2021-09-07T14:12:57Z DEBUG Logging to /var/log/ipaclient-install.log 2021-09-07T14:12:57Z DEBUG ipa-client-install was invoked with arguments [] and options: {'unattended': True, 'principal': 'admin', 'prompt_password': False, 'on_master': False, 'ca_cert_files': None, 'force': False, 'configure_firefox': False, 'firefox_dir': None, 'keytab': None, 'mkhomedir': False, 'force_join': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': True, 'force_ntpd': False, 'nisdomain': None, 'no_nisdomain': True, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_sudo': False, 'no_dns_sshfp': False, 'kinit_attempts': None, 'request_cert': False, 'ip_addresses': None, 'all_ip_addresses': False, 'fixed_primary': False, 'permit': False, 'enable_dns_updates': True, 'no_krb5_offline_passwords': False, 'preserve_sssd': False, 'automount_location': None, 'domain_name': None, 'servers': None, 'realm_name': None, 'host_name': None, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False} 2021-09-07T14:12:57Z DEBUG IPA version 4.9.6-2.fc34 2021-09-07T14:12:57Z DEBUG IPA platform fedora 2021-09-07T14:12:57Z DEBUG IPA os-release Fedora 34 (Thirty Four) 2021-09-07T14:12:57Z DEBUG Starting external process 2021-09-07T14:12:57Z DEBUG args=['/usr/sbin/selinuxenabled'] 2021-09-07T14:12:57Z DEBUG Process finished, return code=0 2021-09-07T14:12:57Z DEBUG stdout= 2021-09-07T14:12:57Z DEBUG stderr= 2021-09-07T14:12:57Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-07T14:12:57Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:12:57Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:12:57Z DEBUG Starting external process 2021-09-07T14:12:57Z DEBUG args=['sudo', '-V'] 2021-09-07T14:12:57Z DEBUG Process finished, return code=0 2021-09-07T14:12:57Z DEBUG stdout=Sudo version 1.9.5p2 Configure options: --build=x86_64-redhat-linux-gnu --host=x86_64-redhat-linux-gnu --program-prefix= --disable-dependency-tracking --prefix=/usr --exec-prefix=/usr --bindir=/usr/bin --sbindir=/usr/sbin --sysconfdir=/etc --datadir=/usr/share --includedir=/usr/include --libdir=/usr/lib64 --libexecdir=/usr/libexec --localstatedir=/var --sharedstatedir=/var/lib --mandir=/usr/share/man --infodir=/usr/share/info --prefix=/usr --sbindir=/usr/sbin --libdir=/usr/lib64 --docdir=/usr/share/doc/sudo --enable-openssl --disable-root-mailer --with-logging=syslog --with-logfac=authpriv --with-pam --with-pam-login --with-editor=/bin/vi --with-env-editor --with-ignore-dot --with-tty-tickets --with-ldap --with-selinux --with-passprompt=[sudo] password for %p: --enable-python --with-linux-audit --with-sssd Sudoers policy plugin version 1.9.5p2 Sudoers file grammar version 48 Sudoers path: /etc/sudoers nsswitch path: /etc/nsswitch.conf ldap.conf path: /etc/ldap.conf ldap.secret path: /etc/ldap.secret Authentication methods: 'pam' Syslog facility if syslog is being used for logging: authpriv Syslog priority to use when user authenticates successfully: notice Syslog priority to use when user authenticates unsuccessfully: alert Ignore '.' in $PATH Send mail if the user is not in sudoers Lecture user the first time they run sudo Require users to authenticate by default Root may run sudo Always set $HOME to the target user's home directory Allow some information gathering to give useful error messages Visudo will honor the EDITOR environment variable Set the LOGNAME and USER environment variables Length at which to wrap log file lines (0 for no wrap): 80 Authentication timestamp timeout: 5.0 minutes Password prompt timeout: 5.0 minutes Number of tries to enter a password: 3 Umask to use or 0777 to use user's: 022 Path to mail program: /usr/sbin/sendmail Flags for mail program: -t Address to send mail to: root Subject line for mail messages: *** SECURITY information for %h *** Incorrect password message: Sorry, try again. Path to lecture status dir: /var/db/sudo/lectured Path to authentication timestamp dir: /run/sudo/ts Default password prompt: [sudo] password for %p: Default user to run commands as: root Value to override user's $PATH with: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/var/lib/snapd/snap/bin Path to the editor for use by visudo: /bin/vi When to require a password for 'list' pseudocommand: any When to require a password for 'verify' pseudocommand: all File descriptors >= 3 will be closed before executing a command Reset the environment to a default set of variables Environment variables to check for safety: TZ TERM LINGUAS LC_* LANGUAGE LANG COLORTERM Environment variables to remove: *=()* RUBYOPT RUBYLIB PYTHONUSERBASE PYTHONINSPECT PYTHONPATH PYTHONHOME TMPPREFIX ZDOTDIR READNULLCMD NULLCMD FPATH PERL5DB PERL5OPT PERL5LIB PERLLIB PERLIO_DEBUG JAVA_TOOL_OPTIONS SHELLOPTS