgenUhP8yvSXTeufDTYp5pqvycnXCnrBCOkgeAwgd2g AwIBEqKB1QSB0o9hzB0hCV/ScVknjU4bLir75RVC37QsyVHiSe3X4D5b kiUX9qvv2HICcVnGpgpWvXGFs9icLIdLX0wXl3VPlzyPrvC0duEVFbJ7 YTU9eLOuAhp02bDWSMkRMOwXUD/pouKlVTlKM3hnqb/mWQxNibKY8sTh e1EzJ8AApx3M+3JtJEze6yUa1TYV3ELYir6c8CkVToQuHo8O0lzDPpSm 8EYSdJ2SzIEq4vjLd+UYJCVwhppW8CjTS5muqB1N0Gnd+aQvAh0IDt3y 2jIrM/W8bqYGzg== 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 60968 ;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 ;; UPDATE SECTION: np0005486751.ooo.test. 1200 IN A 192.168.122.107 ;; TSIG PSEUDOSECTION: 3549838202.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQE//////8AAAAAACebSX0iBHXW1B2edMMF1Q== 60968 NOERROR 0 2025-10-14T07:57:25Z DEBUG stderr=Reply from SOA query: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 29084 ;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;np0005486751.ooo.test. IN SOA ;; AUTHORITY SECTION: ooo.test. 0 IN SOA ipa.ooo.test. hostmaster.ooo.test. 1760427957 3600 900 1209600 3600 Found zone name: ooo.test The master is: ipa.ooo.test start_gssrequest Found realm from ticket: OOO.TEST send_gssrequest recvmsg reply from GSS-TSIG query ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20000 ;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;614287913.sig-ipa.ooo.test. ANY TKEY ;; ANSWER SECTION: 614287913.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760432245 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvMoFBgWs/sLsM pIQ6yVkHvlYbMpo0NilTyItp3N8fnt2aEh/wJW741I8VXVChdodyFEBv ne7hcA5FeG/D5rtyWUbt5659k4FCnQOjrAeh0qZs7mELODvy+Za1fe0h u6OXrmESzhwdg4rcE0tPGo4E 0 ;; TSIG PSEUDOSECTION: 614287913.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAEig6G10rhQ9kGJCKHeKU0w== 20000 NOERROR 0 Sending update to 10.255.255.25#53 Reply from update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 42750 ;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1 ;; ZONE SECTION: ;ooo.test. IN SOA ;; TSIG PSEUDOSECTION: 614287913.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAEig6HCd9s51hlshktnRf3g== 42750 NOERROR 0 Reply from SOA query: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 2247 ;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;np0005486751.ooo.test. IN SOA ;; AUTHORITY SECTION: ooo.test. 0 IN SOA ipa.ooo.test. hostmaster.ooo.test. 1760427957 3600 900 1209600 3600 Found zone name: ooo.test The master is: ipa.ooo.test start_gssrequest send_gssrequest recvmsg reply from GSS-TSIG query ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54028 ;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3206267260.sig-ipa.ooo.test. ANY TKEY ;; ANSWER SECTION: 3206267260.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760432245 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRv8IwoifQHx8Lh om6vBosSwmOy9OX+QCJ+P+F7ZtGLxJtuyTYntIr9iJPaBy3+LgTLJ7xl R7zGtUor784+slwZbHkz8wPB2ahKRkWdOxBT9k0IrGxBBooFPCMIAraA 8JTjMVe+Um0HeYYlmTpXQgKg 0 ;; TSIG PSEUDOSECTION: 3206267260.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAMUQtPBGBvDe8JRa1hBow4A== 54028 NOERROR 0 Sending update to 10.255.255.25#53 Reply from update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 381 ;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1 ;; ZONE SECTION: ;ooo.test. IN SOA ;; TSIG PSEUDOSECTION: 3206267260.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAMUQtPU6nzF0zD3enrW38fw== 381 NOERROR 0 Reply from SOA query: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 61429 ;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;np0005486751.ooo.test. IN SOA ;; AUTHORITY SECTION: ooo.test. 0 IN SOA ipa.ooo.test. hostmaster.ooo.test. 1760427957 3600 900 1209600 3600 Found zone name: ooo.test The master is: ipa.ooo.test start_gssrequest send_gssrequest recvmsg reply from GSS-TSIG query ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46844 ;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3549838202.sig-ipa.ooo.test. ANY TKEY ;; ANSWER SECTION: 3549838202.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760432245 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvIiCFdaYq5uZb 1Jc8xp21ptdGEAVaRe+xpNDoAEnSqe5tZfytyu7hmcZQ/++Q2obsVkw8 hFlPmxruaQsFhZbRUqafGT2HabxTi11SvGvLpIiVm5pX0XMIyaAnhfAC b8mvHb1EIU4YSqusHBzTQpKO 0 ;; TSIG PSEUDOSECTION: 3549838202.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAADMxsqvV4YoTlMD7GrY68BA== 46844 NOERROR 0 Sending update to 10.255.255.25#53 Reply from update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 60968 ;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1 ;; ZONE SECTION: ;ooo.test. IN SOA ;; TSIG PSEUDOSECTION: 3549838202.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAADMxsq/aIKkXmUvopRJ6i8w== 60968 NOERROR 0 2025-10-14T07:57:25Z DEBUG DNS resolver: Query: np0005486751.ooo.test IN A 2025-10-14T07:57:25Z DEBUG DNS resolver: Query: np0005486751.ooo.test IN AAAA 2025-10-14T07:57:25Z DEBUG DNS resolver: No record. 