Hi,

This should really work like a charm, and I'm sure it is a stupid mistake
of mine if it doesn't, but I really can't find out what goes wrong.

Both IPA server and client are on FC21, very up to date.
Server installation (standard, with dns) worked well. Required ports open
in the firewall. Everything seems to work.

I did try to use the IPA server as a DNS (with forwarders) and NTP server
from non-ipa clients, no problem.
I also tried to use it as LDAP server, from a non-fedora machine (a
synology). It worked well and I could see users.

When trying to enroll a client, the enrollment itself seems to succeed, but:
- Unable to sync time with NTP server
- Unable to update DNS
- Unable to find users

I include below the short installation log (I changed the real domain into
hq.example.com), and in attachment, the full log with debug on.

>From the debug log, about the DNS update failure, I can see this:

  ; Communication with 192.168.0.72#53 failed: operation canceled
  could not reach any name server

I'm not sure what communication problem this could be, as the server (which
is both the IPA and the DNS servers), clearly can be reached.

Any idea where to look at?

Thanks,
Roberto


[root@meson ~]# ipa-client-install --mkhomedir --ssh-trust-dns --force-ntpd
--hostname=meson.hq.example.com
Discovery was successful!
Hostname: meson.hq.example.com
Realm: HQ.EXAMPLE.COM
DNS Domain: hq.example.com
IPA Server: ipa.hq.example.com
BaseDN: dc=hq,dc=example,dc=com

Continue to configure the system with these values? [no]: yes
Synchronizing time with KDC...
*Unable to sync time with IPA NTP server, assuming the time is in sync.
Please check that 123 UDP port is opened.*
User authorized to enroll computers: admin
Password for ad...@hq.example.com:
Successfully retrieved CA cert
    Subject:     CN=Certificate Authority,O=HQ.EXAMPLE.COM
    Issuer:      CN=Certificate Authority,O=HQ.EXAMPLE.COM
    Valid From:  Mon Mar 16 18:44:35 2015 UTC
    Valid Until: Fri Mar 16 18:44:35 2035 UTC

Enrolled in IPA realm HQ.EXAMPLE.COM
Created /etc/ipa/default.conf
New SSSD config will be created
Configured sudoers in /etc/nsswitch.conf
Configured /etc/sssd/sssd.conf
Configured /etc/krb5.conf for IPA realm HQ.EXAMPLE.COM
trying https://ipa.hq.example.com/ipa/json
Forwarding 'ping' to json server 'https://ipa.hq.example.com/ipa/json'
Forwarding 'ca_is_enabled' to json server '
https://ipa.hq.example.com/ipa/json'
Systemwide CA database updated.
Added CA certificates to the default NSS database.
Hostname (meson.hq.example.com) not found in DNS
*Failed to update DNS records.*
Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub
Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
Forwarding 'host_mod' to json server 'https://ipa.hq.example.com/ipa/json'
*Could not update DNS SSHFP records.*
SSSD enabled
Configured /etc/openldap/ldap.conf
*Unable to find 'admin' user with 'getent passwd ad...@hq.example.com
<ad...@hq.example.com>'!*
*Unable to reliably detect configuration. Check NSS setup manually.*
NTP enabled
Configured /etc/ssh/ssh_config
Configured /etc/ssh/sshd_config
Configuring hq.example.com as NIS domain.
Client configuration complete.
/usr/sbin/ipa-client-install was invoked with options: {'domain': None, 'force': False, 'krb5_offline_passwords': True, 'configure_firefox': False, 'primary': False, 'conf_sudo': True, 'force_ntpd': True, 'create_sshfp': True, 'conf_sshd': True, 'conf_ntp': True, 'on_master': False, 'no_nisdomain': False, 'nisdomain': None, 'ntp_server': None, 'principal': None, 'keytab': None, 'hostname': 'meson.hq.example.com', 'request_cert': False, 'no_ac': False, 'unattended': None, 'location': None, 'sssd': True, 'trust_sshfp': True, 'dns_updates': True, 'realm_name': None, 'conf_ssh': True, 'force_join': False, 'firefox_dir': None, 'ca_cert_file': None, 'server': None, 'prompt_password': False, 'permit': False, 'debug': True, 'preserve_sssd': False, 'mkhomedir': True, 'uninstall': False}
missing options might be asked for interactively later
IPA version 4.1.3-2.fc21
Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index'
Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
[IPA Discovery]
Starting IPA discovery with domain=None, servers=None, hostname=meson.hq.example.com
Start searching for LDAP SRV record in "hq.example.com" (domain of the hostname) and its sub-domains
Search DNS for SRV record of _ldap._tcp.hq.example.com
DNS record found: 0 100 389 ipa.hq.example.com.
[Kerberos realm search]
Search DNS for TXT record of _kerberos.hq.example.com
DNS record found: "HQ.EXAMPLE.COM"
Search DNS for SRV record of _kerberos._udp.hq.example.com
DNS record found: 0 100 88 ipa.hq.example.com.
[LDAP server check]
Verifying that ipa.hq.example.com (realm HQ.EXAMPLE.COM) is an IPA server
Init LDAP connection to: ipa.hq.example.com
Search LDAP server for IPA base DN
Check if naming context 'dc=hq,dc=example,dc=com' is for IPA
Naming context 'dc=hq,dc=example,dc=com' is a valid IPA context
Search for (objectClass=krbRealmContainer) in dc=hq,dc=example,dc=com (sub)
Found: cn=HQ.EXAMPLE.COM,cn=kerberos,dc=hq,dc=example,dc=com
Discovery result: Success; server=ipa.hq.example.com, domain=hq.example.com, kdc=ipa.hq.example.com, basedn=dc=hq,dc=example,dc=com
Validated servers: ipa.hq.example.com
will use discovered domain: hq.example.com
Start searching for LDAP SRV record in "hq.example.com" (Validating DNS Discovery) and its sub-domains
Search DNS for SRV record of _ldap._tcp.hq.example.com
DNS record found: 0 100 389 ipa.hq.example.com.
DNS validated, enabling discovery
will use discovered server: ipa.hq.example.com
Discovery was successful!
will use discovered realm: HQ.EXAMPLE.COM
will use discovered basedn: dc=hq,dc=example,dc=com
Hostname: meson.hq.example.com
Hostname source: Provided as option
Realm: HQ.EXAMPLE.COM
Realm source: Discovered from LDAP DNS records in ipa.hq.example.com
DNS Domain: hq.example.com
DNS Domain source: Discovered LDAP SRV records from hq.example.com (domain of the hostname)
IPA Server: ipa.hq.example.com
IPA Server source: Discovered from LDAP DNS records in ipa.hq.example.com
BaseDN: dc=hq,dc=example,dc=com
BaseDN source: From IPA server ldap://ipa.hq.example.com:389
Starting external process
args='/usr/sbin/ipa-rmkeytab' '-k' '/etc/krb5.keytab' '-r' 'HQ.EXAMPLE.COM'
Process finished, return code=5
stdout=
stderr=realm not found

