2021-09-13T10:02:20Z DEBUG Logging to /var/log/ipaclient-install.log 2021-09-13T10:02:20Z DEBUG ipa-client-install was invoked with arguments [] and options: {'unattended': True, 'principal': 'admin', 'prompt_password': False, 'on_master': False, 'ca_cert_files': None, 'force': False, 'configure_firefox': False, 'firefox_dir': None, 'keytab': None, 'mkhomedir': False, 'force_join': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': True, 'force_ntpd': False, 'nisdomain': None, 'no_nisdomain': True, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_sudo': False, 'no_dns_sshfp': False, 'kinit_attempts': None, 'request_cert': False, 'ip_addresses': None, 'all_ip_addresses': False, 'fixed_primary': False, 'permit': False, 'enable_dns_updates': True, 'no_krb5_offline_passwords': False, 'preserve_sssd': False, 'automount_location': None, 'domain_name': None, 'servers': None, 'realm_name': None, 'host_name': None, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False} 2021-09-13T10:02:20Z DEBUG IPA version 4.9.6-2.fc34 2021-09-13T10:02:20Z DEBUG IPA platform fedora 2021-09-13T10:02:20Z DEBUG IPA os-release Fedora 34 (Cloud Edition) 2021-09-13T10:02:20Z DEBUG Starting external process 2021-09-13T10:02:20Z DEBUG args=['/usr/sbin/selinuxenabled'] 2021-09-13T10:02:20Z DEBUG Process finished, return code=0 2021-09-13T10:02:20Z DEBUG stdout= 2021-09-13T10:02:20Z DEBUG stderr= 2021-09-13T10:02:20Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-13T10:02:20Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:20Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:20Z DEBUG Starting external process 2021-09-13T10:02:20Z DEBUG args=['sudo', '-V'] 2021-09-13T10:02:20Z DEBUG Process finished, return code=0 2021-09-13T10:02:20Z DEBUG stdout=Sudo version 1.9.5p2 Configure options: --build=x86_64-redhat-linux-gnu --host=x86_64-redhat-linux-gnu --program-prefix= --disable-dependency-tracking --prefix=/usr --exec-prefix=/usr --bindir=/usr/bin --sbindir=/usr/sbin --sysconfdir=/etc --datadir=/usr/share --includedir=/usr/include --libdir=/usr/lib64 --libexecdir=/usr/libexec --localstatedir=/var --sharedstatedir=/var/lib --mandir=/usr/share/man --infodir=/usr/share/info --prefix=/usr --sbindir=/usr/sbin --libdir=/usr/lib64 --docdir=/usr/share/doc/sudo --enable-openssl --disable-root-mailer --with-logging=syslog --with-logfac=authpriv --with-pam --with-pam-login --with-editor=/bin/vi --with-env-editor --with-ignore-dot --with-tty-tickets --with-ldap --with-selinux --with-passprompt=[sudo] password for %p: --enable-python --with-linux-audit --with-sssd Sudoers policy plugin version 1.9.5p2 Sudoers file grammar version 48 Sudoers path: /etc/sudoers nsswitch path: /etc/nsswitch.conf ldap.conf path: /etc/ldap.conf ldap.secret path: /etc/ldap.secret Authentication methods: 'pam' Syslog facility if syslog is being used for logging: authpriv Syslog priority to use when user authenticates successfully: notice Syslog priority to use when user authenticates unsuccessfully: alert Ignore '.' in $PATH Send mail if the user is not in sudoers Lecture user the first time they run sudo Require users to authenticate by default Root may run sudo Always set $HOME to the target user's home directory Allow some information gathering to give useful error messages Visudo will honor the EDITOR environment variable Set the LOGNAME and USER environment variables Length at which to wrap log file lines (0 for no wrap): 80 Authentication timestamp timeout: 5.0 minutes Password prompt timeout: 5.0 minutes Number of tries to enter a password: 3 Umask to use or 0777 to use user's: 022 Path to mail program: /usr/sbin/sendmail Flags for mail program: -t Address to send mail to: root Subject line for mail messages: *** SECURITY information for %h *** Incorrect password message: Sorry, try again. Path to lecture status dir: /var/db/sudo/lectured Path to authentication timestamp dir: /run/sudo/ts Default password prompt: [sudo] password for %p: Default user to run commands as: root Value to override user's $PATH with: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/var/lib/snapd/snap/bin Path to the editor for use by visudo: /bin/vi When to require a password for 'list' pseudocommand: any When to require a password for 'verify' pseudocommand: all File descriptors >= 3 will be closed before executing a command Reset the environment to a default set of variables Environment variables to check for safety: TZ TERM LINGUAS LC_* LANGUAGE LANG COLORTERM Environment variables to remove: *=()* RUBYOPT RUBYLIB PYTHONUSERBASE PYTHONINSPECT