2025-10-14T07:57:25Z DEBUG DNS resolver: Query: 192.168.122.107 IN PTR 2025-10-14T07:57:25Z DEBUG DNS resolver: No record. 2025-10-14T07:57:25Z WARNING Missing reverse record(s) for address(es): 192.168.122.107. 2025-10-14T07:57:25Z INFO Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub 2025-10-14T07:57:25Z INFO Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub 2025-10-14T07:57:25Z INFO Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub 2025-10-14T07:57:25Z DEBUG [try 1]: Forwarding 'host_mod' to json server 'https://ipa.ooo.test/ipa/session/json' 2025-10-14T07:57:25Z DEBUG HTTP connection keep-alive (ipa.ooo.test) 2025-10-14T07:57:25Z DEBUG Writing nsupdate commands to /etc/ipa/.dns_update.txt: 2025-10-14T07:57:25Z DEBUG debug update delete np0005486751.ooo.test. IN SSHFP show send update add np0005486751.ooo.test. 1200 IN SSHFP 1 1 EB779CD1943B51210158C4B02F4A903C57B6784B update add np0005486751.ooo.test. 1200 IN SSHFP 1 2 F68CF95C419CC98D894BC904952EADC24950755EA055524F7B072271DF1F9384 update add np0005486751.ooo.test. 1200 IN SSHFP 3 1 B5FD3D206D23AA5193DC1B6060996726328C20F9 update add np0005486751.ooo.test. 1200 IN SSHFP 3 2 9D989E85181B5DACD3CE59E301912CC271129C7166F609367AEBDEAB96A743E7 update add np0005486751.ooo.test. 1200 IN SSHFP 4 1 0403D43AA8C616D00D3B2716EC2146C2ED5C4F15 update add np0005486751.ooo.test. 1200 IN SSHFP 4 2 462BC518C5DE55742E144FC664C7EA603039E3487CFF1EA02F273C06529F1E32 show send 2025-10-14T07:57:25Z DEBUG Starting external process 2025-10-14T07:57:25Z DEBUG args=['/usr/bin/nsupdate', '-g', '/etc/ipa/.dns_update.txt'] 2025-10-14T07:57:25Z DEBUG Process finished, return code=0 2025-10-14T07:57:25Z DEBUG stdout=Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY SSHFP Outgoing update query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16934 ;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;2988319349.sig-ipa.ooo.test. ANY TKEY ;; ADDITIONAL SECTION: 2988319349.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760428645 3 NOERROR 1775 YIIG6wYGKwYBBQUCoIIG3zCCBtugDTALBgkqhkiG9xIBAgKiggbIBIIG xGCCBsAGCSqGSIb3EgECAgEAboIGrzCCBqugAwIBBaEDAgEOogcDBQAg AAAAo4IFsGGCBawwggWooAMCAQWhChsIT09PLlRFU1SiHjAcoAMCAQGh FTATGwNETlMbDGlwYS5vb28udGVzdKOCBXMwggVvoAMCARqhAwIBAqKC BWEEggVdXrQexUAAEHD+LeIPX00fgwkc4GU9DLful3HZeBhhapO3iPHO vltL5Oz39jTwIfSltx7T9njPyodYuXMTJAH9IFnQgdXoyA1o7wtIo3G9 7m3GEBKUXkLEREDY8SZb/K6GxgpqyoEHGCJOv2sDXaXjvrXA9yqAJlk8 37EQcBUYyY6oOg6qJzLysIcSEwow5O9MRkZfjI2KVglYu8OmKfOlcV6J i+AK9PDww3UO4DOrhqKGVakkqr137w5mKuSx5HrZEW2vaJRPEcmnFuw3 Od0r5lSqR5xk1/Cq7a4XbL0MdY5nWHdbYwHNmi4U611+5BlpPmFalQ7A 21wlX6xcZJ9fA5/TRddCl6WHXrFYBek4PQ52tCnbqu8Mapxd2zBm4jxv 8WjsOczCz+APFZ1nJ9Z0JGRBRifKAEeUiaAbKbM1XlAKKM1PWsfBrSpx oXU8aeO4Ek/l2mlcmvUfL7WnuwviFIBmVVwsPp5qA19pSR38khKtl13l MnRqKh+KvapLMVN8HBImsZHuOo0KKVaiTuurv46xG8oiKfWfzMp0bXkl pY3VeVHVhjRjAYymUkXzXNu367gqmcBigjmQ4EnBS5aB4fLLN14HYvZ5 VkM7BtOYo3FeyJQ4/WK9ZrhHOzQkssq4ZRhMGevk+uF/0cLg54ns1Nzs WU78kul7Of4u/A5g/sLqEVYg8J44K1FUAblMtDSkABe+byNVmqEiKSGM iCy8maeSmT12dGcrel3EDsbVaLmyO9eveSjywnkXUphalRO3WlsLSfyZ JRDGJdUinNzD5/rEITJQbtaAbn3/MfcuCAlV6c9CfaaG2mnixQO4wfTX pT72XiV8dTyAyCEnS5H1Q4vnMrHHwjqH70OJtD+AYBJW6VFF3pAkLnvK eXOxhGrwVx8pzsDLEgG3sM/wtL6ezQnoabRFkkFVkAqVZhHb8f4LRWoD oXOe40xbEoIo9Dv7ue4QT7RDIlRfUy1s5kHclhffCGk6TMCr4DdcxkEK UEoGii6SIWsHTQ/hTUrsVxOvC82fE2TIfvg/VASqRU6XS7LweNnZYzP9 sbYsZeaRDXsZxKvZQRE2i3dBd+rOIdBRfKjXKbtcCdJi/YzsbGRuv1jJ vRuRRP5tjJtmJPnT/11dTr7W1aY+lTAPClwKOBueid9RE0NTUOo0giWH FPy/YGeWbyojttJBYhSnoYupzhljEg9KjzjSN8SKKt+kCwS66cvOI9km cVSSe46rKpRc7hOvyvPXF973eziKxckR3rMugsFolIX+GRRch0v8Xr2v jInkgJv/46+hZe0t5RKCLySCd/bGvCnHTCxVygmwJk1tVBGGglQluPR8 9r3HQiGH2LPK09y0ktEuVRZYuImVkxsOZUIONSYXph5p2ygbOhSFeAoB YuYY+LYaZMjqUxb+abNcibmlu71b7TUX83g4uAVN6ag9Snn0N2CvrA2D ykrGrp58qUhdMYvVdrFq/wH6c1pqkr4CmLZKGuE10QGwyg5L+DhGiXO7 cTCVWespe9l6qdLkKXo+DGmJt3yRGeHISHzkjol760HEH/Wr+Tn0R6qU E7hq97kCJ3Vltne0Zhq1YgEsmjXlg0LpV6/2xg3ANXjUH4xlcmfiu31v 4UOVVEnso3HnWWZ6Ha6XFcHB7X5tMPBQrNzLbkDpq7lWKPI7cjDb5IPJ W6YV0eS5fM0GVSedCizy/+G/0yfPv7mDG5yr84bE/rMgywtDkL4BYf21 BVeQA2vLMxUbXHVw28B3NIS2FsmkT8Um2qnurHY5UgJ4+OrnO2VkPD1G w+sv/c7Gr3dIPvgenUhP8yvSXTeufDTYp5pqvycnXCnrBCOkgeEwgd6g AwIBEqKB1gSB0z/MqQsqPj8B9fX9+mbtoHMFVlSsWhFhZ0BLFZ3EK/HN v0zgO1ms8ur+8Ilca/UCdunj28/VIFdrhaxrdJ2S9FKXNe/S3y0wneVV QBA2B5FV5OROcjOm5AEmKYNX3iWfsU3AHk9OjGqs8sIYigqP5G54G7Qi cYKTUcIyZRgkyw+SAnj4QewKlOfwJKnZLXi7ApMMWfU2tSWxKC+khtms 8Foa4yFiCWt+x1mdbrU7MuFdeXvFi513H94qP5KoV1LUygTcJBo5OeG8 +Bw3engtO8v/GS8= 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 57190 ;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 ;; UPDATE SECTION: np0005486751.ooo.test. 0 ANY SSHFP ;; TSIG PSEUDOSECTION: 2988319349.