BASHOPTS GLOBIGNORE PS4 BASH_ENV ENV TERMCAP TERMPATH TERMINFO_DIRS TERMINFO _RLD* LD_* PATH_LOCALE NLSPATH HOSTALIASES RES_OPTIONS LOCALDOMAIN CDPATH IFS Environment variables to preserve: XAUTHORITY _XKB_CHARSET LINGUAS LANGUAGE LC_ALL LC_TIME LC_TELEPHONE LC_PAPER LC_NUMERIC LC_NAME LC_MONETARY LC_MESSAGES LC_MEASUREMENT LC_IDENTIFICATION LC_COLLATE LC_CTYPE LC_ADDRESS LANG USERNAME QTDIR MAIL LS_COLORS KDEDIR HISTSIZE HOSTNAME DISPLAY COLORS Locale to use while parsing sudoers: C Compress I/O logs using zlib Directory in which to store input/output logs: /var/log/sudo-io File in which to store the input/output log: %{seq} Add an entry to the utmp/utmpx file when allocating a pty PAM service name to use: sudo PAM service name to use for login shells: sudo-i Attempt to establish PAM credentials for the target user Create a new PAM session for the command to run in Perform PAM account validation management Enable sudoers netgroup support Check parent directories for writability when editing files with sudoedit Query the group plugin for unknown system groups Allow commands to be run even if sudo cannot write to the audit log Allow commands to be run even if sudo cannot write to the log file Resolve groups in sudoers and match on the group ID, not the name Log entries larger than this value will be split into multiple syslog messages: 960 File mode to use for the I/O log files: 0600 Execute commands by file descriptor instead of by path: digest_only Type of authentication timestamp record: tty Ignore case when matching user names Ignore case when matching group names Log when a command is allowed by sudoers Log when a command is denied by sudoers Sudo log server timeout in seconds: 30 Enable SO_KEEPALIVE socket option on the socket connected to the logserver Verify that the log server's certificate is valid Set the pam remote user to the user running sudo The format of logs to produce: sudo Enable SELinux RBAC support Local IP address and netmask pairs: 192.168.121.105/255.255.255.0 2620:52:0:4968:2fff:de14:1579:2b9b/ffff:ffff:ffff:ffff:: fe80::c7f6:42d2:a4e9:51e3/ffff:ffff:ffff:ffff:: Sudoers I/O plugin version 1.9.5p2 Sudoers audit plugin version 1.9.5p2 2021-09-07T14:12:57Z DEBUG stderr= 2021-09-07T14:12:58Z DEBUG Deleting invalid keytab: '/etc/krb5.keytab'. 2021-09-07T14:12:58Z DEBUG [IPA Discovery] 2021-09-07T14:12:58Z DEBUG Starting IPA discovery with domain=None, servers=None, hostname=client095.ipa.test 2021-09-07T14:12:58Z DEBUG Start searching for LDAP SRV record in "ipa.test" (domain of the hostname) and its sub-domains 2021-09-07T14:12:58Z DEBUG Search DNS for SRV record of _ldap._tcp.ipa.test 2021-09-07T14:12:58Z DEBUG DNS record found: 0 100 389 server.ipa.test. 2021-09-07T14:12:58Z DEBUG [Kerberos realm search] 2021-09-07T14:12:58Z DEBUG Search DNS for TXT record of _kerberos.ipa.test 2021-09-07T14:12:58Z DEBUG DNS record found: "IPA.TEST" 2021-09-07T14:12:58Z DEBUG Search DNS for SRV record of _kerberos._udp.ipa.test 2021-09-07T14:12:58Z DEBUG DNS record found: 0 100 88 server.ipa.test. 2021-09-07T14:12:58Z DEBUG [LDAP server check] 2021-09-07T14:12:58Z DEBUG Verifying that server.ipa.test (realm IPA.TEST) is an IPA server 2021-09-07T14:12:58Z DEBUG Init LDAP connection to: ldap://server.ipa.test:389 2021-09-07T14:12:58Z DEBUG Search LDAP server for IPA base DN 2021-09-07T14:12:59Z DEBUG Check if naming context 'dc=ipa,dc=test' is for IPA 2021-09-07T14:13:00Z DEBUG Naming context 'dc=ipa,dc=test' is a valid IPA context 2021-09-07T14:13:00Z DEBUG Search for (objectClass=krbRealmContainer) in dc=ipa,dc=test (sub) 2021-09-07T14:13:10Z DEBUG Found: cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2021-09-07T14:13:10Z DEBUG Discovery result: Success; server=server.ipa.test, domain=ipa.test, kdc=server.ipa.test, basedn=dc=ipa,dc=test 2021-09-07T14:13:10Z DEBUG Validated servers: server.ipa.test 2021-09-07T14:13:10Z DEBUG will use discovered domain: ipa.test 2021-09-07T14:13:10Z DEBUG Start searching for LDAP SRV record in "ipa.test" (Validating DNS Discovery) and its sub-domains 2021-09-07T14:13:10Z DEBUG Search DNS for SRV record of _ldap._tcp.ipa.test 2021-09-07T14:13:10Z DEBUG DNS record found: 0 100 389 server.ipa.test. 2021-09-07T14:13:10Z DEBUG DNS validated, enabling discovery 2021-09-07T14:13:10Z DEBUG will use discovered server: server.ipa.test 2021-09-07T14:13:10Z INFO Discovery was successful! 