PYTHONPATH PYTHONHOME TMPPREFIX ZDOTDIR READNULLCMD NULLCMD FPATH PERL5DB PERL5OPT PERL5LIB PERLLIB PERLIO_DEBUG JAVA_TOOL_OPTIONS SHELLOPTS BASHOPTS GLOBIGNORE PS4 BASH_ENV ENV TERMCAP TERMPATH TERMINFO_DIRS TERMINFO _RLD* LD_* PATH_LOCALE NLSPATH HOSTALIASES RES_OPTIONS LOCALDOMAIN CDPATH IFS Environment variables to preserve: XAUTHORITY _XKB_CHARSET LINGUAS LANGUAGE LC_ALL LC_TIME LC_TELEPHONE LC_PAPER LC_NUMERIC LC_NAME LC_MONETARY LC_MESSAGES LC_MEASUREMENT LC_IDENTIFICATION LC_COLLATE LC_CTYPE LC_ADDRESS LANG USERNAME QTDIR MAIL LS_COLORS KDEDIR HISTSIZE HOSTNAME DISPLAY COLORS Locale to use while parsing sudoers: C Compress I/O logs using zlib Directory in which to store input/output logs: /var/log/sudo-io File in which to store the input/output log: %{seq} Add an entry to the utmp/utmpx file when allocating a pty PAM service name to use: sudo PAM service name to use for login shells: sudo-i Attempt to establish PAM credentials for the target user Create a new PAM session for the command to run in Perform PAM account validation management Enable sudoers netgroup support Check parent directories for writability when editing files with sudoedit Query the group plugin for unknown system groups Allow commands to be run even if sudo cannot write to the audit log Allow commands to be run even if sudo cannot write to the log file Resolve groups in sudoers and match on the group ID, not the name Log entries larger than this value will be split into multiple syslog messages: 960 File mode to use for the I/O log files: 0600 Execute commands by file descriptor instead of by path: digest_only Type of authentication timestamp record: tty Ignore case when matching user names Ignore case when matching group names Log when a command is allowed by sudoers Log when a command is denied by sudoers Sudo log server timeout in seconds: 30 Enable SO_KEEPALIVE socket option on the socket connected to the logserver Verify that the log server's certificate is valid Set the pam remote user to the user running sudo The format of logs to produce: sudo Enable SELinux RBAC support Local IP address and netmask pairs: 192.168.121.105/255.255.255.0 10.73.105.167/255.255.254.0 fe80::3d1d:e368:1602:33d2/ffff:ffff:ffff:ffff:: fe80::5054:ff:fe21:a01a/ffff:ffff:ffff:ffff:: Sudoers I/O plugin version 1.9.5p2 Sudoers audit plugin version 1.9.5p2 2021-09-13T10:02:20Z DEBUG stderr= 2021-09-13T10:02:20Z DEBUG Deleting invalid keytab: '/etc/krb5.keytab'. 2021-09-13T10:02:20Z DEBUG [IPA Discovery] 2021-09-13T10:02:20Z DEBUG Starting IPA discovery with domain=None, servers=None, hostname=client141.ipa.test 2021-09-13T10:02:20Z DEBUG Start searching for LDAP SRV record in "ipa.test" (domain of the hostname) and its sub-domains 2021-09-13T10:02:20Z DEBUG Search DNS for SRV record of _ldap._tcp.ipa.test 2021-09-13T10:02:20Z DEBUG DNS record found: 0 100 389 server.ipa.test. 2021-09-13T10:02:20Z DEBUG [Kerberos realm search] 2021-09-13T10:02:20Z DEBUG Search DNS for TXT record of _kerberos.ipa.test 2021-09-13T10:02:20Z DEBUG DNS record found: "IPA.TEST" 2021-09-13T10:02:20Z DEBUG Search DNS for SRV record of _kerberos._udp.ipa.test 2021-09-13T10:02:20Z DEBUG DNS record found: 0 100 88 server.ipa.test. 2021-09-13T10:02:20Z DEBUG [LDAP server check] 2021-09-13T10:02:20Z DEBUG Verifying that server.ipa.test (realm IPA.TEST) is an IPA server 2021-09-13T10:02:20Z DEBUG Init LDAP connection to: ldap://server.ipa.test:389 2021-09-13T10:02:20Z DEBUG Search LDAP server for IPA base DN 2021-09-13T10:02:20Z DEBUG Check if naming context 'dc=ipa,dc=test' is for IPA 2021-09-13T10:02:20Z DEBUG Naming context 'dc=ipa,dc=test' is a valid IPA context 2021-09-13T10:02:20Z DEBUG Search for (objectClass=krbRealmContainer) in dc=ipa,dc=test (sub) 2021-09-13T10:02:20Z DEBUG Found: cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2021-09-13T10:02:20Z DEBUG Discovery result: Success; server=server.ipa.test, domain=ipa.test, kdc=server.ipa.test, basedn=dc=ipa,dc=test 2021-09-13T10:02:20Z DEBUG Validated servers: server.ipa.test 2021-09-13T10:02:20Z DEBUG will use discovered domain: ipa.test 2021-09-13T10:02:20Z DEBUG Start searching for LDAP SRV record in "ipa.test" (Validating DNS Discovery) and its sub-domains 2021-09-13T10:02:20Z DEBUG Search DNS for SRV record of _ldap._tcp.ipa.test 2021-09-13T10:02:20Z DEBUG DNS record found: 0 100 389 server.ipa.test. 2021-09-13T10:02:20Z DEBUG DNS validated, enabling discovery 2021-09-13T10:02:20Z DEBUG will use discovered server: server.ipa.test 2021-09-13T10:02:20Z INFO Discovery was successful! 