Hi Lukas, Martin, Looks I've implemented the approach proposed by Martin. The issue seems to have gone (see the external_ca_out for external_ca test output). Would like you to take a look and tell me what'd you think.
On 03/17/2016 08:37 PM, Lukas Slebodnik wrote: > On (17/03/16 16:00), Oleg Fayans wrote: >> Hi Lukas, >> >> On 03/17/2016 11:28 AM, Lukas Slebodnik wrote: >>> On (10/03/16 23:09), Oleg Fayans wrote: >>>> Hi Martin, >>>> >>>> >>>> >>>> On 03/08/2016 08:18 PM, Martin Basti wrote: >>>>> >>>>> >>>>> On 08.03.2016 18:24, Martin Basti wrote: >>>>>> >>>>>> >>>>>> On 08.03.2016 12:38, Oleg Fayans wrote: >>>>>>> The patches were rebased against the current master >>>>>>> >>>>>>> On 03/04/2016 05:33 PM, Martin Basti wrote: >>>>>>>> * old messages have been removed * >>>>>>>>>>>> 1) >>>>>>>>>>>> this method is unused please remove it >>>>>>>>>>>> >>>>>>>>>>>> def test_kra_install_master(self): >>>>>>>>> Well, in fact it is used twice: in both domain levels, so I'd better >>>>>>>>> keep it: >>>>>>>>> >>>>>>>>> -bash-4.3$ ipa-run-tests test_integration/test_replica_promotion.py >>>>>>>>> --collect-only >>>>>>>>> ==================================================================================== >>>>>>>>> >>>>>>>>> >>>>>>>>> test session starts >>>>>>>>> ===================================================================================== >>>>>>>>> >>>>>>>>> >>>>>>>>> platform linux2 -- Python 2.7.10 -- py-1.4.30 -- pytest-2.7.3 >>>>>>>>> rootdir: /usr/lib/python2.7/site-packages/ipatests, inifile: >>>>>>>>> pytest.ini >>>>>>>>> plugins: sourceorder, multihost >>>>>>>>> collected 8 items >>>>>>>>> <Module 'test_integration/test_replica_promotion.py'> >>>>>>>>> <Class 'TestReplicaPromotionLevel0'> >>>>>>>>> <Instance '()'> >>>>>>>>> <Function 'test_kra_install_master'> >>>>>>>>> <Function 'test_promotion_disabled'> >>>>>>>>> <Function 'test_backup_restore'> >>>>>>>>> <Class 'TestKRAInstall'> >>>>>>>>> <Instance '()'> >>>>>>>>> <Function 'test_kra_install_without_replica_file'> >>>>>>>>> <Class 'TestCAInstall'> >>>>>>>>> <Instance '()'> >>>>>>>>> <Function 'test_ca_install_without_replica_file'> >>>>>>>>> <Class 'TestReplicaPromotionLevel1'> >>>>>>>>> <Instance '()'> >>>>>>>>> <Function 'test_kra_install_master'> >>>>>>>>> <Function 'test_replica_prepare_disabled'> >>>>>>>>> <Class 'TestReplicaManageCommands'> >>>>>>>>> <Instance '()'> >>>>>>>>> <Function 'test_replica_manage_commands'> >>>>>>>> aah my bad, I forgot that pytest executes it when it begins with test_* >>>>>>>> even in parent class >>>>>>>>>>>> 2) >>>>>>>>>>>> Why are these there? I do not see any usage >>>>>>>>>>>> >>>>>>>>>>>> from env_config import get_global_config >>>>>>>>>>>> config = get_global_config() >>>>>>>>> Removed >>>>>>>>> >>>>>>>>>>>> 3) nitpick >>>>>>>>>>>> + num_clients = 0 >>>>>>>>>>>> this is set by default >>>>>>>>> Removed >>>>>>>>> >>>>>>>>>>>> otherwise LGTM >>>>>>>>>>>> >>>>>>>>>>>> Results of testing tomorrow. >>>>>>>>>>>> >>>>>>>>>>>> Martin^2 >>>>>>>>>>>> >>>>>>>>>>> I applied all patches including workarounds, but test failed. >>>>>>>>>>> >>>>>>>>>>> ipatests.test_integration.test_replica_promotion.TestReplicaPromotionLevel0 >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] RUN >>>>>>>>>>> ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', 'Secret123', >>>>>>>>>>> '--setup-ca', '--ip-address', '192.168.144.102', >>>>>>>>>>> '/root/ipatests/replica-info.gpg'] >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] The host >>>>>>>>>>> replica1.ipa.test already exists on the master server. >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] You should >>>>>>>>>>> remove it before proceeding: >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] % ipa >>>>>>>>>>> host-del replica1.ipa.test >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] >>>>>>>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR The >>>>>>>>>>> ipa-replica-install command failed. See >>>>>>>>>>> /var/log/ipareplica-install.log for more information >>>>>>>>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd51] Exit >>>>>>>>>>> code: 3 >>>>>>>>>>> FAILED >>>>>>>>> this is exactly the error that happens when a workaround for 5627 >>>>>>>>> is not >>>>>>>>> applied. I have re-run the tests with all the patches and everything >>>>>>>>> passed. Could you please double-check, whether patch 0027 was applied >>>>>>>>> correctly? >>>>>>>>> >>>>>>>>> bash-4.3$ ipa-run-tests test_integration/test_replica_promotion.py >>>>>>>>> --pdb >>>>>>>>> ==================================================================================== >>>>>>>>> >>>>>>>>> >>>>>>>>> test session starts >>>>>>>>> ===================================================================================== >>>>>>>>> >>>>>>>>> >>>>>>>>> platform linux2 -- Python 2.7.10 -- py-1.4.30 -- pytest-2.7.3 >>>>>>>>> rootdir: /usr/lib/python2.7/site-packages/ipatests, inifile: >>>>>>>>> pytest.ini >>>>>>>>> plugins: sourceorder, multihost >>>>>>>>> collected 8 items >>>>>>>>> >>>>>>>>> test_integration/test_replica_promotion.py ........ >>>>>>>>> >>>>>>>>> ================================================================================ >>>>>>>>> >>>>>>>>> >>>>>>>>> 8 passed in 7561.93 seconds >>>>>>>>> ================================================================================= >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>> I will >>>>>>>> >>>>>>>>>> And it needs ticket, otherwise it will not be in 4-3 branch. >>>>>>>>> https://fedorahosted.org/freeipa/ticket/5723 >>>>>> NACK >>>>>> >>>>>> 1) >>>>>> ipatests.test_integration.test_replica_promotion.TestReplicaPromotionLevel0 >>>>>> >>>>>> >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.ParamikoTransport] >>>>>> RUN ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', >>>>>> 'Secret123', '--setup-ca', '--ip-address', '192.168.200.103', '-r', >>>>>> 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] RUN >>>>>> ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', 'Secret123', >>>>>> '--setup-ca', '--ip-address', '192.168.200.103', '-r', 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] IPA client is >>>>>> already configured on this system, ignoring the --domain, --server, >>>>>> --realm, --hostname, --password and --keytab options. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] Your system >>>>>> may be partly configured. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] Run >>>>>> /usr/sbin/ipa-server-install --uninstall to clean up. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR You must >>>>>> provide a file generated by ipa-replica-prepare to create a replica >>>>>> when the domain is at level 0. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR The >>>>>> ipa-replica-install command failed. See >>>>>> /var/log/ipareplica-install.log for more information >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd65] Exit code: 1 >>>>>> FAILED >>>>>> >>>>>> 2) >>>>>> ipatests.test_integration.test_replica_promotion.TestKRAInstall >>>>>> >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.ParamikoTransport] >>>>>> RUN ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', >>>>>> 'Secret123', '--setup-ca', '--ip-address', '192.168.200.103', '-r', >>>>>> 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] RUN >>>>>> ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', 'Secret123', >>>>>> '--setup-ca', '--ip-address', '192.168.200.103', '-r', 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] IPA client is >>>>>> already configured on this system, ignoring the --domain, --server, >>>>>> --realm, --hostname, --password and --keytab options. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Your system >>>>>> may be partly configured. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Run >>>>>> /usr/sbin/ipa-server-install --uninstall to clean up. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR You must >>>>>> provide a file generated by ipa-replica-prepare to create a replica >>>>>> when the domain is at level 0. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR The >>>>>> ipa-replica-install command failed. See >>>>>> /var/log/ipareplica-install.log for more information >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Exit code: 1 >>>>>> FAILED >>>>>> >>>>>> >>>>>> 3) >>>>>> ipatests.test_integration.test_replica_promotion.TestCAInstall >>>>>> >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.ParamikoTransport] >>>>>> RUN ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', >>>>>> 'Secret123', '--setup-dns', '--forwarder', '10.34.78.1', >>>>>> '--ip-address', '192.168.200.103', '-r', 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] RUN >>>>>> ['ipa-replica-install', '-U', '-p', 'Secret123', '-w', 'Secret123', >>>>>> '--setup-dns', '--forwarder', '10.34.78.1', '--ip-address', >>>>>> '192.168.200.103', '-r', 'IPA.TEST'] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] IPA client is >>>>>> already configured on this system, ignoring the --domain, --server, >>>>>> --realm, --hostname, --password and --keytab options. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Your system >>>>>> may be partly configured. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Run >>>>>> /usr/sbin/ipa-server-install --uninstall to clean up. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR You must >>>>>> provide a file generated by ipa-replica-prepare to create a replica >>>>>> when the domain is at level 0. >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] >>>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR The >>>>>> ipa-replica-install command failed. See >>>>>> /var/log/ipareplica-install.log for more information >>>>>> [ipa.ipatests.test_integration.host.Host.replica2.cmd22] Exit code: 1 >>>>>> FAILED >>>>>> >>>>>> >>>>>> Reason: >>>>>> >>>>>> def install_replica(master, replica, setup_ca=True, setup_dns=False, >>>>>> - setup_kra=False, extra_args=()): >>>>>> + setup_kra=False, extra_args=(), domain_level=None): >>>>>> + if domain_level is None: >>>>>> + domain_level = domainlevel(master) >>>> >>>> Oops. Sorry, must have been a result of inaccurate rebase. Fixed >>>> The successful run is attached >>>> >>>>>> >>>>>> - if domainlevel(master) == DOMAIN_LEVEL_0: >>>>>> + if domainlevel == DOMAIN_LEVEL_0: >>>>>> >>>>>> domain_level variable is actually unused >>>>>> >>>>> Also with your patch that removes host_prepare, I see many following >>>>> errors in test debug output >>>>> >>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd8] -bash: line 1: >>>>> cd: /root/ipatests: No such file or directory >>>>> [ipa.ipatests.test_integration.host.Host.replica1.cmd8] -bash: line 2: >>>>> /root/ipatests/env.sh: No such file or directory >>>>> >>>>> >>>>> I do not see these errors in current tests, so the patch does not seem >>>>> right to me. >>>> >>>> http://jenkins.idm.lab.eng.brq.redhat.com:8080/job/freeipa-integration-f23master-customized_ds_config_install-domlevel-1/23/consoleFull >>>> >>>> I've been experimenting a lot to find get rid of it but was >>>> unsuccessful. Seemingly it does not affect the tests. >>>> >>> Oleg it looks like you broke something >>> in the test_integration/test_external_ca.py >>> >>> _______________________ TestExternalCA.test_external_ca >>> ________________________ >>> >>> self = <ipatests.test_integration.test_external_ca.TestExternalCA object at >>> 0x7ff560a51750> >>> >>> def test_external_ca(self): >>> # Step 1 of ipa-server-install >>> self.master.run_command([ >>> 'ipa-server-install', '-U', >>> '-a', self.master.config.admin_password, >>> '-p', self.master.config.dirman_password, >>> '--setup-dns', '--no-forwarders', >>> '-n', self.master.domain.name, >>> '-r', self.master.domain.realm, >>> '--domain-level=%i' % self.master.config.domain_level, >>> '--external-ca' >>> ]) >>> >>> nss_db = os.path.join(self.master.config.test_dir, 'testdb') >>> external_cert_file = os.path.join(nss_db, 'ipa.crt') >>> external_ca_file = os.path.join(nss_db, 'ca.crt') >>> noisefile = os.path.join(self.master.config.test_dir, 'noise.txt') >>> pwdfile = os.path.join(self.master.config.test_dir, 'pwdfile.txt') >>> >>> # Create noise and password files for NSS database >>>> self.master.run_command('date | sha256sum > %s' % noisefile) >>> >>> test_integration/test_external_ca.py:49: >>> _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ >>> _ _ >>> ../pytest_multihost/host.py:246: in run_command >>> command.wait(raiseonerr=raiseonerr) >>> _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ >>> _ _ >>> >>> self = <pytest_multihost.transport.SSHCommand object at 0x7ff5609eb610> >>> raiseonerr = True >>> >>> def wait(self, raiseonerr=True): >>> """Wait for the remote process to exit >>> >>> Raises an excption if the exit code is not 0, unless raiseonerr >>> is >>> true. >>> """ >>> if self._done: >>> return self.returncode >>> >>> self._end_process() >>> >>> self._done = True >>> >>> if raiseonerr and self.returncode: >>> self.log.error('Exit code: %s', self.returncode) >>>> raise subprocess.CalledProcessError(self.returncode, self.argv) >>> E CalledProcessError: Command 'date | sha256sum > >>> /root/ipatests/noise.txt' returned non-zero exit status 1 >>> >>> ../pytest_multihost/transport.py:159: CalledProcessError >>> ---------------------------- Captured stdout setup >>> ----------------------------- >>> <ipatests.test_integration.config.Config object at 0x7ff560a51cd0> >>> ========================== 1 failed in 32.25 seconds >>> =========================== >>> >>> >>> >>> The command "date | sha256sum > /root/ipatests/noise.txt" >>> >>> The only explanation is that the directory /root/ipatests/ does not exist. >> >> Obviously this is caused by my patch N 0025 >> freeipa-ofayans-0025-Removed-a-constantly-failing-call-to-prepare_host.patch >> >> Without it replica_promotion tests would fail. The only compromise I see >> is to remove this line in unapply_fixes function in >> ipatests/test_integration/tasks.py: >> >> host.run_command(['rm', '-rvf', host.config.test_dir]) >> >> Now the biggest question is: why do we keep removing the config folder >> anyway? All the files (backups of /etc/hosts, etc) that ever get there >> get overwritten each time anyway so it's quite safe to just keep the >> folder throughout the whole test execution. >> > I do not know why it was removed. IMHO it shoudl be enough > to remove just content of this directory. > > But it will bee godd to fix it ASAP > and unblock test test_integration/test_external_ca.py > I hope we want to have green test in 4.3 branch. > Please also open a ticket so it can be backported to > stable branch (if needed) > > LS > -- Oleg Fayans Quality Engineer FreeIPA team RedHat.