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQE//////8AAAAADihEJqaRkM+fdK10jJjXdQ== 57190 NOERROR 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: np0005486751.ooo.test. 1200 IN SSHFP 1 1 EB779CD1943B51210158C4B02F4A903C57B6784B np0005486751.ooo.test. 1200 IN SSHFP 1 2 F68CF95C419CC98D894BC904952EADC24950755EA055524F7B072271 DF1F9384 np0005486751.ooo.test. 1200 IN SSHFP 3 1 B5FD3D206D23AA5193DC1B6060996726328C20F9 np0005486751.ooo.test. 1200 IN SSHFP 3 2 9D989E85181B5DACD3CE59E301912CC271129C7166F609367AEBDEAB 96A743E7 np0005486751.ooo.test. 1200 IN SSHFP 4 1 0403D43AA8C616D00D3B2716EC2146C2ED5C4F15 np0005486751.ooo.test. 1200 IN SSHFP 4 2 462BC518C5DE55742E144FC664C7EA603039E3487CFF1EA02F273C06 529F1E32 Outgoing update query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13653 ;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3219401217.sig-ipa.ooo.test. ANY TKEY ;; ADDITIONAL SECTION: 3219401217.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760428645 3 NOERROR 1775 YIIG6wYGKwYBBQUCoIIG3zCCBtugDTALBgkqhkiG9xIBAgKiggbIBIIG xGCCBsAGCSqGSIb3EgECAgEAboIGrzCCBqugAwIBBaEDAgEOogcDBQAg AAAAo4IFsGGCBawwggWooAMCAQWhChsIT09PLlRFU1SiHjAcoAMCAQGh FTATGwNETlMbDGlwYS5vb28udGVzdKOCBXMwggVvoAMCARqhAwIBAqKC BWEEggVdXrQexUAAEHD+LeIPX00fgwkc4GU9DLful3HZeBhhapO3iPHO vltL5Oz39jTwIfSltx7T9njPyodYuXMTJAH9IFnQgdXoyA1o7wtIo3G9 7m3GEBKUXkLEREDY8SZb/K6GxgpqyoEHGCJOv2sDXaXjvrXA9yqAJlk8 37EQcBUYyY6oOg6qJzLysIcSEwow5O9MRkZfjI2KVglYu8OmKfOlcV6J i+AK9PDww3UO4DOrhqKGVakkqr137w5mKuSx5HrZEW2vaJRPEcmnFuw3 Od0r5lSqR5xk1/Cq7a4XbL0MdY5nWHdbYwHNmi4U611+5BlpPmFalQ7A 21wlX6xcZJ9fA5/TRddCl6WHXrFYBek4PQ52tCnbqu8Mapxd2zBm4jxv 8WjsOczCz+APFZ1nJ9Z0JGRBRifKAEeUiaAbKbM1XlAKKM1PWsfBrSpx oXU8aeO4Ek/l2mlcmvUfL7WnuwviFIBmVVwsPp5qA19pSR38khKtl13l MnRqKh+KvapLMVN8HBImsZHuOo0KKVaiTuurv46xG8oiKfWfzMp0bXkl pY3VeVHVhjRjAYymUkXzXNu367gqmcBigjmQ4EnBS5aB4fLLN14HYvZ5 VkM7BtOYo3FeyJQ4/WK9ZrhHOzQkssq4ZRhMGevk+uF/0cLg54ns1Nzs WU78kul7Of4u/A5g/sLqEVYg8J44K1FUAblMtDSkABe+byNVmqEiKSGM iCy8maeSmT12dGcrel3EDsbVaLmyO9eveSjywnkXUphalRO3WlsLSfyZ JRDGJdUinNzD5/rEITJQbtaAbn3/MfcuCAlV6c9CfaaG2mnixQO4wfTX pT72XiV8dTyAyCEnS5H1Q4vnMrHHwjqH70OJtD+AYBJW6VFF3pAkLnvK eXOxhGrwVx8pzsDLEgG3sM/wtL6ezQnoabRFkkFVkAqVZhHb8f4LRWoD oXOe40xbEoIo9Dv7ue4QT7RDIlRfUy1s5kHclhffCGk6TMCr4DdcxkEK UEoGii6SIWsHTQ/hTUrsVxOvC82fE2TIfvg/VASqRU6XS7LweNnZYzP9 sbYsZeaRDXsZxKvZQRE2i3dBd+rOIdBRfKjXKbtcCdJi/YzsbGRuv1jJ vRuRRP5tjJtmJPnT/11dTr7W1aY+lTAPClwKOBueid9RE0NTUOo0giWH FPy/YGeWbyojttJBYhSnoYupzhljEg9KjzjSN8SKKt+kCwS66cvOI9km cVSSe46rKpRc7hOvyvPXF973eziKxckR3rMugsFolIX+GRRch0v8Xr2v jInkgJv/46+hZe0t5RKCLySCd/bGvCnHTCxVygmwJk1tVBGGglQluPR8 9r3HQiGH2LPK09y0ktEuVRZYuImVkxsOZUIONSYXph5p2ygbOhSFeAoB YuYY+LYaZMjqUxb+abNcibmlu71b7TUX83g4uAVN6ag9Snn0N2CvrA2D ykrGrp58qUhdMYvVdrFq/wH6c1pqkr4CmLZKGuE10QGwyg5L+DhGiXO7 cTCVWespe9l6qdLkKXo+DGmJt3yRGeHISHzkjol760HEH/Wr+Tn0R6qU E7hq97kCJ3Vltne0Zhq1YgEsmjXlg0LpV6/2xg3ANXjUH4xlcmfiu31v 4UOVVEnso3HnWWZ6Ha6XFcHB7X5tMPBQrNzLbkDpq7lWKPI7cjDb5IPJ W6YV0eS5fM0GVSedCizy/+G/0yfPv7mDG5yr84bE/rMgywtDkL4BYf21 BVeQA2vLMxUbXHVw28B3NIS2FsmkT8Um2qnurHY5UgJ4+OrnO2VkPD1G w+sv/c7Gr3dIPvgenUhP8yvSXTeufDTYp5pqvycnXCnrBCOkgeEwgd6g AwIBEqKB1gSB06xnAlCO9DGJiKnFTBsxkX1F0jJlOOiibLg078w9an+p 4bJ4TfmOLGPSgirAMP42+/gColcjQ/UGlFRmv/BKiLT7EoQaw9JAXgxF VZhQ/GcUuk/UnuWhyG1mNnMkLcr/X9hLZtNc2SkVzPNiA5fRSaWU1g3b ByvHrxxbU3DP0mn0WLJue3CuppzuTyWXPXtULYM9/gIZmmc+aYLzeqcx LxAKNWKuZ3S3GpJ7Kpi4r0PlEN9y5oZlUwBnpozGr+2nCLn+osHDDB4A frgZyYsN0UEjWKk= 0 Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 58903 ;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 6, ADDITIONAL: 1 ;; UPDATE SECTION: np0005486751.ooo.test. 1200 IN SSHFP 1 1 EB779CD1943B51210158C4B02F4A903C57B6784B np0005486751.ooo.test. 1200 IN SSHFP 1 2 F68CF95C419CC98D894BC904952EADC24950755EA055524F7B072271 DF1F9384 np0005486751.ooo.test. 1200 IN SSHFP 3 1 B5FD3D206D23AA5193DC1B6060996726328C20F9 np0005486751.ooo.test. 1200 IN SSHFP 3 2 9D989E85181B5DACD3CE59E301912CC271129C7166F609367AEBDEAB 96A743E7 np0005486751.ooo.test. 1200 IN SSHFP 4 1 0403D43AA8C616D00D3B2716EC2146C2ED5C4F15 np0005486751.ooo.test. 1200 IN SSHFP 4 2 462BC518C5DE55742E144FC664C7EA603039E3487CFF1EA02F273C06 529F1E32 ;; TSIG PSEUDOSECTION: 3219401217.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQE//////8AAAAAE4rtdXW73taDspm9VexI7w== 58903 NOERROR 0 2025-10-14T07:57:25Z DEBUG stderr=Reply from SOA query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12483 ;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;np0005486751.ooo.test. IN SOA ;; AUTHORITY SECTION: ooo.test. 3600 IN SOA ipa.ooo.test. hostmaster.ooo.test. 1760428650 3600 900 1209600 3600 Found zone name: ooo.test The master is: ipa.ooo.test start_gssrequest Found realm from ticket: OOO.TEST send_gssrequest recvmsg reply from GSS-TSIG query ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16934 ;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;2988319349.sig-ipa.ooo.test. ANY TKEY ;; ANSWER SECTION: 2988319349.