2021-09-13T10:02:20Z DEBUG will use discovered realm: IPA.TEST 2021-09-13T10:02:21Z DEBUG will use discovered basedn: dc=ipa,dc=test 2021-09-13T10:02:21Z INFO Client hostname: client141.ipa.test 2021-09-13T10:02:21Z DEBUG Hostname source: Machine's FQDN 2021-09-13T10:02:21Z INFO Realm: IPA.TEST 2021-09-13T10:02:21Z DEBUG Realm source: Discovered from LDAP DNS records in server.ipa.test 2021-09-13T10:02:21Z INFO DNS Domain: ipa.test 2021-09-13T10:02:21Z DEBUG DNS Domain source: Discovered LDAP SRV records from ipa.test (domain of the hostname) 2021-09-13T10:02:21Z INFO IPA Server: server.ipa.test 2021-09-13T10:02:21Z DEBUG IPA Server source: Discovered from LDAP DNS records in server.ipa.test 2021-09-13T10:02:21Z INFO BaseDN: dc=ipa,dc=test 2021-09-13T10:02:21Z DEBUG BaseDN source: From IPA server ldap://server.ipa.test:389 2021-09-13T10:02:21Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-13T10:02:21Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:21Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:21Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '-k', '/etc/krb5.keytab', '-r', 'IPA.TEST'] 2021-09-13T10:02:21Z DEBUG Process finished, return code=7 2021-09-13T10:02:21Z DEBUG stdout= 2021-09-13T10:02:21Z DEBUG stderr=Failed to set cursor 'No such file or directory' 2021-09-13T10:02:21Z INFO Skipping chrony configuration 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/usr/sbin/selinuxenabled'] 2021-09-13T10:02:21Z DEBUG Process finished, return code=0 2021-09-13T10:02:21Z DEBUG stdout= 2021-09-13T10:02:21Z DEBUG stderr= 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/sbin/restorecon', '/etc/krb5.conf.d/freeipa'] 2021-09-13T10:02:21Z DEBUG Process finished, return code=0 2021-09-13T10:02:21Z DEBUG stdout= 2021-09-13T10:02:21Z DEBUG stderr= 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2021-09-13T10:02:21Z DEBUG Process finished, return code=0 2021-09-13T10:02:21Z DEBUG stdout=284039728 2021-09-13T10:02:21Z DEBUG stderr= 2021-09-13T10:02:21Z DEBUG Enabling persistent keyring CCACHE 2021-09-13T10:02:21Z DEBUG Writing Kerberos configuration to /tmp/tmpyksks5q8: 2021-09-13T10:02:21Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = IPA.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] IPA.TEST = { kdc = server.ipa.test:88 master_kdc = server.ipa.test:88 admin_server = server.ipa.test:749 kpasswd_server = server.ipa.test:464 default_domain = ipa.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ipa.test = IPA.TEST ipa.test = IPA.TEST client141.ipa.test = IPA.TEST 2021-09-13T10:02:21Z DEBUG Writing configuration file /tmp/tmpyksks5q8 2021-09-13T10:02:21Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = IPA.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] IPA.TEST = { kdc = server.ipa.test:88 master_kdc = server.ipa.test:88 admin_server = server.ipa.test:749 kpasswd_server = server.ipa.test:464 default_domain = ipa.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ipa.test = IPA.TEST ipa.test = IPA.TEST client141.ipa.test = IPA.TEST 2021-09-13T10:02:21Z DEBUG Initializing principal admin@IPA.TEST using password 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/usr/bin/kinit', 'admin@IPA.TEST', '-c', '/tmp/krbccut6vmlc6/ccache'] 2021-09-13T10:02:21Z DEBUG Process finished, return code=0 2021-09-13T10:02:21Z DEBUG stdout=Password for admin@IPA.TEST: 2021-09-13T10:02:21Z DEBUG stderr= 2021-09-13T10:02:21Z DEBUG trying to retrieve CA cert via LDAP from server.ipa.test 2021-09-13T10:02:21Z DEBUG retrieving schema for SchemaCache url=ldap://server.ipa.test:389 conn= 2021-09-13T10:02:21Z INFO Successfully retrieved CA cert Subject: CN=Certificate Authority,O=IPA.TEST Issuer: CN=Certificate Authority,O=IPA.TEST Valid From: 2021-09-13 09:47:54 Valid Until: 2041-09-13 09:47:54 2021-09-13T10:02:21Z DEBUG Starting external process 2021-09-13T10:02:21Z DEBUG args=['/usr/sbin/ipa-join', '-s', 'server.ipa.test', '-b', 'dc=ipa,dc=test', '-h', 'client141.ipa.test', '-k', '/etc/krb5.keytab'] 2021-09-13T10:02:29Z DEBUG Process finished, return code=1 2021-09-13T10:02:29Z DEBUG stdout= 2021-09-13T10:02:29Z DEBUG stderr=cannot connect to 'ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket': 2021-09-13T10:02:29Z ERROR Joining realm failed: cannot connect to 'ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket': 2021-09-13T10:02:29Z ERROR Installation failed. Rolling back changes. 