2021-09-07T14:13:10Z DEBUG will use discovered realm: IPA.TEST 2021-09-07T14:13:10Z DEBUG will use discovered basedn: dc=ipa,dc=test 2021-09-07T14:13:10Z INFO Client hostname: client095.ipa.test 2021-09-07T14:13:10Z DEBUG Hostname source: Machine's FQDN 2021-09-07T14:13:10Z INFO Realm: IPA.TEST 2021-09-07T14:13:10Z DEBUG Realm source: Discovered from LDAP DNS records in server.ipa.test 2021-09-07T14:13:10Z INFO DNS Domain: ipa.test 2021-09-07T14:13:10Z DEBUG DNS Domain source: Discovered LDAP SRV records from ipa.test (domain of the hostname) 2021-09-07T14:13:10Z INFO IPA Server: server.ipa.test 2021-09-07T14:13:10Z DEBUG IPA Server source: Discovered from LDAP DNS records in server.ipa.test 2021-09-07T14:13:10Z INFO BaseDN: dc=ipa,dc=test 2021-09-07T14:13:10Z DEBUG BaseDN source: From IPA server ldap://server.ipa.test:389 2021-09-07T14:13:10Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-07T14:13:10Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:13:10Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:13:10Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:13:10Z DEBUG Starting external process 2021-09-07T14:13:10Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '-k', '/etc/krb5.keytab', '-r', 'IPA.TEST'] 2021-09-07T14:13:10Z DEBUG Process finished, return code=7 2021-09-07T14:13:10Z DEBUG stdout= 2021-09-07T14:13:10Z DEBUG stderr=Failed to set cursor 'No such file or directory' 2021-09-07T14:13:10Z INFO Skipping chrony configuration 2021-09-07T14:13:10Z DEBUG Starting external process 2021-09-07T14:13:10Z DEBUG args=['/usr/sbin/selinuxenabled'] 2021-09-07T14:13:10Z DEBUG Process finished, return code=0 2021-09-07T14:13:10Z DEBUG stdout= 2021-09-07T14:13:10Z DEBUG stderr= 2021-09-07T14:13:10Z DEBUG Starting external process 2021-09-07T14:13:10Z DEBUG args=['/sbin/restorecon', '/etc/krb5.conf.d/freeipa'] 2021-09-07T14:13:10Z DEBUG Process finished, return code=0 2021-09-07T14:13:10Z DEBUG stdout= 2021-09-07T14:13:10Z DEBUG stderr= 2021-09-07T14:13:10Z DEBUG Starting external process 2021-09-07T14:13:10Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2021-09-07T14:13:10Z DEBUG Process finished, return code=0 2021-09-07T14:13:10Z DEBUG stdout=689814766 2021-09-07T14:13:10Z DEBUG stderr= 2021-09-07T14:13:10Z DEBUG Enabling persistent keyring CCACHE 2021-09-07T14:13:10Z DEBUG Writing Kerberos configuration to /tmp/tmplch1km7o: 2021-09-07T14:13:10Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = IPA.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] IPA.TEST = { kdc = server.ipa.test:88 master_kdc = server.ipa.test:88 admin_server = server.ipa.test:749 kpasswd_server = server.ipa.test:464 default_domain = ipa.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ipa.test = IPA.TEST ipa.test = IPA.TEST client095.ipa.test = IPA.TEST 2021-09-07T14:13:10Z DEBUG Writing configuration file /tmp/tmplch1km7o 2021-09-07T14:13:10Z DEBUG #File modified by ipa-client-install includedir /etc/krb5.conf.d/ includedir /var/lib/sss/pubconf/krb5.include.d/ [libdefaults] default_realm = IPA.TEST dns_lookup_realm = false rdns = false dns_canonicalize_hostname = false dns_lookup_kdc = true ticket_lifetime = 24h forwardable = true udp_preference_limit = 0 default_ccache_name = KEYRING:persistent:%{uid} [realms] IPA.TEST = { kdc = server.ipa.test:88 master_kdc = server.ipa.test:88 admin_server = server.ipa.test:749 kpasswd_server = server.ipa.test:464 default_domain = ipa.test pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem } [domain_realm] .ipa.test = IPA.TEST ipa.test = IPA.TEST client095.ipa.test = IPA.TEST 2021-09-07T14:13:10Z DEBUG Initializing principal admin@IPA.TEST using password 2021-09-07T14:13:10Z DEBUG Starting external process 2021-09-07T14:13:10Z DEBUG args=['/usr/bin/kinit', 'admin@IPA.TEST', '-c', '/tmp/krbcc7dq142_o/ccache'] 2021-09-07T14:13:37Z DEBUG Process finished, return code=1 2021-09-07T14:13:37Z DEBUG stdout= 2021-09-07T14:13:37Z DEBUG stderr=kinit: Cannot contact any KDC for realm 'IPA.TEST' while getting initial credentials 2021-09-07T14:13:37Z INFO Please make sure the following ports are opened in the firewall settings: TCP: 80, 88, 389 UDP: 88 (at least one of TCP/UDP ports 88 has to be open) Also note that following ports are necessary for ipa-client working properly after enrollment: TCP: 464 UDP: 464, 123 (if NTP enabled) 2021-09-07T14:13:37Z ERROR Installation failed. Rolling back changes. 