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760432245 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvu9cESaKq4qxY ZANvhHBV55HZS69MsgGuQpFaRW9E7ZTmDGe+dsOvV08owDqppQ/dfcA3 ESFdgDcD2w8Tg/FyZ8M8h7GtsjNuZQIiFlzrga0eEs8zgJgper3P/3jW L5JfJB0BLNEwVZxZhhkcPJEX 0 ;; TSIG PSEUDOSECTION: 2988319349.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAOysX5X4WsaCfA3OIP/UKCw== 16934 NOERROR 0 Sending update to 10.255.255.25#53 Reply from update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 57190 ;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1 ;; ZONE SECTION: ;ooo.test. IN SOA ;; TSIG PSEUDOSECTION: 2988319349.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAAOysX5pqtIeTImMWJ0sq0BQ== 57190 NOERROR 0 Reply from SOA query: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 43034 ;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;np0005486751.ooo.test. IN SOA ;; AUTHORITY SECTION: ooo.test. 3600 IN SOA ipa.ooo.test. hostmaster.ooo.test. 1760428650 3600 900 1209600 3600 Found zone name: ooo.test The master is: ipa.ooo.test start_gssrequest send_gssrequest recvmsg reply from GSS-TSIG query ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13653 ;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;3219401217.sig-ipa.ooo.test. ANY TKEY ;; ANSWER SECTION: 3219401217.sig-ipa.ooo.test. 0 ANY TKEY gss-tsig. 1760428645 1760432245 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRv/PsksJL2qbhc sWCVqmw/NmDnaRwqHbFXG4fSKwkGMKIdY2a6+lMaBVvot4XNTFfAZ1sq +LWx1Vzj13DT4Iv826L0twA4eRte/D8b+VO+pZ9fPp/2QkJtNHpmSR0x lWz/m05GuwQGuwKiKuAcOgZA 0 ;; TSIG PSEUDOSECTION: 3219401217.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAACc6cERkOl+LTGsXGo77+vg== 13653 NOERROR 0 Sending update to 10.255.255.25#53 Reply from update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 58903 ;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1 ;; ZONE SECTION: ;ooo.test. IN SOA ;; TSIG PSEUDOSECTION: 3219401217.sig-ipa.ooo.test. 0 ANY TSIG gss-tsig. 1760428645 300 28 BAQF//////8AAAAACc6cEiI+Ouuxp+g+o7FO/g== 58903 NOERROR 0 2025-10-14T07:57:25Z DEBUG Starting external process 2025-10-14T07:57:25Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2025-10-14T07:57:25Z DEBUG Process finished, return code=0 2025-10-14T07:57:25Z DEBUG stdout=UNIT FILE STATE PRESET efi.automount generated - proc-sys-fs-binfmt_misc.automount static - -.mount generated - boot-efi.mount generated - boot.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - efi.mount generated - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount disabled disabled var-lib-nfs-rpc_pipefs.mount static - insights-client-results.path disabled disabled systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-1.scope transient - session-13.scope transient - session-14.scope transient - arptables.service disabled disabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - blk-availability.service disabled disabled certmonger.service disabled disabled chrony-online.service enabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled cloud-config.service enabled disabled cloud-final.service enabled disabled cloud-init-hotplugd.service static - cloud-init-local.service enabled disabled cloud-init.service enabled disabled cockpit-motd.service static - cockpit-wsinstance-http.service static - cockpit-wsinstance-https-factory@.service static - cockpit-wsinstance-https@.service static - cockpit.service static - console-getty.service disabled disabled container-getty@.service static - cpupower.service disabled disabled crond.service enabled enabled dbus-broker.service enabled enabled dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dm-event.service static - dnf-makecache.service static - dnf-system-upgrade-cleanup.service static - dnf-system-upgrade.service disabled disabled dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown-onfailure.service static - dracut-shutdown.service static - driverctl@.service static - ebtables.service disabled disabled emergency.service static - fstrim.service static - fwupd-offline-update.service static - fwupd-refresh.service static - fwupd.