Starting external process
args='/bin/hostname' 'meson.hq.example.com'
Process finished, return code=0
stdout=
stderr=
Backing up system configuration file '/etc/hostname'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='/usr/sbin/selinuxenabled'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/sbin/restorecon' '/etc/hostname'
Process finished, return code=0
stdout=
stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Synchronizing time with KDC...
Search DNS for SRV record of _ntp._udp.hq.example.com
DNS record found: 0 100 123 ipa.hq.example.com.
Starting external process
args='/usr/sbin/ntpd' '-qgc' '/tmp/tmpW6Y5MU'
Process finished, return code=1
stdout=
stderr=
Starting external process
args='/usr/sbin/ntpd' '-qgc' '/tmp/tmp8ZErmz'
Process finished, return code=1
stdout=
stderr=
Unable to sync time with IPA NTP server, assuming the time is in sync. Please check that 123 UDP port is opened.
will use principal provided as option: admin
Starting external process
args='keyctl' 'get_persistent' '@s' '0'
Process finished, return code=0
stdout=801729351

stderr=
Enabling persistent keyring CCACHE
Writing Kerberos configuration to /tmp/tmp5LVtJU:
#File modified by ipa-client-install

includedir /var/lib/sss/pubconf/krb5.include.d/

[libdefaults]
  default_realm = HQ.EXAMPLE.COM
  dns_lookup_realm = false
  dns_lookup_kdc = false
  rdns = false
  ticket_lifetime = 24h
  forwardable = yes
  udp_preference_limit = 0
  default_ccache_name = KEYRING:persistent:%{uid}


[realms]
  HQ.EXAMPLE.COM = {
    kdc = ipa.hq.example.com:88
    master_kdc = ipa.hq.example.com:88
    admin_server = ipa.hq.example.com:749
    default_domain = hq.example.com
    pkinit_anchors = FILE:/etc/ipa/ca.crt

  }


[domain_realm]
  .hq.example.com = HQ.EXAMPLE.COM
  hq.example.com = HQ.EXAMPLE.COM



Starting external process
args='kinit' 'ad...@hq.example.com'
Process finished, return code=0
stdout=Password for ad...@hq.example.com: 

stderr=
trying to retrieve CA cert via LDAP from ipa.hq.example.com
flushing ldap://ipa.hq.example.com:389 from SchemaCache
retrieving schema for SchemaCache url=ldap://ipa.hq.example.com:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7ff5d8594c68>
Successfully retrieved CA cert
    Subject:     CN=Certificate Authority,O=HQ.EXAMPLE.COM
    Issuer:      CN=Certificate Authority,O=HQ.EXAMPLE.COM
    Valid From:  Mon Mar 16 18:44:35 2015 UTC
    Valid Until: Fri Mar 16 18:44:35 2035 UTC

Starting external process
args='/usr/sbin/ipa-join' '-s' 'ipa.hq.example.com' '-b' 'dc=hq,dc=example,dc=com' '-h' 'meson.hq.example.com' '-d'
Process finished, return code=0
stdout=
stderr=XML-RPC CALL:

<?xml version="1.0" encoding="UTF-8"?>\r\n
<methodCall>\r\n
<methodName>join</methodName>\r\n
<params>\r\n
<param><value><array><data>\r\n
<value><string>meson.hq.example.com</string></value>\r\n
</data></array></value></param>\r\n
<param><value><struct>\r\n
<member><name>nsosversion</name>\r\n
<value><string>3.18.9-200.fc21.x86_64</string></value></member>\r\n
<member><name>nshardwareplatform</name>\r\n
<value><string>x86_64</string></value></member>\r\n
</struct></value></param>\r\n
</params>\r\n
</methodCall>\r\n

* Hostname was NOT found in DNS cache
*   Trying 192.168.0.72...
* Connected to ipa.hq.example.com (192.168.0.72) port 443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
*   CAfile: /etc/ipa/ca.crt
  CApath: none
* SSL connection using TLS_RSA_WITH_AES_128_CBC_SHA
* Server certificate:
* 	subject: CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM
* 	start date: Mar 16 18:45:29 2015 GMT
* 	expire date: Mar 16 18:45:29 2017 GMT
* 	common name: ipa.hq.example.com
* 	issuer: CN=Certificate Authority,O=HQ.EXAMPLE.COM
> POST /ipa/xml HTTP/1.1
Host: ipa.hq.example.com
Accept: */*
Content-Type: text/xml
User-Agent: ipa-join/4.1.3
Referer: https://ipa.hq.example.com/ipa/xml
X-Original-User-Agent: Xmlrpc-c/1.32.5 Curl/7.37.0
Content-Length: 477

* upload completely sent off: 477 out of 477 bytes
< HTTP/1.1 401 Unauthorized
< Date: Thu, 19 Mar 2015 19:33:13 GMT
* Server Apache/2.4.10 (Fedora) mod_auth_kerb/5.4 mod_nss/2.4.10 NSS/3.17.1 Basic ECC mod_wsgi/4.3.2 Python/2.7.8 is not blacklisted
< Server: Apache/2.4.10 (Fedora) mod_auth_kerb/5.4 mod_nss/2.4.10 NSS/3.17.1 Basic ECC mod_wsgi/4.3.2 Python/2.7.8
< WWW-Authenticate: Negotiate
< Last-Modified: Tue, 17 Feb 2015 11:38:16 GMT
< Accept-Ranges: bytes
< Content-Length: 1469
< Content-Type: text/html; charset=UTF-8
< 
* Ignoring the response-body
* Connection #0 to host ipa.hq.example.com left intact
* Issue another request to this URL: 'https://ipa.hq.example.com:443/ipa/xml'
* Found bundle for host ipa.hq.example.com: 0x7f8f1829a3c0
* Re-using existing connection! (#0) with host ipa.hq.example.com
* Connected to ipa.hq.example.com (192.168.0.72) port 443 (#0)
* Server auth using GSS-Negotiate with user ''
> POST /ipa/xml HTTP/1.1
Authorization: Negotiate YIIFZQYGKwYBBQUCoIIFWTCCBVWgJzAlBgkqhkiG9xIBAgIGBSsFAQUCBgkqhkiC9xIBAgIGBisGAQUCBaKCBSgEggUkYIIFIAYJKoZIhvcSAQICAQBuggUPMIIFC6ADAgEFoQMCAQ6iBwMFACAAAACjggFnYYIBYzCCAV+gAwIBBaEQGw5IUS5TUElOUVVFLkNPTaIrMCmgAwIBA6EiMCAbBEhUVFAbGHNwaW5xdWUwNC5ocS5zcGlucXVlLmNvbaOCARcwggEToAMCARKhAwIBAqKCAQUEggEBrot3Dv+bOimp3EL0xatvkBfI/Nxi0frQ644vlggVIdmSpw05Hf+rCqER9EqQWJpmM/OmRQMyxqXT8EDkkrBu7JoXIz3qzaEyVuOB2RKHEqF7HiR7pVvAXf+d9UIqUZwDeTrq/F0Gc5JYzeeQuIpEdC5rF2Js1LBRS6Mfacba7SYrkjH3S0G2VHitcWz+6yonkSjA+7xM9C+IjrBW22wYNQX9IZYAMI2WEeJYYlSwUtUCzhRyPJ3TOnP7T9RKIefP0uIUm4P4nmu0deYUQufHcGlToLGMlYs52uyIM3d2JUoM+kVI59GDdC6yDjwboZqbk1R/dtDQ941NttrV3R1uXxCkggOJMIIDhaADAgESooIDfASCA3gGLTJZ3Um1PSPDqWx3czYV1hBQaaOoCXmEnqJlU8iewfgXI18xqtZGLAPfPoKwnrdAuBia4xpNG/tZVY8g7ut2vLRo2NdtCtribcHJZ2EGR5QcqQUlcSc9euBwZv/qT7JsZ3eZDyN2iG/9pecw8Z1BY1r9MoH+VFy3sJMsae0NjQ7ozgRd3ROF12zL5auKGAQRKjklSuKuazURcefTDsaDdlE/GBvPoL7ASJmwYNvkkhyE1whdl1su3JJigYiAfol4CD2u33AzYd6aAdPl+ljH+TPpgK0MFm6YZzp+d8H+NOgxQ8CG8wYTXM3oNYjcqsqNJ7pbtdxFpZyi3M+qhiqlzbgTnn7KVP+gVxtHLtG3cIoyFK+O9+p2/NQLbusEDExnBO3iT9eM6rIwI0tELnTKYYv16yeou+YGQr7BYjL3NN5yVXmDrOMbsbVphrinB7zDMXCZ4lnJBv5ZeiKEDe+8x4Is2QRw+JJFP8O+R4Lf9UGFYIlPU0zY7GkEJVvFNEgkjxzYII0AWlVs6OAuFZ64VIbsgI8bXO1RcgRyPVkS+Y2t1FobgoX54DCIHop4meV0u6YK5c12iXnbmNlq5T0dwJnlRBj458QFTxZ8sI++vvfQS/U/L682JcYbJV47gYnyOvnEPLeSOJvARIc/CYg5OTxtC3oOZ3fII7+rZAmqbQHzNRo07aPKjFE+31lQzj+RqDgNCSAA7J9NZ4/Mm//nZl9UsNQXitTiTUFDD60On64N2KRbmoBDC0yYkP9IdBDYK6LNke/lnK7NCxS4jQcTd7a8mWr9GlHASixjT/n8gO6ORjyplXyQ4yV6nsbdJp4uBWkl5/Bd/PGPC6fFxv7lGGSNctHxqo5xZY9DEKcWk3SrIkJh6YTPUz0jsTp//F40N4KJD0Mb+tFWFh3UWX8/iPpx1vSE3l5rlhGjfcFgMNNXX1uImfqORroj1o+DP4U0Lt7pOpjTIFsx/wyciMxrg5yFSz6RM83MclBwheUe9WztsFA7AolM2trGDAEilHenDRj2nTtDQHYuaFAifjAshWKHXOcS+7mTQ4ZTcgatYKO7OOxh4Aase1A1AixC9dxJ7I6gQHsJTuM6jvfSLldwj6/n3RVyOBTPJcNlH/CPGdufljb2lm8ZXWrlkMN8M8an1UFIY/s/XG/5H62dzgtWf6AD6wahfWg=
Host: ipa.hq.example.com
Accept: */*
Content-Type: text/xml
User-Agent: ipa-join/4.1.3
Referer: https://ipa.hq.example.com/ipa/xml
X-Original-User-Agent: Xmlrpc-c/1.32.5 Curl/7.37.0
Content-Length: 477