2021-09-07T14:13:37Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-07T14:13:37Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:13:37Z DEBUG Starting external process 2021-09-07T14:13:37Z DEBUG args=['/usr/sbin/ipa-client-automount', '--uninstall', '--debug'] 2021-09-07T14:13:51Z DEBUG Process finished, return code=2 2021-09-07T14:13:51Z DEBUG stdout=IPA client is not configured on this system 2021-09-07T14:13:51Z DEBUG stderr= 2021-09-07T14:13:51Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2021-09-07T14:13:51Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:13:52Z DEBUG Starting external process 2021-09-07T14:13:52Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/pki/nssdb', '-L', '-n', 'IPA Machine Certificate - client095.ipa.test', '-a', '-f', '/etc/pki/nssdb/pwdfile.txt'] 2021-09-07T14:14:07Z DEBUG Process finished, return code=255 2021-09-07T14:14:07Z DEBUG stdout= 2021-09-07T14:14:07Z DEBUG stderr=certutil: Could not find cert: IPA Machine Certificate - client095.ipa.test : PR_FILE_NOT_FOUND_ERROR: File not found 2021-09-07T14:14:07Z DEBUG Starting external process 2021-09-07T14:14:07Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2021-09-07T14:14:07Z DEBUG Process finished, return code=0 2021-09-07T14:14:07Z DEBUG stdout= 2021-09-07T14:14:07Z DEBUG stderr= 2021-09-07T14:14:07Z DEBUG Starting external process 2021-09-07T14:14:07Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2021-09-07T14:14:08Z DEBUG Process finished, return code=0 2021-09-07T14:14:08Z DEBUG stdout=active 2021-09-07T14:14:08Z DEBUG stderr= 2021-09-07T14:14:08Z DEBUG Start of certmonger.service complete 2021-09-07T14:14:09Z DEBUG Starting external process 2021-09-07T14:14:10Z DEBUG args=['/bin/systemctl', 'stop', 'certmonger.service'] 2021-09-07T14:14:11Z DEBUG Process finished, return code=0 2021-09-07T14:14:11Z DEBUG stdout= 2021-09-07T14:14:11Z DEBUG stderr= 2021-09-07T14:14:11Z DEBUG Stop of certmonger.service complete 2021-09-07T14:14:11Z DEBUG Starting external process 2021-09-07T14:14:11Z DEBUG args=['/bin/systemctl', 'disable', 'certmonger.service'] 2021-09-07T14:14:14Z DEBUG Process finished, return code=0 2021-09-07T14:14:14Z DEBUG stdout= 2021-09-07T14:14:14Z DEBUG stderr= 2021-09-07T14:14:15Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:15Z DEBUG Starting external process 2021-09-07T14:14:15Z DEBUG args=['/bin/systemctl', 'stop', 'oddjobd.service'] 2021-09-07T14:14:15Z DEBUG Process finished, return code=0 2021-09-07T14:14:15Z DEBUG stdout= 2021-09-07T14:14:15Z DEBUG stderr= 2021-09-07T14:14:15Z DEBUG Stop of oddjobd.service complete 2021-09-07T14:14:15Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:15Z DEBUG Starting external process 2021-09-07T14:14:15Z DEBUG args=['/bin/systemctl', 'disable', 'oddjobd.service'] 2021-09-07T14:14:30Z DEBUG Process finished, return code=0 2021-09-07T14:14:30Z DEBUG stdout= 2021-09-07T14:14:30Z DEBUG stderr= 2021-09-07T14:14:30Z INFO Disabling client Kerberos and LDAP configurations 2021-09-07T14:14:30Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:30Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:30Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:31Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:31Z DEBUG Starting external process 2021-09-07T14:14:31Z DEBUG args=['/usr/bin/authselect', 'select', 'sssd', '--force'] 2021-09-07T14:14:31Z DEBUG Process finished, return code=0 2021-09-07T14:14:31Z DEBUG stdout=Backup stored at /var/lib/authselect/backups/2021-09-07-14-14-31.UHWlsu Profile "sssd" was selected. The following nsswitch maps are overwritten by the profile: - passwd - group - netgroup - automount - services Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. 2021-09-07T14:14:31Z DEBUG stderr= 2021-09-07T14:14:31Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:31Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:31Z DEBUG Starting external process 2021-09-07T14:14:31Z DEBUG args=['/bin/systemctl', 'disable', 'nis-domainname.service'] 2021-09-07T14:14:49Z DEBUG Process finished, return code=0 2021-09-07T14:14:49Z DEBUG stdout= 2021-09-07T14:14:49Z DEBUG stderr= 2021-09-07T14:14:49Z DEBUG Starting external process 2021-09-07T14:14:49Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2021-09-07T14:14:52Z DEBUG Process finished, return code=0 2021-09-07T14:14:52Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET proc-sys-fs-binfmt_misc.automount static - -.mount generated - boot.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount masked disabled var-lib-nfs-rpc_pipefs.mount static - systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-6.scope transient - arp-ethers.service disabled disabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - blk-availability.service disabled disabled certmonger.service disabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled console-getty.service disabled disabled container-getty@.service static - cpupower.service disabled disabled crond.service enabled enabled dbus-broker.service enabled enabled dbus-org.fedoraproject.FirewallD1.service alias - dbus-org.freedesktop.home1.service alias - dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.oom1.service alias - dbus-org.freedesktop.portable1.service alias - dbus-org.freedesktop.resolve1.