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - insights-client-boot.service enabled enabled insights-client-results.service static - insights-client.service static - ip6tables.service disabled disabled iptables.service disabled disabled irqbalance.service enabled enabled kdump.service enabled enabled kmod-static-nodes.service static - kvm_stat.service disabled disabled ldconfig.service static - loadmodules.service enabled enabled logrotate.service static - lvm2-lvmpolld.service static - lvm2-monitor.service enabled enabled man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled microcode.service enabled enabled modprobe@.service static - network.service generated - NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled disabled NetworkManager.service enabled enabled neutron-cleanup.service enabled disabled nfs-blkmap.service disabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nftables.service enabled disabled nis-domainname.service enabled enabled nm-priv-helper.service static - nmstate.service disabled disabled oddjobd.service disabled disabled openvswitch.service enabled disabled os-collect-config.service disabled disabled ovs-delete-transient-ports.service static - ovs-vswitchd.service static - ovsdb-server.service static - packagekit-offline-update.service static - packagekit.service static - pam_namespace.service static - podman-auto-update.service disabled disabled podman-clean-transient.service disabled disabled podman-kube@.service disabled disabled podman-restart.service disabled disabled podman.service disabled disabled polkit.service static - puppet.service disabled disabled puppetagent.service alias - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rhsm-facts.service disabled disabled rhsm.service disabled disabled rhsmcertd.service enabled enabled rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service enabled enabled rpmdb-rebuild.service disabled disabled rsyslog.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service indirect disabled setroubleshootd.service static - sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-boot-update.service enabled enabled systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service static - systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service enabled enabled systemd-pcrphase-initrd.service static - systemd-pcrphase-sysinit.service static - systemd-pcrphase.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysupdate-reboot.service indirect disabled systemd-sysupdate.service indirect disabled systemd-sysusers.service static - systemd-timedated.service static - systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-vconsole-setup.service static - systemd-volatile-root.service static - teamd@.service static - tuned.service enabled enabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - system-cockpithttps.slice static - system-systemd\x2dcryptsetup.slice static - user.slice static - cloud-init-hotplugd.socket disabled disabled cockpit-wsinstance-http.socket static - cockpit-wsinstance-https-factory.socket static - cockpit-wsinstance-https@.socket static - cockpit.socket disabled disabled dbus.socket enabled enabled dm-event.socket enabled enabled lvm2-lvmpolld.socket enabled enabled podman.socket disabled disabled rpcbind.socket enabled enabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cloud-config.target static - cloud-init.target enabled-runtime disabled cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - emergency.target static - exit.target disabled disabled factory-reset.target static - final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd-usr-fs.target static - initrd.target static - integritysetup-pre.target static - integritysetup.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target enabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer disabled disabled fwupd-refresh.timer disabled disabled insights-client.timer disabled disabled logrotate.timer enabled enabled podman-auto-update.timer disabled disabled sysstat-collect.timer enabled disabled sysstat-summary.timer enabled disabled systemd-sysupdate-reboot.timer disabled disabled systemd-sysupdate.timer disabled disabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 358 unit files listed. 2025-10-14T07:57:25Z DEBUG stderr= 2025-10-14T07:57:25Z DEBUG Starting external process 2025-10-14T07:57:25Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout=UNIT FILE STATE PRESET efi.automount generated - proc-sys-fs-binfmt_misc.automount static - -.mount generated - boot-efi.mount generated - boot.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - efi.mount generated - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount disabled disabled var-lib-nfs-rpc_pipefs.mount static - insights-client-results.path disabled disabled systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-1.scope transient - session-13.scope transient - session-14.scope transient - arptables.service disabled disabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - blk-availability.service disabled disabled certmonger.service disabled disabled chrony-online.service enabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled cloud-config.service enabled disabled cloud-final.service enabled disabled cloud-init-hotplugd.service static - cloud-init-local.service enabled disabled cloud-init.service enabled disabled cockpit-motd.service static - cockpit-wsinstance-http.service static - cockpit-wsinstance-https-factory@.service