* upload completely sent off: 477 out of 477 bytes
< HTTP/1.1 200 Success
< Date: Thu, 19 Mar 2015 19:33:13 GMT
* Server Apache/2.4.10 (Fedora) mod_auth_kerb/5.4 mod_nss/2.4.10 NSS/3.17.1 Basic ECC mod_wsgi/4.3.2 Python/2.7.8 is not blacklisted
< Server: Apache/2.4.10 (Fedora) mod_auth_kerb/5.4 mod_nss/2.4.10 NSS/3.17.1 Basic ECC mod_wsgi/4.3.2 Python/2.7.8
* Added cookie ipa_session="6b3eadc96f49225bc1c0be09503bb8f6" for domain ipa.hq.example.com, path /ipa, expire 1426794793
< Set-Cookie: ipa_session=6b3eadc96f49225bc1c0be09503bb8f6; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:13 GMT; Secure; HttpOnly
< WWW-Authenticate: Negotiate oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvPVuTegUbGKfkoMwhQaCcJ86RyDIwC+ZgwzqB1BlqDUluhudTturQiruLZqyjG8wZfZs+GRE5wsWu+bjl+XQcHzbN1Kcp//6upGm8Qq+mtx8oC6yvxFYwabR+oMqsakS0i7e89vdLmiYpfFt0FzEo
< Vary: Accept-Encoding
< Transfer-Encoding: chunked
< Content-Type: text/xml; charset=utf-8
< 
* Connection #0 to host ipa.hq.example.com left intact
XML-RPC RESPONSE:

<?xml version='1.0' encoding='UTF-8'?>\n
<methodResponse>\n
<params>\n
<param>\n
<value><array><data>\n
<value><string>fqdn=meson.hq.example.com,cn=computers,cn=accounts,dc=hq,dc=example,dc=com</string></value>\n
<value><struct>\n
<member>\n
<name>dn</name>\n
<value><string>fqdn=meson.hq.example.com,cn=computers,cn=accounts,dc=hq,dc=example,dc=com</string></value>\n
</member>\n
<member>\n
<name>sshpubkeyfp</name>\n
<value><array><data>\n
<value><string>D4:FD:38:CA:24:A4:82:C2:00:E9:80:13:38:D2:0E:E3 (ssh-rsa)</string></value>\n
<value><string>B3:B2:A7:40:0F:CC:B2:1C:58:85:A7:7A:2B:A3:1E:83 (ssh-ed25519)</string></value>\n
<value><string>27:61:0A:13:03:F1:7C:AA:EB:72:5D:BA:CE:58:C5:0C (ecdsa-sha2-nistp256)</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>has_keytab</name>\n
<value><boolean>0</boolean></value>\n
</member>\n
<member>\n
<name>ipasshpubkey</name>\n
<value><array><data>\n
<value><string>ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDXL8NPyzODLVWVsuO+PtZC1YZ08P7n4m8mtH2/Jc7UJ7XrCgJUlGxUJJaD6SHJjjxaIHrypBuDW3PQB+mHV1r/P2vhweQBnMqccZWjx1wY/SYWPWIO3NrkWqRehaZFgUxPg17U228lQ0EThGrXmMeen3+8+BJ+ebXYHr0FvF4cbOhtijoooochRCzqtnnt1sYORL/sk3EKXOPhgfsd9m/zITu1Pf9CteoQ5FHabGWO6Vxk3Or56wDbt1CMeeWNVt4aSSVXukLwfJeagbcwg/hYX/Na6WRdMF4mt8pmYMxh3cjzafbdmeOwduLPwpC3r/jiIhvuuGcKQCL6Qin6IHuv</string></value>\n
<value><string>ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMaXo+1XwmpZOVrHiwrHpcuPYsHs8A1LLbB0QyCsfo8E</string></value>\n
<value><string>ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGoen3p2K/cJurmRQeyddpwEcuH/F71CgCojg7oNFcKSiI7P5sv6lIOpuhvyYQyeEZE5MZiCCn9VV+08byfiISo=</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>cn</name>\n
<value><array><data>\n
<value><string>meson.hq.example.com</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>ipacertificatesubjectbase</name>\n
<value><array><data>\n
<value><string>O=HQ.EXAMPLE.COM</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>objectclass</name>\n
<value><array><data>\n
<value><string>ipaSshGroupOfPubKeys</string></value>\n
<value><string>ipaobject</string></value>\n
<value><string>ieee802device</string></value>\n
<value><string>nshost</string></value>\n
<value><string>top</string></value>\n
<value><string>ipaservice</string></value>\n
<value><string>pkiuser</string></value>\n
<value><string>ipahost</string></value>\n
<value><string>krbprincipal</string></value>\n
<value><string>krbprincipalaux</string></value>\n
<value><string>ipasshhost</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>ipakrbokasdelegate</name>\n
<value><boolean>0</boolean></value>\n
</member>\n
<member>\n
<name>fqdn</name>\n
<value><array><data>\n
<value><string>meson.hq.example.com</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>managing_host</name>\n
<value><array><data>\n
<value><string>meson.hq.example.com</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>krblastsuccessfulauth</name>\n
<value><array><data>\n
<value><string>20150319193244Z</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>krbextradata</name>\n
<value><array><data>\n
<value><base64>\n
AAIlJAtVaG9zdC9tZXNvbi5ocS5zcGlucXVlLmNvbUBIUS5TUElOUVVFLkNPTQA=\n
</base64></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>has_password</name>\n
<value><boolean>0</boolean></value>\n
</member>\n
<member>\n
<name>ipakrbrequirespreauth</name>\n
<value><boolean>1</boolean></value>\n
</member>\n
<member>\n
<name>krbprincipalname</name>\n
<value><array><data>\n
<value><string>host/meson.hq.example....@hq.example.com</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>managedby_host</name>\n
<value><array><data>\n
<value><string>meson.hq.example.com</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>serverhostname</name>\n
<value><array><data>\n
<value><string>meson</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>enrolledby_user</name>\n
<value><array><data>\n
<value><string>admin</string></value>\n
</data></array></value>\n
</member>\n
<member>\n
<name>ipauniqueid</name>\n
<value><array><data>\n
<value><string>961e639c-ce6e-11e4-ac96-0cc47a018bec</string></value>\n
</data></array></value>\n
</member>\n
</struct></value>\n
</data></array></value>\n
</param>\n
</params>\n
</methodResponse>\n

Keytab successfully retrieved and stored in: /etc/krb5.keytab
Certificate subject base is: O=HQ.EXAMPLE.COM

Enrolled in IPA realm HQ.EXAMPLE.COM
Starting external process
args='kdestroy'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/usr/bin/kinit' '-k' '-t' '/etc/krb5.keytab' 'host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=
stderr=
Backing up system configuration file '/etc/ipa/default.conf'
  -> Not backing up - '/etc/ipa/default.conf' doesn't exist
Created /etc/ipa/default.conf
importing all plugin modules in '/usr/lib/python2.7/site-packages/ipalib/plugins'...
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/aci.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automember.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automount.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/baseldap.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/batch.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/cert.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/config.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/delegation.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/dns.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/group.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacrule.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvc.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvcgroup.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbactest.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/host.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hostgroup.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/idrange.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/idviews.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/internal.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/kerberos.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/krbtpolicy.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/migration.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/misc.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/netgroup.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/otpconfig.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/otptoken.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/otptoken_yubikey.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/passwd.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/permission.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/ping.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pkinit.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/privilege.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pwpolicy.py'
Starting external process
args='klist' '-V'
Process finished, return code=0
stdout=Kerberos 5 version 1.12.2

stderr=
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/radiusproxy.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/realmdomains.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/role.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/rpcclient.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selfservice.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selinuxusermap.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/service.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmd.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmdgroup.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudorule.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/trust.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/user.py'
importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/virtual.py'
Backing up system configuration file '/etc/sssd/sssd.conf'
  -> Not backing up - '/etc/sssd/sssd.conf' doesn't exist
New SSSD config will be created
Backing up system configuration file '/etc/nsswitch.conf'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Configured sudoers in /etc/nsswitch.conf
Configured /etc/sssd/sssd.conf
Backing up system configuration file '/etc/krb5.conf'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='keyctl' 'get_persistent' '@s' '0'
Process finished, return code=0
stdout=801729351