2021-09-13T10:02:29Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-13T10:02:29Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:29Z DEBUG Starting external process 2021-09-13T10:02:29Z DEBUG args=['/usr/sbin/ipa-client-automount', '--uninstall', '--debug'] 2021-09-13T10:02:29Z DEBUG Process finished, return code=2 2021-09-13T10:02:29Z DEBUG stdout=IPA client is not configured on this system 2021-09-13T10:02:29Z DEBUG stderr= 2021-09-13T10:02:29Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-13T10:02:29Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:29Z DEBUG Starting external process 2021-09-13T10:02:29Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/pki/nssdb', '-L', '-n', 'IPA Machine Certificate - client141.ipa.test', '-a', '-f', '/etc/pki/nssdb/pwdfile.txt'] 2021-09-13T10:02:32Z DEBUG Process finished, return code=255 2021-09-13T10:02:32Z DEBUG stdout= 2021-09-13T10:02:32Z DEBUG stderr=certutil: Could not find cert: IPA Machine Certificate - client141.ipa.test : PR_FILE_NOT_FOUND_ERROR: File not found 2021-09-13T10:02:32Z DEBUG Starting external process 2021-09-13T10:02:32Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2021-09-13T10:02:32Z DEBUG Process finished, return code=0 2021-09-13T10:02:32Z DEBUG stdout= 2021-09-13T10:02:32Z DEBUG stderr= 2021-09-13T10:02:32Z DEBUG Starting external process 2021-09-13T10:02:32Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2021-09-13T10:02:32Z DEBUG Process finished, return code=0 2021-09-13T10:02:32Z DEBUG stdout=active 2021-09-13T10:02:32Z DEBUG stderr= 2021-09-13T10:02:32Z DEBUG Start of certmonger.service complete 2021-09-13T10:02:33Z DEBUG Starting external process 2021-09-13T10:02:33Z DEBUG args=['/bin/systemctl', 'stop', 'certmonger.service'] 2021-09-13T10:02:33Z DEBUG Process finished, return code=0 2021-09-13T10:02:33Z DEBUG stdout= 2021-09-13T10:02:33Z DEBUG stderr= 2021-09-13T10:02:33Z DEBUG Stop of certmonger.service complete 2021-09-13T10:02:33Z DEBUG Starting external process 2021-09-13T10:02:33Z DEBUG args=['/bin/systemctl', 'disable', 'certmonger.service'] 2021-09-13T10:02:35Z DEBUG Process finished, return code=0 2021-09-13T10:02:35Z DEBUG stdout= 2021-09-13T10:02:35Z DEBUG stderr= 2021-09-13T10:02:35Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:35Z DEBUG Starting external process 2021-09-13T10:02:35Z DEBUG args=['/bin/systemctl', 'stop', 'oddjobd.service'] 2021-09-13T10:02:35Z DEBUG Process finished, return code=0 2021-09-13T10:02:35Z DEBUG stdout= 2021-09-13T10:02:35Z DEBUG stderr= 2021-09-13T10:02:35Z DEBUG Stop of oddjobd.service complete 2021-09-13T10:02:35Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:35Z DEBUG Starting external process 2021-09-13T10:02:35Z DEBUG args=['/bin/systemctl', 'disable', 'oddjobd.service'] 2021-09-13T10:02:36Z DEBUG Process finished, return code=0 2021-09-13T10:02:36Z DEBUG stdout= 2021-09-13T10:02:36Z DEBUG stderr= 2021-09-13T10:02:36Z INFO Disabling client Kerberos and LDAP configurations 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Starting external process 2021-09-13T10:02:36Z DEBUG args=['/usr/bin/authselect', 'select', 'sssd', '--force'] 2021-09-13T10:02:36Z DEBUG Process finished, return code=0 2021-09-13T10:02:36Z DEBUG stdout=Backup stored at /var/lib/authselect/backups/2021-09-13-10-02-36.2IiqfZ Profile "sssd" was selected. The following nsswitch maps are overwritten by the profile: - passwd - group - netgroup - automount - services Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. 2021-09-13T10:02:36Z DEBUG stderr= 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:36Z DEBUG Starting external process 2021-09-13T10:02:36Z DEBUG args=['/bin/systemctl', 'disable', 'nis-domainname.service'] 2021-09-13T10:02:37Z DEBUG Process finished, return code=0 2021-09-13T10:02:37Z DEBUG stdout= 2021-09-13T10:02:37Z DEBUG stderr= 2021-09-13T10:02:37Z DEBUG Starting external process 2021-09-13T10:02:37Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2021-09-13T10:02:38Z DEBUG Process finished, return code=0 2021-09-13T10:02:38Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET proc-sys-fs-binfmt_misc.automount static - -.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount static - var-lib-nfs-rpc_pipefs.mount static - systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-6.scope transient - arp-ethers.service disabled disabled atd.service enabled enabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - certmonger.service disabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled cloud-config.service masked disabled cloud-final.service masked disabled cloud-init-local.service masked disabled cloud-init.service masked disabled console-getty.service disabled disabled console-login-helper-messages-gensnippet-os-release.service disabled disabled console-login-helper-messages-gensnippet-ssh-keys.service disabled disabled container-getty@.service static - dbus-broker.service enabled enabled dbus-org.freedesktop.home1.service alias - dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.oom1.service alias - dbus-org.freedesktop.portable1.service alias - dbus-org.freedesktop.resolve1.