static - cockpit-wsinstance-https@.service static - cockpit.service static - console-getty.service disabled disabled container-getty@.service static - cpupower.service disabled disabled crond.service enabled enabled dbus-broker.service enabled enabled dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dm-event.service static - dnf-makecache.service static - dnf-system-upgrade-cleanup.service static - dnf-system-upgrade.service disabled disabled dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown-onfailure.service static - dracut-shutdown.service static - driverctl@.service static - ebtables.service disabled disabled emergency.service static - fstrim.service static - fwupd-offline-update.service static - fwupd-refresh.service static - fwupd.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - insights-client-boot.service enabled enabled insights-client-results.service static - insights-client.service static - ip6tables.service disabled disabled iptables.service disabled disabled irqbalance.service enabled enabled kdump.service enabled enabled kmod-static-nodes.service static - kvm_stat.service disabled disabled ldconfig.service static - loadmodules.service enabled enabled logrotate.service static - lvm2-lvmpolld.service static - lvm2-monitor.service enabled enabled man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled microcode.service enabled enabled modprobe@.service static - network.service generated - NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled disabled NetworkManager.service enabled enabled neutron-cleanup.service enabled disabled nfs-blkmap.service disabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nftables.service enabled disabled nis-domainname.service enabled enabled nm-priv-helper.service static - nmstate.service disabled disabled oddjobd.service disabled disabled openvswitch.service enabled disabled os-collect-config.service disabled disabled ovs-delete-transient-ports.service static - ovs-vswitchd.service static - ovsdb-server.service static - packagekit-offline-update.service static - packagekit.service static - pam_namespace.service static - podman-auto-update.service disabled disabled podman-clean-transient.service disabled disabled podman-kube@.service disabled disabled podman-restart.service disabled disabled podman.service disabled disabled polkit.service static - puppet.service disabled disabled puppetagent.service alias - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rhsm-facts.service disabled disabled rhsm.service disabled disabled rhsmcertd.service enabled enabled rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service enabled enabled rpmdb-rebuild.service disabled disabled rsyslog.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service indirect disabled setroubleshootd.service static - sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-boot-update.service enabled enabled systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service static - systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service enabled enabled systemd-pcrphase-initrd.service static - systemd-pcrphase-sysinit.service static - systemd-pcrphase.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysupdate-reboot.service indirect disabled systemd-sysupdate.service indirect disabled systemd-sysusers.service static - systemd-timedated.service static - systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-vconsole-setup.service static - systemd-volatile-root.service static - teamd@.service static - tuned.service enabled enabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - system-cockpithttps.slice static - system-systemd\x2dcryptsetup.slice static - user.slice static - cloud-init-hotplugd.socket disabled disabled cockpit-wsinstance-http.socket static - cockpit-wsinstance-https-factory.socket static - cockpit-wsinstance-https@.socket static - cockpit.socket disabled disabled dbus.socket enabled enabled dm-event.socket enabled enabled lvm2-lvmpolld.socket enabled enabled podman.socket disabled disabled rpcbind.socket enabled enabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cloud-config.target static - cloud-init.target enabled-runtime disabled cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - emergency.target static - exit.target disabled disabled factory-reset.target static - final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd-usr-fs.target static - initrd.target static - integritysetup-pre.target static - integritysetup.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target enabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer disabled disabled fwupd-refresh.timer disabled disabled insights-client.timer disabled disabled logrotate.timer enabled enabled podman-auto-update.timer disabled disabled sysstat-collect.timer enabled disabled sysstat-summary.timer enabled disabled systemd-sysupdate-reboot.timer disabled disabled systemd-sysupdate.timer disabled disabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 358 unit files listed. 