From 95b4d6eb0e541a7b1d092d26a2891f0ad5b8287d Mon Sep 17 00:00:00 2001 From: Oleg Fayans <[email protected]> Date: Mon, 21 Mar 2016 14:19:06 +0100 Subject: [PATCH] refactor the way the test folder is created/deleted in integration tests https://fedorahosted.org/freeipa/ticket/5748 --- ipatests/test_integration/base.py | 5 +++++ ipatests/test_integration/tasks.py | 12 ++++++++---- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/ipatests/test_integration/base.py b/ipatests/test_integration/base.py index ee271679912fa6218dcd91de61570f9d8fc09d06..a900e4c13e6c1c5e243a550c5d55af11dc4b0692 100644 --- a/ipatests/test_integration/base.py +++ b/ipatests/test_integration/base.py @@ -63,6 +63,8 @@ class IntegrationTest(object): @classmethod def install(cls, mh): + for host in cls.get_all_hosts(): + tasks.prepare_host(host) if cls.domain_level is not None: domain_level = cls.domain_level else: @@ -73,6 +75,7 @@ class IntegrationTest(object): tasks.install_topo(cls.topology, cls.master, cls.replicas, cls.clients, domain_level) + @classmethod def teardown_class(cls): pass @@ -84,6 +87,8 @@ class IntegrationTest(object): tasks.uninstall_master(replica) for client in cls.clients: tasks.uninstall_client(client) + for host in cls.get_all_hosts(): + tasks.unapply_fixes(host, rm_runfolder=True) IntegrationTest.log = log_mgr.get_logger(IntegrationTest()) diff --git a/ipatests/test_integration/tasks.py b/ipatests/test_integration/tasks.py index c2129708b5e75d9b492fb8b33784478b50122115..fb6e296e7fc2a1492ad1be16f36ef4c6b4a5acf4 100644 --- a/ipatests/test_integration/tasks.py +++ b/ipatests/test_integration/tasks.py @@ -81,7 +81,11 @@ def prepare_host(host): host.run_command(['true'], set_env=False) host.collect_log(env_filename) - host.transport.mkdir_recursive(host.config.test_dir) + try: + host.transport.mkdir_recursive(host.config.test_dir) + except IOError: + # The folder already exists + pass host.put_file_contents(env_filename, env_to_script(host.to_env())) @@ -94,7 +98,6 @@ def allow_sync_ptr(host): def apply_common_fixes(host): fix_etc_hosts(host) fix_hostname(host) - prepare_host(host) def backup_file(host, filename): @@ -164,12 +167,13 @@ def fix_apache_semaphores(master): 'do ipcrm -s $line; done', raiseonerr=False) -def unapply_fixes(host): +def unapply_fixes(host, rm_runfolder=False): restore_files(host) restore_hostname(host) # Clean up the test directory - host.run_command(['rm', '-rvf', host.config.test_dir]) + if rm_runfolder: + host.run_command(['rm', '-rvf', host.config.test_dir]) def restore_files(host): -- 1.8.3.1
============================= test session starts ============================== platform linux2 -- Python 2.7.10 -- py-1.4.30 -- pytest-2.7.3 rootdir: /usr/lib/python2.7/site-packages/ipatests, inifile: pytest.ini plugins: multihost, sourceorder collected 1 items test_integration/test_external_ca.py [ipa.ipatests.test_integration.base.IntegrationTest] Preparing host f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] Authenticating with private RSA key using user root [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['true'] [ipa.ipatests.test_integration.host.Host.f23master.cmd1] RUN ['true'] [ipa.ipatests.test_integration.host.Host.f23master.cmd1] -bash: line 1: cd: /home/ofayans/ipatests: No such file or directory [ipa.ipatests.test_integration.host.Host.f23master.cmd1] Exit code: 0 [ipa.ipatests.pytest_plugins.integration] Adding f23master.pesen.net:/home/ofayans/ipatests/env.sh to list of logs to collect [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] STAT /home/ofayans/ipatests [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] STAT /home/ofayans [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] MKDIR /home/ofayans/ipatests [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] WRITE /home/ofayans/ipatests/env.sh [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['true'] [ipa.ipatests.test_integration.host.Host.f23master.cmd2] RUN ['true'] [ipa.ipatests.test_integration.host.Host.f23master.cmd2] Exit code: 0 [ipa.ipatests.pytest_plugins.integration] Adding f23master.pesen.net:/home/ofayans/ipatests/env.sh to list of logs to collect [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] STAT /home/ofayans/ipatests [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] WRITE /home/ofayans/ipatests/env.sh [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['ipa-server-install', '-U', '-a', 'x2k1j5tdsl', '-p', 'x2k1j5tdsl', '--setup-dns', '--no-forwarders', '-n', 'pesen.net', '-r', 'PESEN.NET', '--domain-level=1', '--external-ca'] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] RUN ['ipa-server-install', '-U', '-a', 'x2k1j5tdsl', '-p', 'x2k1j5tdsl', '--setup-dns', '--no-forwarders', '-n', 'pesen.net', '-r', 'PESEN.NET', '--domain-level=1', '--external-ca'] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Checking DNS domain pesen.net, please wait ... [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] The log file for this installation can be found in /var/log/ipaserver-install.log [ipa.ipatests.test_integration.host.Host.f23master.cmd3] ============================================================================== [ipa.ipatests.test_integration.host.Host.f23master.cmd3] This program will set up the FreeIPA Server. [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] This includes: [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Configure a stand-alone CA (dogtag) for certificate management [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Configure the Network Time Daemon (ntpd) [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Create and configure an instance of Directory Server [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Create and configure a Kerberos Key Distribution Center (KDC) [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Configure Apache (httpd) [ipa.ipatests.test_integration.host.Host.f23master.cmd3] * Configure DNS (bind) [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Warning: skipping DNS resolution of host f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Checking DNS domain pesen.net., please wait ... [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] The IPA Master Server will be configured with: [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Hostname: f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd3] IP address(es): 192.168.122.63 [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Domain name: pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Realm name: PESEN.NET [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] BIND DNS server will be configured to serve IPA domain with: [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Forwarders: No forwarders [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Reverse zone(s): No reverse zone [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Configuring NTP daemon (ntpd) [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [1/4]: stopping ntpd [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [2/4]: writing configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [3/4]: configuring ntpd to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [4/4]: starting ntpd [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Done configuring NTP daemon (ntpd). [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Configuring directory server (dirsrv). Estimated time: 1 minute [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [1/46]: creating directory server user [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [2/46]: creating directory server instance [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [3/46]: restarting directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [4/46]: adding default schema [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [5/46]: enabling memberof plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [6/46]: enabling winsync plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [7/46]: configuring replication version plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [8/46]: enabling IPA enrollment plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [9/46]: enabling ldapi [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [10/46]: configuring uniqueness plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [11/46]: configuring uuid plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [12/46]: configuring modrdn plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [13/46]: configuring DNS plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [14/46]: enabling entryUSN plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [15/46]: configuring lockout plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [16/46]: configuring topology plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [17/46]: creating indices [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [18/46]: enabling referential integrity plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [19/46]: configuring certmap.conf [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [20/46]: configure autobind for root [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [21/46]: configure new location for managed entries [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [22/46]: configure dirsrv ccache [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [23/46]: enabling SASL mapping fallback [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [24/46]: restarting directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [25/46]: adding sasl mappings to the directory [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [26/46]: adding default layout [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [27/46]: adding delegation layout [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [28/46]: creating container for managed entries [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [29/46]: configuring user private groups [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [30/46]: configuring netgroups from hostgroups [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [31/46]: creating default Sudo bind user [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [32/46]: creating default Auto Member layout [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [33/46]: adding range check plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [34/46]: creating default HBAC rule allow_all [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [35/46]: adding sasl mappings to the directory [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [36/46]: adding entries for topology management [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [37/46]: initializing group membership [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [38/46]: adding master entry [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [39/46]: initializing domain level [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [40/46]: configuring Posix uid/gid generation [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [41/46]: adding replication acis [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [42/46]: enabling compatibility plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [43/46]: activating sidgen plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [44/46]: activating extdom plugin [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [45/46]: tuning directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [46/46]: configuring directory to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Done configuring directory server (dirsrv). [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 30 seconds [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [1/8]: creating certificate server user [ipa.ipatests.test_integration.host.Host.f23master.cmd3] [2/8]: configuring certificate server instance [ipa.ipatests.test_integration.host.Host.f23master.cmd3] The next step is to get /root/ipa.csr signed by your CA and re-run /usr/sbin/ipa-server-install as: [ipa.ipatests.test_integration.host.Host.f23master.cmd3] /usr/sbin/ipa-server-install --external-cert-file=/path/to/signed_certificate --external-cert-file=/path/to/external_ca_certificate [ipa.ipatests.test_integration.host.Host.f23master.cmd3] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN date | sha256sum > /home/ofayans/ipatests/noise.txt [ipa.ipatests.test_integration.host.Host.f23master.cmd4] RUN date | sha256sum > /home/ofayans/ipatests/noise.txt [ipa.ipatests.test_integration.host.Host.f23master.cmd4] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN echo x2k1j5tdsl > /home/ofayans/ipatests/pwdfile.txt [ipa.ipatests.test_integration.host.Host.f23master.cmd5] RUN echo x2k1j5tdsl > /home/ofayans/ipatests/pwdfile.txt [ipa.ipatests.test_integration.host.Host.f23master.cmd5] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['mkdir', '/home/ofayans/ipatests/testdb'] [ipa.ipatests.test_integration.host.Host.f23master.cmd6] RUN ['mkdir', '/home/ofayans/ipatests/testdb'] [ipa.ipatests.test_integration.host.Host.f23master.cmd6] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['certutil', '-N', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt'] [ipa.ipatests.test_integration.host.Host.f23master.cmd7] RUN ['certutil', '-N', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt'] [ipa.ipatests.test_integration.host.Host.f23master.cmd7] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['certutil', '-S', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt', '-n', 'external', '-s', 'CN=External CA, O=pesen.net', '-x', '-t', 'CTu,CTu,CTu', '-g', '2048', '-m', '0', '-v', '60', '-z', '/home/ofayans/ipatests/noise.txt', '-2', '-1', '-5'] [ipa.ipatests.test_integration.host.Host.f23master.cmd8] RUN ['certutil', '-S', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt', '-n', 'external', '-s', 'CN=External CA, O=pesen.net', '-x', '-t', 'CTu,CTu,CTu', '-g', '2048', '-m', '0', '-v', '60', '-z', '/home/ofayans/ipatests/noise.txt', '-2', '-1', '-5'] [ipa.ipatests.test_integration.host.Host.f23master.cmd8] [ipa.ipatests.test_integration.host.Host.f23master.cmd8] [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Generating key. This may take a few moments... [ipa.ipatests.test_integration.host.Host.f23master.cmd8] [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Is this a CA certificate [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Enter the path length constraint, enter to skip [<0 for unlimited path]: > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Notice: Trust flag u is set automatically if the private key is present. [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd8] > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd8] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['certutil', '-C', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt', '-c', 