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dnf-makecache.service static - dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown.service static - emergency.service static - fstrim.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - kmod-static-nodes.service static - ldconfig.service static - loadmodules.service disabled disabled logrotate.service static - man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled modprobe@.service static - NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled enabled NetworkManager.service enabled enabled nfs-blkmap.service disabled disabled nfs-convert.service enabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nis-domainname.service disabled disabled oddjobd.service disabled disabled pam_namespace.service static - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service disabled disabled rpmdb-rebuild.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service indirect disabled sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service enabled-runtime disabled systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-homed-activate.service enabled disabled systemd-homed.service enabled enabled systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service disabled disabled systemd-networkd-wait-online.service disabled disabled systemd-networkd.service disabled disabled systemd-oomd.service enabled enabled systemd-portabled.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-resolved.service enabled enabled systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysusers.service static - systemd-time-wait-sync.service disabled disabled systemd-timedated.service static - systemd-timesyncd.service disabled disabled systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-userdbd.service indirect disabled systemd-vconsole-setup.service static - systemd-volatile-root.service static - tcsd.service disabled disabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - system-systemd\x2dcryptsetup.slice static - user.slice static - dbus.socket enabled enabled rpcbind.socket disabled disabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-networkd.socket disabled disabled systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - systemd-userdbd.socket enabled enabled basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cloud-config.target static - cloud-init.target static - cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - emergency.target static - exit.target disabled disabled final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target enabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer enabled enabled logrotate.timer enabled enabled sysstat-collect.timer enabled enabled sysstat-summary.timer enabled enabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 291 unit files listed. 2021-09-13T10:02:38Z DEBUG stderr= 2021-09-13T10:02:38Z INFO nscd daemon is not installed, skip configuration 2021-09-13T10:02:38Z DEBUG Starting external process 2021-09-13T10:02:38Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2021-09-13T10:02:39Z DEBUG Process finished, return code=0 2021-09-13T10:02:39Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET proc-sys-fs-binfmt_misc.automount static - -.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount static - var-lib-nfs-rpc_pipefs.mount static - systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-6.scope transient - arp-ethers.service disabled disabled atd.service enabled enabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - certmonger.service disabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled cloud-config.service masked disabled cloud-final.service masked disabled cloud-init-local.service masked disabled cloud-init.service masked disabled console-getty.service disabled disabled console-login-helper-messages-gensnippet-os-release.service disabled disabled console-login-helper-messages-gensnippet-ssh-keys.service disabled disabled container-getty@.service static - dbus-broker.service enabled enabled dbus-org.freedesktop.home1.service alias - dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.oom1.service alias - dbus-org.freedesktop.portable1.service alias - dbus-org.freedesktop.resolve1.