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dirsrv@.service disabled disabled dm-event.service static - dnf-makecache.service static - dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown.service static - emergency.service static - firewalld.service enabled enabled fstrim.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled haveged-switch-root.service disabled disabled haveged.service enabled disabled htcacheclean.service static - httpd-init.service static - httpd.service disabled disabled httpd@.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - ipa-ccache-sweep.service disabled disabled ipa-custodia.service disabled disabled ipa-dnskeysyncd.service disabled disabled ipa-epn.service disabled disabled ipa-healthcheck.service disabled disabled ipa-ods-exporter.service disabled disabled ipa-otpd@.service static - ipa.service disabled disabled kadmin.service disabled disabled kmod-static-nodes.service static - kprop.service disabled disabled krb5kdc.service disabled disabled ldconfig.service static - loadmodules.service disabled disabled logrotate.service static - lvm2-lvmpolld.service static - lvm2-monitor.service enabled enabled lvm2-pvscan@.service static - man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled memcached.service enabled disabled mlocate-updatedb.service static - modprobe@.service static - named-setup-rndc.service static - named.service disabled disabled NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled enabled NetworkManager.service enabled enabled nfs-blkmap.service disabled disabled nfs-convert.service enabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nftables.service disabled disabled nis-domainname.service disabled disabled nmb.service disabled disabled oddjobd.service disabled disabled ods-enforcerd.service disabled disabled ods-signerd.service disabled disabled pam_namespace.service static - pkcsslotd.service disabled disabled pki-tomcatd-nuxwdog@.service disabled disabled pki-tomcatd@.service disabled disabled polkit.service static - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service disabled disabled rpmdb-rebuild.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service disabled disabled smb.service disabled disabled sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service static - systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-homed-activate.service enabled disabled systemd-homed.service enabled enabled systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service disabled disabled systemd-networkd-wait-online.service disabled disabled systemd-networkd.service disabled disabled systemd-oomd.service enabled enabled systemd-portabled.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-resolved.service enabled enabled systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysusers.service static - systemd-time-wait-sync.service disabled disabled systemd-timedated.service static - systemd-timesyncd.service disabled disabled systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-userdbd.service indirect disabled systemd-vconsole-setup.service static - systemd-volatile-root.service static - systemd-zram-setup@.service static - tcsd.service disabled disabled tomcat.service disabled disabled tomcat@.service disabled disabled tuned.service enabled disabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - winbind.service disabled disabled system-systemd\x2dcryptsetup.slice static - user.slice static - dbus.socket enabled enabled dm-event.socket enabled enabled httpd.socket disabled disabled ipa-ods-exporter.socket disabled disabled ipa-otpd.socket disabled disabled lvm2-lvmpolld.socket enabled enabled rpcbind.socket disabled disabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-networkd.socket disabled disabled systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - systemd-userdbd.socket enabled enabled dev-mapper-fedora\x2dswap.swap generated - dev-zram0.swap generated - basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - dirsrv.target disabled disabled emergency.target static - exit.target disabled disabled final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - pki-tomcatd-nuxwdog.target disabled disabled pki-tomcatd.target disabled disabled poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target disabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer enabled enabled ipa-ccache-sweep.timer disabled disabled ipa-epn.timer disabled disabled ipa-healthcheck.timer disabled disabled logrotate.timer enabled enabled mlocate-updatedb.timer enabled enabled sysstat-collect.timer enabled enabled sysstat-summary.timer enabled enabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 342 unit files listed. 