'external', '-m', '1', '-v', '60', '-2', '-1', '-5', '-i', '/root/ipa.csr', '-o', '/home/ofayans/ipatests/testdb/ipa.crt', '-a'] [ipa.ipatests.test_integration.host.Host.f23master.cmd9] RUN ['certutil', '-C', '-d', '/home/ofayans/ipatests/testdb', '-f', '/home/ofayans/ipatests/pwdfile.txt', '-c', 'external', '-m', '1', '-v', '60', '-2', '-1', '-5', '-i', '/root/ipa.csr', '-o', '/home/ofayans/ipatests/testdb/ipa.crt', '-a'] [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - Digital Signature [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - Non-repudiation [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - Key encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Data encipherment [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Key agreement [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - Cert signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - CRL signing key [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Is this a CA certificate [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Enter the path length constraint, enter to skip [<0 for unlimited path]: > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > 0 - SSL Client [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 1 - SSL Server [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 2 - S/MIME [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 3 - Object Signing [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 4 - Reserved for future use [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 5 - SSL CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 6 - S/MIME CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] 7 - Object Signing CA [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Other to finish [ipa.ipatests.test_integration.host.Host.f23master.cmd9] > Is this a critical extension [y/N]? [ipa.ipatests.test_integration.host.Host.f23master.cmd9] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN certutil -L -d /home/ofayans/ipatests/testdb -n "external" -a > /home/ofayans/ipatests/testdb/ca.crt [ipa.ipatests.test_integration.host.Host.f23master.cmd10] RUN certutil -L -d /home/ofayans/ipatests/testdb -n "external" -a > /home/ofayans/ipatests/testdb/ca.crt [ipa.ipatests.test_integration.host.Host.f23master.cmd10] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['ipa-server-install', '-a', 'x2k1j5tdsl', '-p', 'x2k1j5tdsl', '--external-cert-file', '/home/ofayans/ipatests/testdb/ipa.crt', '--external-cert-file', '/home/ofayans/ipatests/testdb/ca.crt'] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] RUN ['ipa-server-install', '-a', 'x2k1j5tdsl', '-p', 'x2k1j5tdsl', '--external-cert-file', '/home/ofayans/ipatests/testdb/ipa.crt', '--external-cert-file', '/home/ofayans/ipatests/testdb/ca.crt'] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] The log file for this installation can be found in /var/log/ipaserver-install.log [ipa.ipatests.test_integration.host.Host.f23master.cmd11] ============================================================================== [ipa.ipatests.test_integration.host.Host.f23master.cmd11] This program will set up the FreeIPA Server. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] This includes: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Configure a stand-alone CA (dogtag) for certificate management [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Configure the Network Time Daemon (ntpd) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Create and configure an instance of Directory Server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Create and configure a Kerberos Key Distribution Center (KDC) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Configure Apache (httpd) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * Configure DNS (bind) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Warning: skipping DNS resolution of host f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Checking DNS domain pesen.net., please wait ... [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] The IPA Master Server will be configured with: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Hostname: f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] IP address(es): 192.168.122.63 [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Domain name: pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Realm name: PESEN.NET [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] BIND DNS server will be configured to serve IPA domain with: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Forwarders: No forwarders [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Reverse zone(s): No reverse zone [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 30 seconds [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/28]: creating certificate server user [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/28]: configuring certificate server instance [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/28]: stopping certificate server instance to update CS.cfg [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/28]: backing up CS.cfg [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/28]: disabling nonces [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/28]: set up CRL publishing [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/28]: enable PKIX certificate path discovery and validation [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [8/28]: starting certificate server instance [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [9/28]: creating RA agent certificate database [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [10/28]: importing CA chain to RA certificate database [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [11/28]: fixing RA database permissions [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [12/28]: setting up signing cert profile [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [13/28]: setting audit signing renewal to 2 years [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [14/28]: restarting certificate server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [15/28]: requesting RA certificate from CA [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [16/28]: issuing RA agent certificate [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [17/28]: adding RA agent as a trusted user [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [18/28]: authorizing RA to modify profiles [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [19/28]: configure certmonger for renewals [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [20/28]: configure certificate renewals [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [21/28]: configure RA certificate renewal [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [22/28]: configure Server-Cert certificate renewal [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [23/28]: Configure HTTP to proxy connections [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [24/28]: restarting certificate server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [25/28]: migrating certificate profiles to LDAP [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [26/28]: importing IPA certificate profiles [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [27/28]: adding default CA ACL [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [28/28]: updating IPA configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring certificate server (pki-tomcatd). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring directory server (dirsrv). Estimated time: 10 seconds [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/3]: configuring ssl for ds instance [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/3]: restarting directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/3]: adding CA certificate entry [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring directory server (dirsrv). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring Kerberos KDC (krb5kdc). Estimated time: 30 seconds [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/9]: adding kerberos container to the directory [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/9]: configuring KDC [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/9]: initialize kerberos container [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/9]: adding default ACIs [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/9]: creating a keytab for the directory [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/9]: creating a keytab for the machine [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/9]: adding the password extension to the directory [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [8/9]: starting the KDC [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [9/9]: configuring KDC to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring Kerberos KDC (krb5kdc). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring kadmin [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/2]: starting kadmin [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/2]: configuring kadmin to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring kadmin. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring ipa_memcached [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/2]: starting ipa_memcached [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/2]: configuring ipa_memcached to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring ipa_memcached. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring ipa-otpd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/2]: starting ipa-otpd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/2]: configuring ipa-otpd to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring ipa-otpd. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring ipa-custodia [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/5]: Generating ipa-custodia config file [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/5]: Making sure custodia container exists [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/5]: Generating ipa-custodia keys [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/5]: starting ipa-custodia [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/5]: configuring ipa-custodia to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring ipa-custodia. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring the web interface (httpd). Estimated time: 1 minute [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/21]: setting mod_nss port to 443 [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/21]: setting mod_nss cipher suite [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/21]: setting mod_nss protocol list to TLSv1.0 - TLSv1.2 [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/21]: setting mod_nss password file [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/21]: enabling mod_nss renegotiate [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/21]: adding URL rewriting rules [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/21]: configuring httpd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [8/21]: configure certmonger for renewals [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [9/21]: setting up httpd keytab [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [10/21]: setting up ssl [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [11/21]: importing CA certificates from LDAP [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [12/21]: setting up browser autoconfig [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [13/21]: publish CA cert [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [14/21]: clean up any existing httpd ccache [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [15/21]: configuring SELinux for httpd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [16/21]: create KDC proxy user [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [17/21]: create KDC proxy config [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [18/21]: enable KDC proxy [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [19/21]: restarting httpd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [20/21]: configuring httpd to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [21/21]: enabling oddjobd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring the web interface (httpd). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Applying LDAP updates [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Upgrading IPA: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/9]: stopping directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/9]: saving configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/9]: disabling listeners [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/9]: enabling DS global lock [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/9]: starting directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/9]: upgrading server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/9]: stopping directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [8/9]: restoring configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [9/9]: starting directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Restarting the directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Restarting the KDC [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring DNS (named) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/11]: generating rndc key file [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/11]: adding DNS container [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/11]: setting up our zone [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/11]: setting up our own record [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/11]: setting up records for other masters [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/11]: adding NS record to the zones [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/11]: setting up CA record [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [8/11]: setting up kerberos principal [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [9/11]: setting up named.conf [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [10/11]: configuring named to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [11/11]: changing resolv.conf to point to ourselves [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring DNS (named). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring DNS key synchronization service (ipa-dnskeysyncd) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [1/7]: checking status [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [2/7]: setting up bind-dyndb-ldap working directory [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [3/7]: setting up kerberos principal [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [4/7]: setting up SoftHSM [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [5/7]: adding DNSSEC containers [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [6/7]: creating replica keys [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [7/7]: configuring ipa-dnskeysyncd to start on boot [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Done configuring DNS key synchronization service (ipa-dnskeysyncd). [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Restarting ipa-dnskeysyncd [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Restarting named [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Restarting the web server [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring client side components [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Using existing certificate '/etc/ipa/ca.crt'. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Client hostname: f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Realm: PESEN.NET [ipa.ipatests.test_integration.host.Host.f23master.cmd11] DNS Domain: pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] IPA Server: f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] BaseDN: dc=pesen,dc=net [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Skipping synchronizing time with NTP server. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] New SSSD config will be created [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configured sudoers in /etc/nsswitch.conf [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configured /etc/sssd/sssd.conf [ipa.ipatests.test_integration.host.Host.f23master.cmd11] trying https://f23master.pesen.net/ipa/json [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Forwarding 'ping' to json server 'https://f23master.pesen.net/ipa/json' [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Forwarding 'ca_is_enabled' to json server 'https://f23master.pesen.net/ipa/json' [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Systemwide CA database updated. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Forwarding 'host_mod' to json server 'https://f23master.pesen.net/ipa/json' [ipa.ipatests.test_integration.host.Host.f23master.cmd11] SSSD enabled [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configured /etc/openldap/ldap.conf [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configured /etc/ssh/ssh_config [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configured /etc/ssh/sshd_config [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Configuring pesen.net as NIS domain. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Client configuration complete. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] ============================================================================== [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Setup complete [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Next steps: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] 1. You must make sure these network ports are open: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] TCP Ports: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 80, 443: HTTP/HTTPS [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 389, 636: LDAP/LDAPS [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 88, 464: kerberos [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 53: bind [ipa.ipatests.test_integration.host.Host.f23master.cmd11] UDP Ports: [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 88, 464: kerberos [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 53: bind [ipa.ipatests.test_integration.host.Host.f23master.cmd11] * 123: ntp [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] 2. You can now obtain a kerberos ticket using the command: 'kinit admin' [ipa.ipatests.test_integration.host.Host.f23master.cmd11] This ticket will allow you to use the IPA tools (e.g., ipa user-add) [ipa.ipatests.test_integration.host.Host.f23master.cmd11] and the web user interface. [ipa.ipatests.test_integration.host.Host.f23master.cmd11] [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Be sure to back up the CA certificates stored in /root/cacert.p12 [ipa.ipatests.test_integration.host.Host.f23master.cmd11] These files are required to create replicas. The password for these [ipa.ipatests.test_integration.host.Host.f23master.cmd11] files is the Directory Manager password [ipa.ipatests.test_integration.host.Host.f23master.cmd11] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['kinit', 'admin'] [ipa.ipatests.test_integration.host.Host.f23master.cmd12] RUN ['kinit', 'admin'] [ipa.ipatests.test_integration.host.Host.f23master.cmd12] Password for [email protected]: [ipa.ipatests.test_integration.host.Host.f23master.cmd12] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['ipa', 'user-show', 'admin'] [ipa.ipatests.test_integration.host.Host.f23master.cmd13] RUN ['ipa', 'user-show', 'admin'] [ipa.ipatests.test_integration.host.Host.f23master.cmd13] User login: admin [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Last name: Administrator [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Home directory: /home/admin [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Login shell: /bin/bash [ipa.ipatests.test_integration.host.Host.f23master.cmd13] UID: 269200000 [ipa.ipatests.test_integration.host.Host.f23master.cmd13] GID: 269200000 [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Account disabled: False [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Password: True [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Member of groups: admins, trust admins [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Kerberos keys available: True [ipa.ipatests.test_integration.host.Host.f23master.cmd13] Exit code: 0 .[ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['ipa', 'domainlevel-get'] [ipa.ipatests.test_integration.host.Host.f23master.cmd14] RUN ['ipa', 'domainlevel-get'] [ipa.ipatests.test_integration.host.Host.f23master.cmd14] ----------------------- [ipa.ipatests.test_integration.host.Host.f23master.cmd14] Current domain level: 1 [ipa.ipatests.test_integration.host.Host.f23master.cmd14] ----------------------- [ipa.ipatests.test_integration.host.Host.f23master.cmd14] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['ipa-server-install', '--uninstall', '-U', '--ignore-topology-disconnect'] [ipa.ipatests.test_integration.host.Host.f23master.cmd15] RUN ['ipa-server-install', '--uninstall', '-U', '--ignore-topology-disconnect'] [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Shutting down all IPA services [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring ntpd [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Configuring certmonger to stop tracking system certificates for KRA [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Configuring certmonger to stop tracking system certificates for CA [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring CA [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring named [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring ipa-dnskeysyncd [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring web server [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring krb5kdc [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring kadmin [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring directory