stderr=
Enabling persistent keyring CCACHE
Writing Kerberos configuration to /etc/krb5.conf:
#File modified by ipa-client-install

includedir /var/lib/sss/pubconf/krb5.include.d/

[libdefaults]
  default_realm = HQ.EXAMPLE.COM
  dns_lookup_realm = true
  dns_lookup_kdc = true
  rdns = false
  ticket_lifetime = 24h
  forwardable = yes
  udp_preference_limit = 0
  default_ccache_name = KEYRING:persistent:%{uid}


[realms]
  HQ.EXAMPLE.COM = {
    pkinit_anchors = FILE:/etc/ipa/ca.crt

  }


[domain_realm]
  .hq.example.com = HQ.EXAMPLE.COM
  hq.example.com = HQ.EXAMPLE.COM



Configured /etc/krb5.conf for IPA realm HQ.EXAMPLE.COM
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=454163523

stderr=
Starting external process
args='keyctl' 'unlink' '454163523' '@s'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/usr/bin/certutil' '-d' '/tmp/tmp7_kCRk' '-N' '-f' '/tmp/tmpLcceAz'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/usr/bin/certutil' '-d' '/tmp/tmp7_kCRk' '-A' '-n' 'CA certificate 1' '-t' 'C,,'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=1
stdout=
stderr=keyctl_search: Required key not available

failed to find session_cookie in persistent storage for principal 'host/meson.hq.example....@hq.example.com'
trying https://ipa.hq.example.com/ipa/json
Created connection context.rpcclient
Try RPC connection
Forwarding 'ping' to json server 'https://ipa.hq.example.com/ipa/json'
NSSConnection init ipa.hq.example.com
Connecting: 192.168.0.72:0
auth_certificate_callback: check_sig=True is_server=False
Data:
        Version:       3 (0x2)
        Serial Number: 9 (0x9)
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Issuer: CN=Certificate Authority,O=HQ.EXAMPLE.COM
        Validity:
            Not Before: ma mrt 16 18:45:29 2015 UTC
            Not After:  do mrt 16 18:45:29 2017 UTC
        Subject: CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM
        Subject Public Key Info:
            Public Key Algorithm:
                Algorithm: PKCS #1 RSA Encryption
            RSA Public Key:
                Modulus:
                    e4:20:e2:17:30:f8:c4:10:a5:ed:19:3e:b5:31:22:8e:
                    97:10:92:b9:3d:b9:08:76:09:8f:87:8a:e9:e1:6d:30:
                    c1:5e:92:1b:aa:51:95:ec:85:63:90:5e:a4:ff:e9:97:
                    be:0b:74:37:e6:0c:80:83:1c:56:82:69:78:39:b3:2b:
                    65:64:d6:91:40:52:6e:77:41:4a:53:3b:0c:9a:be:dc:
                    85:09:c3:0b:25:7f:76:72:bb:cc:24:94:48:21:88:ed:
                    33:bc:87:31:66:9c:95:3c:2b:05:2a:39:ad:96:5c:7f:
                    02:27:0a:c9:86:48:b5:89:c2:f6:1f:9d:86:a7:98:ee:
                    df:2d:b1:f0:1d:ef:1a:53:28:81:6e:f0:8b:3a:0a:93:
                    87:a1:2d:80:f9:a0:b5:26:75:0e:77:15:28:5d:b3:f4:
                    2c:57:a4:7e:a3:54:af:5d:4a:0c:bc:8c:d9:f7:93:15:
                    fd:c7:78:aa:f4:1a:a4:49:19:e6:7f:76:73:4e:66:6f:
                    65:c0:48:84:e7:d6:74:e4:78:56:83:d3:97:46:1d:84:
                    98:c0:e6:2f:0d:81:5c:98:a8:e1:bb:5f:6b:b8:ac:1f:
                    79:d5:d4:00:39:21:28:6a:ec:83:b5:d3:ca:23:db:5f:
                    a5:30:f1:51:c7:20:4e:78:94:4b:5b:a3:75:2e:90:8d
                Exponent:
                    65537 (0x10001)
    Signed Extensions: (6 total)
        Name:     Certificate Authority Key Identifier
        Critical: False
        Key ID:
            a5:ae:1d:c8:7c:19:c6:2b:47:ad:00:27:c5:67:8a:40:
            bb:a2:48:2d
        Serial Number: None
        General Names: [0 total]

        Name:     Authority Information Access
        Critical: False
        Authority Information Access: [1 total]
            Info [1]:
                Method:   PKIX Online Certificate Status Protocol
                Location: URI: http://ipa-ca.hq.example.com/ca/ocsp

        Name:     Certificate Key Usage
        Critical: True
        Usages:
            Digital Signature
            Non-Repudiation
            Key Encipherment
            Data Encipherment

        Name:     Extended Key Usage
        Critical: False
        Usages:
            TLS Web Server Authentication Certificate
            TLS Web Client Authentication Certificate