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:26Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:26Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:26Z DEBUG Starting external process 2025-10-14T07:57:26Z DEBUG args=['/usr/bin/authselect', 'select', 'sssd', 'with-sudo', '--force', '--backup=pre_ipaclient_20251014075726'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout=Backup stored at /var/lib/authselect/backups/pre_ipaclient_20251014075726 Profile "sssd" was selected. The following nsswitch maps are overwritten by the profile: - passwd - group - netgroup - automount - services - sudoers Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:26Z INFO SSSD enabled 2025-10-14T07:57:26Z DEBUG Starting external process 2025-10-14T07:57:26Z DEBUG args=['/bin/systemctl', 'restart', 'sssd.service'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout= 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:26Z DEBUG Starting external process 2025-10-14T07:57:26Z DEBUG args=['/bin/systemctl', 'is-active', 'sssd.service'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout=active 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:26Z DEBUG Restart of sssd.service complete 2025-10-14T07:57:26Z DEBUG Starting external process 2025-10-14T07:57:26Z DEBUG args=['/bin/systemctl', 'enable', 'sssd.service'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout= 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:26Z DEBUG Backing up system configuration file '/etc/openldap/ldap.conf' 2025-10-14T07:57:26Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:26Z DEBUG Updating configuration file /etc/openldap/ldap.conf 2025-10-14T07:57:26Z DEBUG # File modified by ipa-client-install # We do not want to break your existing configuration, hence: # URI, BASE, and SASL_MECH # have been added if they were not set. # In case any of them were set, a comment has been inserted and # "# CONF_NAME modified by IPA" added to the line above. # To use IPA server with openLDAP tools, please comment out your # existing configuration for these options and uncomment the # corresponding lines generated by IPA. # # LDAP Defaults # # See ldap.conf(5) for details # This file should be world readable but not world writable. #BASE dc=example,dc=com #URI ldap://ldap.example.com ldap://ldap-master.example.com:666 #SIZELIMIT 12 #TIMELIMIT 15 #DEREF never # When no CA certificates are specified the Shared System Certificates # are in use. In order to have these available along with the ones specified # by TLS_CACERTDIR one has to include them explicitly: #TLS_CACERT /etc/pki/tls/cert.pem # System-wide Crypto Policies provide up to date cipher suite which should # be used unless one needs a finer grinded selection of ciphers. Hence, the # PROFILE=SYSTEM value represents the default behavior which is in place # when no explicit setting is used. (see openssl-ciphers(1) for more info) #TLS_CIPHER_SUITE PROFILE=SYSTEM # Turning this off breaks GSSAPI used with krb5 when rdns = false SASL_NOCANON on URI ldaps://ipa.ooo.test BASE dc=ooo,dc=test SASL_MECH GSSAPI 2025-10-14T07:57:26Z INFO Configured /etc/openldap/ldap.conf 2025-10-14T07:57:26Z DEBUG Starting external process 2025-10-14T07:57:26Z DEBUG args=['/usr/bin/getent', 'passwd', 'admin@ooo.test'] 2025-10-14T07:57:26Z DEBUG Process finished, return code=0 2025-10-14T07:57:26Z DEBUG stdout=admin:*:1464600000:1464600000:Administrator:/home/admin:/bin/bash 2025-10-14T07:57:26Z DEBUG stderr= 2025-10-14T07:57:27Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:27Z DEBUG Backing up system configuration file '/etc/ssh/ssh_config' 2025-10-14T07:57:27Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:27Z INFO Configured /etc/ssh/ssh_config 2025-10-14T07:57:27Z DEBUG Backing up system configuration file '/etc/ssh/sshd_config' 2025-10-14T07:57:27Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:27Z DEBUG Starting external process 2025-10-14T07:57:27Z DEBUG args=['/usr/sbin/sshd', '-t', '-f', '/dev/null', '-o', 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys', '-o', 'AuthorizedKeysCommandUser=nobody'] 2025-10-14T07:57:27Z DEBUG Process finished, return code=0 2025-10-14T07:57:27Z DEBUG stdout= 2025-10-14T07:57:27Z DEBUG stderr=main: sshd: ssh-rsa algorithm is disabled 2025-10-14T07:57:27Z INFO Configured /etc/ssh/sshd_config 2025-10-14T07:57:27Z DEBUG Starting external process 2025-10-14T07:57:27Z DEBUG args=['/bin/systemctl', 'is-active', 'sshd.service'] 2025-10-14T07:57:27Z DEBUG Process finished, return code=0 2025-10-14T07:57:27Z DEBUG stdout=active 