server [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring ipa-custodia [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring ipa_memcached [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring ipa-otpd [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Removing Kerberos service principals from /etc/krb5.keytab [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Failed to remove Kerberos service principals: Command '/usr/sbin/ipa-rmkeytab -k /etc/krb5.keytab -r PESEN.NET' returned non-zero exit status 5 [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Disabling client Kerberos and LDAP configurations [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Redundant SSSD configuration file /etc/sssd/sssd.conf was moved to /etc/sssd/sssd.conf.deleted [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Restoring client configuration files [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Unconfiguring the NIS domain. [ipa.ipatests.test_integration.host.Host.f23master.cmd15] nscd daemon is not installed, skip configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd15] nslcd daemon is not installed, skip configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Systemwide CA database updated. [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Client uninstall complete. [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Removing IPA client configuration [ipa.ipatests.test_integration.host.Host.f23master.cmd15] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['pkidestroy', '-s', 'CA', '-i', 'pki-tomcat'] [ipa.ipatests.test_integration.host.Host.f23master.cmd16] RUN ['pkidestroy', '-s', 'CA', '-i', 'pki-tomcat'] [ipa.ipatests.test_integration.host.Host.f23master.cmd16] ERROR: PKI instance '/var/lib/pki/pki-tomcat' does NOT exist! [ipa.ipatests.test_integration.host.Host.f23master.cmd16] [ipa.ipatests.test_integration.host.Host.f23master.cmd16] Exit code: 255 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['rm', '-rf', '/var/log/pki/pki-tomcat', '/etc/sysconfig/pki-tomcat', '/etc/sysconfig/pki/tomcat/pki-tomcat', '/var/lib/pki/pki-tomcat', '/etc/pki/pki-tomcat', '/var/lib/ipa/replica-info-f23master.pesen.net.gpg'] [ipa.ipatests.test_integration.host.Host.f23master.cmd17] RUN ['rm', '-rf', '/var/log/pki/pki-tomcat', '/etc/sysconfig/pki-tomcat', '/etc/sysconfig/pki/tomcat/pki-tomcat', '/var/lib/pki/pki-tomcat', '/etc/pki/pki-tomcat', '/var/lib/ipa/replica-info-f23master.pesen.net.gpg'] [ipa.ipatests.test_integration.host.Host.f23master.cmd17] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN if [ -d '/home/ofayans/ipatests/file_backup'/ ]; then cp -arvf '/home/ofayans/ipatests/file_backup'/* /; fi ; (find /home/ofayans/ipatests/file_backup | sed 's/\/home\/ofayans\/ipatests\/file_backup//g' | sed '/^$/d' | xargs -d ' ' /sbin/restorecon -v ||:) [ipa.ipatests.test_integration.host.Host.f23master.cmd18] RUN if [ -d '/home/ofayans/ipatests/file_backup'/ ]; then cp -arvf '/home/ofayans/ipatests/file_backup'/* /; fi ; (find /home/ofayans/ipatests/file_backup | sed 's/\/home\/ofayans\/ipatests\/file_backup//g' | sed '/^$/d' | xargs -d ' ' /sbin/restorecon -v ||:) [ipa.ipatests.test_integration.host.Host.f23master.cmd18] find: ‘/home/ofayans/ipatests/file_backup’: No such file or directory [ipa.ipatests.test_integration.host.Host.f23master.cmd18] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['xargs', '-d', '\\n', '-a', '/home/ofayans/ipatests/file_remove', 'rm', '-vf'] [ipa.ipatests.test_integration.host.Host.f23master.cmd19] RUN ['xargs', '-d', '\\n', '-a', '/home/ofayans/ipatests/file_remove', 'rm', '-vf'] [ipa.ipatests.test_integration.host.Host.f23master.cmd19] xargs: Cannot open input file ‘/home/ofayans/ipatests/file_remove’: No such file or directory [ipa.ipatests.test_integration.host.Host.f23master.cmd19] Exit code: 1 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['rm', '-rvf', '/home/ofayans/ipatests/file_backup', '/home/ofayans/ipatests/file_remove'] [ipa.ipatests.test_integration.host.Host.f23master.cmd20] RUN ['rm', '-rvf', '/home/ofayans/ipatests/file_backup', '/home/ofayans/ipatests/file_remove'] [ipa.ipatests.test_integration.host.Host.f23master.cmd20] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] READ /home/ofayans/ipatests/backup_hostname [ipa.ipatests.test_integration.tasks] No hostname backed up on f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN if [ -d '/home/ofayans/ipatests/file_backup'/ ]; then cp -arvf '/home/ofayans/ipatests/file_backup'/* /; fi ; (find /home/ofayans/ipatests/file_backup | sed 's/\/home\/ofayans\/ipatests\/file_backup//g' | sed '/^$/d' | xargs -d ' ' /sbin/restorecon -v ||:) [ipa.ipatests.test_integration.host.Host.f23master.cmd21] RUN if [ -d '/home/ofayans/ipatests/file_backup'/ ]; then cp -arvf '/home/ofayans/ipatests/file_backup'/* /; fi ; (find /home/ofayans/ipatests/file_backup | sed 's/\/home\/ofayans\/ipatests\/file_backup//g' | sed '/^$/d' | xargs -d ' ' /sbin/restorecon -v ||:) [ipa.ipatests.test_integration.host.Host.f23master.cmd21] find: ‘/home/ofayans/ipatests/file_backup’: No such file or directory [ipa.ipatests.test_integration.host.Host.f23master.cmd21] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['xargs', '-d', '\\n', '-a', '/home/ofayans/ipatests/file_remove', 'rm', '-vf'] [ipa.ipatests.test_integration.host.Host.f23master.cmd22] RUN ['xargs', '-d', '\\n', '-a', '/home/ofayans/ipatests/file_remove', 'rm', '-vf'] [ipa.ipatests.test_integration.host.Host.f23master.cmd22] xargs: Cannot open input file ‘/home/ofayans/ipatests/file_remove’: No such file or directory [ipa.ipatests.test_integration.host.Host.f23master.cmd22] Exit code: 1 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['rm', '-rvf', '/home/ofayans/ipatests/file_backup', '/home/ofayans/ipatests/file_remove'] [ipa.ipatests.test_integration.host.Host.f23master.cmd23] RUN ['rm', '-rvf', '/home/ofayans/ipatests/file_backup', '/home/ofayans/ipatests/file_remove'] [ipa.ipatests.test_integration.host.Host.f23master.cmd23] Exit code: 0 [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] READ /home/ofayans/ipatests/backup_hostname [ipa.ipatests.test_integration.tasks] No hostname backed up on f23master.pesen.net [ipa.ipatests.test_integration.host.Host.f23master.ParamikoTransport] RUN ['rm', '-rvf', '/home/ofayans/ipatests'] [ipa.ipatests.test_integration.host.Host.f23master.cmd24] RUN ['rm', '-rvf', '/home/ofayans/ipatests'] [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/env.sh’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/noise.txt’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/pwdfile.txt’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/testdb/secmod.db’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/testdb/cert8.db’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/testdb/key3.db’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/testdb/ipa.crt’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed ‘/home/ofayans/ipatests/testdb/ca.crt’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed directory: ‘/home/ofayans/ipatests/testdb’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] removed directory: ‘/home/ofayans/ipatests’ [ipa.ipatests.test_integration.host.Host.f23master.cmd24] Exit code: 0 ========================== 1 passed in 397.84 seconds ==========================
-- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code