        Name:     CRL Distribution Points
        Critical: False
        CRL Distribution Points: [1 total]
            Point [1]:
                General Names: [1 total]
                    http://ipa-ca.hq.example.com/ipa/crl/MasterCRL.bin
                Issuer:  Directory Name: CN=Certificate Authority,O=ipaca
                Reasons: ()

        Name:     Certificate Subject Key ID
        Critical: False
        Data:
            1e:83:e1:54:20:17:4b:67:85:91:d2:a0:d9:48:0b:cf:
            51:e4:c6:4c

    Signature:
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Signature:
            41:d8:b7:83:6b:64:59:8b:06:77:41:3b:ed:a9:59:a9:
            cb:d6:9d:9a:61:ea:d8:67:8c:02:4a:ad:51:7b:4a:3e:
            4e:12:b6:2e:b5:ee:8c:46:16:22:a7:b5:06:d4:f1:de:
            01:92:7a:c1:1c:e9:fe:46:62:14:23:5f:08:75:1b:f5:
            9c:1d:b2:2c:f7:b8:69:dc:da:91:ce:da:a4:0f:30:9e:
            76:fc:bb:ff:12:a5:c6:d4:8c:a9:c4:ca:d1:d0:df:8d:
            03:56:3f:da:78:4a:f4:31:d0:57:0d:72:91:37:d9:a2:
            bb:3e:0e:03:00:91:a3:76:41:76:df:7a:3c:87:53:02:
            45:d7:3e:4b:b1:8b:19:d2:2a:84:b8:fd:6c:e5:59:29:
            df:6d:5b:a1:33:8a:8a:25:db:85:b1:f6:27:80:9c:a1:
            5f:ef:66:ec:b2:70:98:97:da:ed:a2:0b:bf:f8:ed:34:
            d7:9d:85:e2:c4:09:b7:59:d3:03:01:f7:ff:bb:64:ff:
            cb:a2:27:a2:1f:9a:36:6e:35:2b:37:4b:e1:d7:6a:31:
            95:69:d6:72:31:31:17:64:e9:dc:c6:91:43:14:87:af:
            1d:b9:06:77:4b:39:80:7d:8e:8e:5d:7d:7d:6f:b0:c4:
            83:8f:15:6f:d8:c7:2a:88:3e:c8:cf:33:d2:56:c4:bf
        Fingerprint (MD5):
            68:33:01:f8:b0:ac:7c:c5:c7:a8:2e:3c:fd:ad:c5:8f
        Fingerprint (SHA1):
            d7:37:35:ff:c5:4d:0b:19:1f:16:33:c0:5c:fd:7f:86:
            8e:12:64:98
approved_usage = SSL Server intended_usage = SSL Server
cert valid True for "CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM"
handshake complete, peer = 192.168.0.72:443
Protocol: TLS1.2
Cipher: TLS_RSA_WITH_AES_128_CBC_SHA
received Set-Cookie 'ipa_session=d9aea28239f784a3cfe2f219841fa16d; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:14 GMT; Secure; HttpOnly'
storing cookie 'ipa_session=d9aea28239f784a3cfe2f219841fa16d; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:14 GMT; Secure; HttpOnly' for principal host/meson.hq.example....@hq.example.com
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=1
stdout=
stderr=keyctl_search: Required key not available

Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=1
stdout=
stderr=keyctl_search: Required key not available

Starting external process
args='keyctl' 'padd' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com' '@s'
Process finished, return code=0
stdout=645769519

stderr=
Forwarding 'ca_is_enabled' to json server 'https://ipa.hq.example.com/ipa/json'
NSSConnection init ipa.hq.example.com
Connecting: 192.168.0.72:0
auth_certificate_callback: check_sig=True is_server=False
Data:
        Version:       3 (0x2)
        Serial Number: 9 (0x9)
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Issuer: CN=Certificate Authority,O=HQ.EXAMPLE.COM
        Validity:
            Not Before: ma mrt 16 18:45:29 2015 UTC
            Not After:  do mrt 16 18:45:29 2017 UTC
        Subject: CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM
        Subject Public Key Info:
            Public Key Algorithm:
                Algorithm: PKCS #1 RSA Encryption
            RSA Public Key:
                Modulus:
                    e4:20:e2:17:30:f8:c4:10:a5:ed:19:3e:b5:31:22:8e:
                    97:10:92:b9:3d:b9:08:76:09:8f:87:8a:e9:e1:6d:30:
                    c1:5e:92:1b:aa:51:95:ec:85:63:90:5e:a4:ff:e9:97:
                    be:0b:74:37:e6:0c:80:83:1c:56:82:69:78:39:b3:2b:
                    65:64:d6:91:40:52:6e:77:41:4a:53:3b:0c:9a:be:dc:
                    85:09:c3:0b:25:7f:76:72:bb:cc:24:94:48:21:88:ed:
                    33:bc:87:31:66:9c:95:3c:2b:05:2a:39:ad:96:5c:7f:
                    02:27:0a:c9:86:48:b5:89:c2:f6:1f:9d:86:a7:98:ee:
                    df:2d:b1:f0:1d:ef:1a:53:28:81:6e:f0:8b:3a:0a:93:
                    87:a1:2d:80:f9:a0:b5:26:75:0e:77:15:28:5d:b3:f4:
                    2c:57:a4:7e:a3:54:af:5d:4a:0c:bc:8c:d9:f7:93:15:
                    fd:c7:78:aa:f4:1a:a4:49:19:e6:7f:76:73:4e:66:6f:
                    65:c0:48:84:e7:d6:74:e4:78:56:83:d3:97:46:1d:84:
                    98:c0:e6:2f:0d:81:5c:98:a8:e1:bb:5f:6b:b8:ac:1f:
                    79:d5:d4:00:39:21:28:6a:ec:83:b5:d3:ca:23:db:5f:
                    a5:30:f1:51:c7:20:4e:78:94:4b:5b:a3:75:2e:90:8d
                Exponent:
                    65537 (0x10001)
    Signed Extensions: (6 total)
        Name:     Certificate Authority Key Identifier
        Critical: False
        Key ID:
            a5:ae:1d:c8:7c:19:c6:2b:47:ad:00:27:c5:67:8a:40:
            bb:a2:48:2d
        Serial Number: None
        General Names: [0 total]