2021-09-07T14:14:52Z DEBUG stderr= 2021-09-07T14:14:52Z INFO nscd daemon is not installed, skip configuration 2021-09-07T14:14:52Z DEBUG Starting external process 2021-09-07T14:14:52Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full'] 2021-09-07T14:14:55Z DEBUG Process finished, return code=0 2021-09-07T14:14:55Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET proc-sys-fs-binfmt_misc.automount static - -.mount generated - boot.mount generated - dev-hugepages.mount static - dev-mqueue.mount static - proc-fs-nfsd.mount static - proc-sys-fs-binfmt_misc.mount disabled disabled sys-fs-fuse-connections.mount static - sys-kernel-config.mount static - sys-kernel-debug.mount static - sys-kernel-tracing.mount static - tmp.mount masked disabled var-lib-nfs-rpc_pipefs.mount static - systemd-ask-password-console.path static - systemd-ask-password-wall.path static - session-6.scope transient - arp-ethers.service disabled disabled auditd.service enabled enabled auth-rpcgss-module.service static - autofs.service disabled disabled autovt@.service alias - blk-availability.service disabled disabled certmonger.service disabled disabled chrony-wait.service disabled disabled chronyd.service enabled enabled console-getty.service disabled disabled container-getty@.service static - cpupower.service disabled disabled crond.service enabled enabled dbus-broker.service enabled enabled dbus-org.fedoraproject.FirewallD1.service alias - dbus-org.freedesktop.home1.service alias - dbus-org.freedesktop.hostname1.service alias - dbus-org.freedesktop.locale1.service alias - dbus-org.freedesktop.login1.service alias - dbus-org.freedesktop.nm-dispatcher.service alias - dbus-org.freedesktop.oom1.service alias - dbus-org.freedesktop.portable1.service alias - dbus-org.freedesktop.resolve1.service alias - dbus-org.freedesktop.timedate1.service alias - dbus.service alias - debug-shell.service disabled disabled dirsrv@.service disabled disabled dm-event.service static - dnf-makecache.service static - dracut-cmdline.service static - dracut-initqueue.service static - dracut-mount.service static - dracut-pre-mount.service static - dracut-pre-pivot.service static - dracut-pre-trigger.service static - dracut-pre-udev.service static - dracut-shutdown.service static - emergency.service static - firewalld.service enabled enabled fstrim.service static - getty@.service enabled enabled grub-boot-indeterminate.service static - grub2-systemd-integration.service static - gssproxy.service disabled disabled haveged-switch-root.service disabled disabled haveged.service enabled disabled htcacheclean.service static - httpd-init.service static - httpd.service disabled disabled httpd@.service disabled disabled import-state.service enabled enabled initrd-cleanup.service static - initrd-parse-etc.service static - initrd-switch-root.service static - initrd-udevadm-cleanup-db.service static - ipa-ccache-sweep.service disabled disabled ipa-custodia.service disabled disabled ipa-dnskeysyncd.service disabled disabled ipa-epn.service disabled disabled ipa-healthcheck.service disabled disabled ipa-ods-exporter.service disabled disabled ipa-otpd@.service static - ipa.service disabled disabled kadmin.service disabled disabled kmod-static-nodes.service static - kprop.service disabled disabled krb5kdc.service disabled disabled ldconfig.service static - loadmodules.service disabled disabled logrotate.service static - lvm2-lvmpolld.service static - lvm2-monitor.service enabled enabled lvm2-pvscan@.service static - man-db-cache-update.service static - man-db-restart-cache-update.service disabled disabled memcached.service enabled disabled mlocate-updatedb.service static - modprobe@.service static - named-setup-rndc.service static - named.service disabled disabled NetworkManager-dispatcher.service enabled enabled NetworkManager-wait-online.service enabled enabled NetworkManager.service enabled enabled nfs-blkmap.service disabled disabled nfs-convert.service enabled disabled nfs-idmapd.service static - nfs-mountd.service static - nfs-server.service disabled disabled nfs-utils.service static - nfsdcld.service static - nftables.service disabled disabled nis-domainname.service disabled disabled nmb.service disabled disabled oddjobd.service disabled disabled ods-enforcerd.service disabled disabled ods-signerd.service disabled disabled pam_namespace.service static - pkcsslotd.service disabled disabled pki-tomcatd-nuxwdog@.service disabled disabled pki-tomcatd@.service disabled disabled polkit.service static - qemu-guest-agent.service enabled enabled quotaon.service static - rc-local.service static - rdisc.service disabled disabled rescue.service static - rpc-gssd.service static - rpc-statd-notify.service static - rpc-statd.service static - rpcbind.service disabled