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dnf-makecache.service static - dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown.service static - emergency.service static - fstrim.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - kmod-static-nodes.service static - ldconfig.service static - loadmodules.service disabled disabled logrotate.service static - man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled modprobe@.service static - NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled enabled NetworkManager.service enabled enabled nfs-blkmap.service disabled disabled nfs-convert.service enabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nis-domainname.service disabled disabled oddjobd.service disabled disabled pam_namespace.service static - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service disabled disabled rpmdb-rebuild.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service indirect disabled sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service enabled-runtime disabled systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-homed-activate.service enabled disabled systemd-homed.service enabled enabled systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service disabled disabled systemd-networkd-wait-online.service disabled disabled systemd-networkd.service disabled disabled systemd-oomd.service enabled enabled systemd-portabled.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-resolved.service enabled enabled systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysusers.service static - systemd-time-wait-sync.service disabled disabled systemd-timedated.service static - systemd-timesyncd.service disabled disabled systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-userdbd.service indirect disabled systemd-vconsole-setup.service static - systemd-volatile-root.service static - tcsd.service disabled disabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - system-systemd\x2dcryptsetup.slice static - user.slice static - dbus.socket enabled enabled rpcbind.socket disabled disabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-networkd.socket disabled disabled systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - systemd-userdbd.socket enabled enabled basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cloud-config.target static - cloud-init.target static - cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - emergency.target static - exit.target disabled disabled final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target enabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer enabled enabled logrotate.timer enabled enabled sysstat-collect.timer enabled enabled sysstat-summary.timer enabled enabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 291 unit files listed. 2021-09-13T10:02:39Z DEBUG stderr= 2021-09-13T10:02:39Z INFO nslcd daemon is not installed, skip configuration 2021-09-13T10:02:39Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:39Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-13T10:02:39Z DEBUG -> no modules, removing file 2021-09-13T10:02:39Z INFO Client uninstall complete. 2021-09-13T10:02:39Z DEBUG File "/usr/lib/python3.9/site-packages/ipapython/admintool.py", line 180, in execute return_value = self.run() File "/usr/lib/python3.9/site-packages/ipapython/install/cli.py", line 342, in run return cfgr.run() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 360, in run return self.execute() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 386, in execute for rval in self._executor(): File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 655, in _configure next(executor) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 518, in _handle_exception self.__parent._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 515, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.9/site-packages/ipapython/install/common.py", line 65, in _install for unused in self._installer(self.parent): File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 3949, in main install(self) File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 2649, in install _install(options) File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 2853, in _install raise ScriptError(rval=CLIENT_INSTALL_ERROR) 2021-09-13T10:02:39Z DEBUG The ipa-client-install command failed, exception: ScriptError: 2021-09-13T10:02:39Z ERROR The ipa-client-install command failed. See /var/log/ipaclient-install.log for more information