2025-10-14T07:57:27Z DEBUG stderr= 2025-10-14T07:57:27Z DEBUG Starting external process 2025-10-14T07:57:27Z DEBUG args=['/bin/systemctl', 'restart', 'sshd.service'] 2025-10-14T07:57:27Z DEBUG Process finished, return code=0 2025-10-14T07:57:27Z DEBUG stdout= 2025-10-14T07:57:27Z DEBUG stderr= 2025-10-14T07:57:27Z DEBUG Starting external process 2025-10-14T07:57:27Z DEBUG args=['/bin/systemctl', 'is-active', 'sshd.service'] 2025-10-14T07:57:27Z DEBUG Process finished, return code=0 2025-10-14T07:57:27Z DEBUG stdout=active 2025-10-14T07:57:27Z DEBUG stderr= 2025-10-14T07:57:27Z DEBUG Restart of sshd.service complete 2025-10-14T07:57:29Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:29Z INFO Configuring ooo.test as NIS domain. 2025-10-14T07:57:29Z DEBUG Starting external process 2025-10-14T07:57:29Z DEBUG args=['/usr/bin/nisdomainname'] 2025-10-14T07:57:29Z DEBUG Process finished, return code=1 2025-10-14T07:57:29Z DEBUG stdout=nisdomainname: Local domain name not set 2025-10-14T07:57:29Z DEBUG stderr= 2025-10-14T07:57:29Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:29Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:29Z DEBUG Starting external process 2025-10-14T07:57:29Z DEBUG args=['/bin/systemctl', 'is-enabled', 'nis-domainname.service'] 2025-10-14T07:57:29Z DEBUG Process finished, return code=0 2025-10-14T07:57:29Z DEBUG stdout=enabled 2025-10-14T07:57:29Z DEBUG stderr= 2025-10-14T07:57:29Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:29Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2025-10-14T07:57:29Z DEBUG Starting external process 2025-10-14T07:57:29Z DEBUG args=['/bin/systemctl', 'enable', 'nis-domainname.service'] 2025-10-14T07:57:30Z DEBUG Process finished, return code=0 2025-10-14T07:57:30Z DEBUG stdout= 2025-10-14T07:57:30Z DEBUG stderr= 2025-10-14T07:57:30Z DEBUG Starting external process 2025-10-14T07:57:30Z DEBUG args=['/bin/systemctl', 'restart', 'nis-domainname.service'] 2025-10-14T07:57:30Z DEBUG Process finished, return code=0 2025-10-14T07:57:30Z DEBUG stdout= 2025-10-14T07:57:30Z DEBUG stderr= 2025-10-14T07:57:30Z DEBUG Starting external process 2025-10-14T07:57:30Z DEBUG args=['/bin/systemctl', 'is-active', 'nis-domainname.service'] 2025-10-14T07:57:30Z DEBUG Process finished, return code=0 2025-10-14T07:57:30Z DEBUG stdout=active 2025-10-14T07:57:30Z DEBUG stderr= 2025-10-14T07:57:30Z DEBUG Restart of nis-domainname.service complete 2025-10-14T07:57:31Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:31Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2025-10-14T07:57:31Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:31Z DEBUG Starting external process 2025-10-14T07:57:31Z DEBUG args=['/usr/sbin/selinuxenabled'] 2025-10-14T07:57:31Z DEBUG Process finished, return code=0 2025-10-14T07:57:31Z DEBUG stdout= 2025-10-14T07:57:31Z DEBUG stderr= 2025-10-14T07:57:31Z DEBUG Starting external process 2025-10-14T07:57:31Z DEBUG args=['/sbin/restorecon', '/etc/krb5.conf.d/freeipa'] 2025-10-14T07:57:31Z DEBUG Process finished, return code=0 2025-10-14T07:57:31Z DEBUG stdout= 2025-10-14T07:57:31Z DEBUG stderr= 2025-10-14T07:57:31Z DEBUG Starting external process 2025-10-14T07:57:31Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2025-10-14T07:57:31Z DEBUG Process finished, return code=0 2025-10-14T07:57:31Z DEBUG stdout=867487207 2025-10-14T07:57:31Z DEBUG stderr= 2025-10-14T07:57:31Z DEBUG Enabling persistent keyring CCACHE 2025-10-14T07:57:31Z DEBUG Writing Kerberos configuration to /etc/krb5.conf: 2025-10-14T07:57:31Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:31Z DEBUG Writing configuration file /etc/krb5.conf 2025-10-14T07:57:31Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = OOO.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] OOO.TEST = { kdc = ipa.ooo.test:88 master_kdc = ipa.ooo.test:88 admin_server = ipa.ooo.test:749 kpasswd_server = ipa.ooo.test:464 default_domain = ooo.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ooo.test = OOO.TEST ooo.test = OOO.TEST np0005486751.ooo.test = OOO.TEST 2025-10-14T07:57:31Z INFO Configured /etc/krb5.conf for IPA realm OOO.TEST 2025-10-14T07:57:32Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2025-10-14T07:57:32Z DEBUG Starting external process 2025-10-14T07:57:32Z DEBUG args=['/bin/systemctl', 'try-restart', 'certmonger.service'] 2025-10-14T07:57:32Z DEBUG Process finished, return code=0 2025-10-14T07:57:32Z DEBUG stdout= 2025-10-14T07:57:32Z DEBUG stderr= 2025-10-14T07:57:32Z DEBUG Starting external process 2025-10-14T07:57:32Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2025-10-14T07:57:32Z DEBUG Process finished, return code=3 2025-10-14T07:57:32Z DEBUG stdout=inactive 2025-10-14T07:57:32Z DEBUG stderr= 2025-10-14T07:57:32Z DEBUG Restart of certmonger.service complete