disabled rpmdb-rebuild.service enabled enabled selinux-autorelabel-mark.service enabled enabled selinux-autorelabel.service static - selinux-check-proper-disable.service disabled disabled serial-getty@.service disabled disabled smb.service disabled disabled sshd-keygen@.service disabled disabled sshd.service enabled enabled sshd@.service static - sssd-autofs.service indirect disabled sssd-ifp.service static - sssd-kcm.service indirect disabled sssd-nss.service indirect disabled sssd-pac.service indirect disabled sssd-pam.service indirect disabled sssd-ssh.service indirect disabled sssd-sudo.service indirect disabled sssd.service enabled enabled sysstat-collect.service static - sysstat-summary.service static - sysstat.service enabled enabled system-update-cleanup.service static - systemd-ask-password-console.service static - systemd-ask-password-wall.service static - systemd-backlight@.service static - systemd-binfmt.service static - systemd-bless-boot.service static - systemd-boot-check-no-failures.service disabled disabled systemd-boot-system-token.service static - systemd-coredump@.service static - systemd-exit.service static - systemd-firstboot.service static - systemd-fsck-root.service static - systemd-fsck@.service static - systemd-halt.service static - systemd-hibernate-resume@.service static - systemd-hibernate.service static - systemd-homed-activate.service enabled disabled systemd-homed.service enabled enabled systemd-hostnamed.service static - systemd-hwdb-update.service static - systemd-hybrid-sleep.service static - systemd-initctl.service static - systemd-journal-catalog-update.service static - systemd-journal-flush.service static - systemd-journald.service static - systemd-journald@.service static - systemd-kexec.service static - systemd-localed.service static - systemd-logind.service static - systemd-machine-id-commit.service static - systemd-modules-load.service static - systemd-network-generator.service disabled disabled systemd-networkd-wait-online.service disabled disabled systemd-networkd.service disabled disabled systemd-oomd.service enabled enabled systemd-portabled.service static - systemd-poweroff.service static - systemd-pstore.service disabled enabled systemd-quotacheck.service static - systemd-random-seed.service static - systemd-reboot.service static - systemd-remount-fs.service enabled-runtime disabled systemd-repart.service static - systemd-resolved.service enabled enabled systemd-rfkill.service static - systemd-suspend-then-hibernate.service static - systemd-suspend.service static - systemd-sysctl.service static - systemd-sysext.service disabled disabled systemd-sysusers.service static - systemd-time-wait-sync.service disabled disabled systemd-timedated.service static - systemd-timesyncd.service disabled disabled systemd-tmpfiles-clean.service static - systemd-tmpfiles-setup-dev.service static - systemd-tmpfiles-setup.service static - systemd-udev-settle.service static - systemd-udev-trigger.service static - systemd-udevd.service static - systemd-update-done.service static - systemd-update-utmp-runlevel.service static - systemd-update-utmp.service static - systemd-user-sessions.service static - systemd-userdbd.service indirect disabled systemd-vconsole-setup.service static - systemd-volatile-root.service static - systemd-zram-setup@.service static - tcsd.service disabled disabled tomcat.service disabled disabled tomcat@.service disabled disabled tuned.service enabled disabled unbound-anchor.service static - user-runtime-dir@.service static - user@.service static - winbind.service disabled disabled system-systemd\x2dcryptsetup.slice static - user.slice static - dbus.socket enabled enabled dm-event.socket enabled enabled httpd.socket disabled disabled ipa-ods-exporter.socket disabled disabled ipa-otpd.socket disabled disabled lvm2-lvmpolld.socket enabled enabled rpcbind.socket disabled disabled sshd.socket disabled disabled sssd-autofs.socket disabled disabled sssd-kcm.socket enabled enabled sssd-nss.socket disabled disabled sssd-pac.socket disabled disabled sssd-pam-priv.socket disabled disabled sssd-pam.socket disabled disabled sssd-ssh.socket disabled disabled sssd-sudo.socket disabled disabled syslog.socket static - systemd-coredump.socket static - systemd-initctl.socket static - systemd-journald-audit.socket static - systemd-journald-dev-log.socket static - systemd-journald-varlink@.socket static - systemd-journald.socket static - systemd-journald@.socket static - systemd-networkd.socket disabled disabled systemd-rfkill.socket static - systemd-udevd-control.socket static - systemd-udevd-kernel.socket static - systemd-userdbd.socket enabled enabled dev-mapper-fedora\x2dswap.swap generated - dev-zram0.swap generated - basic.target static - blockdev@.target static - bluetooth.target static - boot-complete.target static - cryptsetup-pre.target static - cryptsetup.target static - ctrl-alt-del.target alias - default.target alias - dirsrv.target disabled disabled emergency.target static - exit.target disabled disabled final.target static - first-boot-complete.target static - getty-pre.target static - getty.target static - graphical.target static - halt.target disabled disabled hibernate.target static - hybrid-sleep.target static - initrd-fs.target static - initrd-root-device.target static - initrd-root-fs.target static - initrd-switch-root.target static - initrd.target static - kexec.target disabled disabled local-fs-pre.target static - local-fs.target static - multi-user.target indirect disabled network-online.target static - network-pre.target static - network.target static - nfs-client.target enabled disabled nss-lookup.target static - nss-user-lookup.target static - paths.target static - pki-tomcatd-nuxwdog.target disabled disabled pki-tomcatd.target disabled disabled poweroff.target disabled disabled printer.target static - reboot.target enabled enabled remote-cryptsetup.target disabled enabled remote-fs-pre.target static - remote-fs.target disabled enabled remote-veritysetup.target disabled disabled rescue.target static - rpc_pipefs.target static - rpcbind.target static - runlevel0.target alias - runlevel1.target alias - runlevel2.target alias - runlevel3.target alias - runlevel4.target alias - runlevel5.target alias - runlevel6.target alias - selinux-autorelabel.target static - shutdown.target static - sigpwr.target static - sleep.target static - slices.target static - smartcard.target static - sockets.target static - sound.target static - sshd-keygen.target static - suspend-then-hibernate.target static - suspend.target static - swap.target static - sysinit.target static - system-update-pre.target static - system-update.target static - time-set.target static - time-sync.target static - timers.target static - umount.target static - usb-gadget.target static - veritysetup-pre.target static - veritysetup.target static - dnf-makecache.timer enabled enabled fstrim.timer enabled enabled ipa-ccache-sweep.timer disabled disabled ipa-epn.timer disabled disabled ipa-healthcheck.timer disabled disabled logrotate.timer enabled enabled mlocate-updatedb.timer enabled enabled sysstat-collect.timer enabled enabled sysstat-summary.timer enabled enabled systemd-tmpfiles-clean.timer static - unbound-anchor.timer enabled enabled 342 unit files listed. 2021-09-07T14:14:55Z DEBUG stderr= 2021-09-07T14:14:55Z INFO nslcd daemon is not installed, skip configuration 2021-09-07T14:14:55Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:55Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state' 2021-09-07T14:14:55Z DEBUG -> no modules, removing file 2021-09-07T14:14:55Z INFO Client uninstall complete. 2021-09-07T14:14:56Z DEBUG File "/usr/lib/python3.9/site-packages/ipapython/admintool.py", line 180, in execute return_value = self.run() File "/usr/lib/python3.9/site-packages/ipapython/install/cli.py", line 342, in run return cfgr.run() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 360, in run return self.execute() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 386, in execute for rval in self._executor(): File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 655, in _configure next(executor) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 518, in _handle_exception self.__parent._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 515, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info) File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.9/site-packages/six.py", line 709, in reraise raise value File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.9/site-packages/ipapython/install/common.py", line 65, in _install for unused in self._installer(self.parent): File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 3949, in main install(self) File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 2649, in install _install(options) File "/usr/lib/python3.9/site-packages/ipaclient/install/client.py", line 2783, in _install raise ScriptError( 2021-09-07T14:14:56Z DEBUG The ipa-client-install command failed, exception: ScriptError: Kerberos authentication failed: kinit: Cannot contact any KDC for realm 'IPA.TEST' while getting initial credentials 2021-09-07T14:14:56Z ERROR Kerberos authentication failed: kinit: Cannot contact any KDC for realm 'IPA.TEST' while getting initial credentials 2021-09-07T14:14:56Z ERROR The ipa-client-install command failed. See /var/log/ipaclient-install.log for more information