        Name:     Authority Information Access
        Critical: False
        Authority Information Access: [1 total]
            Info [1]:
                Method:   PKIX Online Certificate Status Protocol
                Location: URI: http://ipa-ca.hq.example.com/ca/ocsp

        Name:     Certificate Key Usage
        Critical: True
        Usages:
            Digital Signature
            Non-Repudiation
            Key Encipherment
            Data Encipherment

        Name:     Extended Key Usage
        Critical: False
        Usages:
            TLS Web Server Authentication Certificate
            TLS Web Client Authentication Certificate

        Name:     CRL Distribution Points
        Critical: False
        CRL Distribution Points: [1 total]
            Point [1]:
                General Names: [1 total]
                    http://ipa-ca.hq.example.com/ipa/crl/MasterCRL.bin
                Issuer:  Directory Name: CN=Certificate Authority,O=ipaca
                Reasons: ()

        Name:     Certificate Subject Key ID
        Critical: False
        Data:
            1e:83:e1:54:20:17:4b:67:85:91:d2:a0:d9:48:0b:cf:
            51:e4:c6:4c

    Signature:
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Signature:
            41:d8:b7:83:6b:64:59:8b:06:77:41:3b:ed:a9:59:a9:
            cb:d6:9d:9a:61:ea:d8:67:8c:02:4a:ad:51:7b:4a:3e:
            4e:12:b6:2e:b5:ee:8c:46:16:22:a7:b5:06:d4:f1:de:
            01:92:7a:c1:1c:e9:fe:46:62:14:23:5f:08:75:1b:f5:
            9c:1d:b2:2c:f7:b8:69:dc:da:91:ce:da:a4:0f:30:9e:
            76:fc:bb:ff:12:a5:c6:d4:8c:a9:c4:ca:d1:d0:df:8d:
            03:56:3f:da:78:4a:f4:31:d0:57:0d:72:91:37:d9:a2:
            bb:3e:0e:03:00:91:a3:76:41:76:df:7a:3c:87:53:02:
            45:d7:3e:4b:b1:8b:19:d2:2a:84:b8:fd:6c:e5:59:29:
            df:6d:5b:a1:33:8a:8a:25:db:85:b1:f6:27:80:9c:a1:
            5f:ef:66:ec:b2:70:98:97:da:ed:a2:0b:bf:f8:ed:34:
            d7:9d:85:e2:c4:09:b7:59:d3:03:01:f7:ff:bb:64:ff:
            cb:a2:27:a2:1f:9a:36:6e:35:2b:37:4b:e1:d7:6a:31:
            95:69:d6:72:31:31:17:64:e9:dc:c6:91:43:14:87:af:
            1d:b9:06:77:4b:39:80:7d:8e:8e:5d:7d:7d:6f:b0:c4:
            83:8f:15:6f:d8:c7:2a:88:3e:c8:cf:33:d2:56:c4:bf
        Fingerprint (MD5):
            68:33:01:f8:b0:ac:7c:c5:c7:a8:2e:3c:fd:ad:c5:8f
        Fingerprint (SHA1):
            d7:37:35:ff:c5:4d:0b:19:1f:16:33:c0:5c:fd:7f:86:
            8e:12:64:98
approved_usage = SSL Server intended_usage = SSL Server
cert valid True for "CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM"
handshake complete, peer = 192.168.0.72:443
Protocol: TLS1.2
Cipher: TLS_RSA_WITH_AES_128_CBC_SHA
received Set-Cookie 'ipa_session=1f5af8891e9e61192d4a07681949ae41; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:14 GMT; Secure; HttpOnly'
storing cookie 'ipa_session=1f5af8891e9e61192d4a07681949ae41; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:14 GMT; Secure; HttpOnly' for principal host/meson.hq.example....@hq.example.com
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=645769519

stderr=
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=645769519

stderr=
Starting external process
args='keyctl' 'pupdate' '645769519'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/usr/bin/certutil' '-d' '/etc/ipa/nssdb' '-N' '-f' '/etc/ipa/nssdb/pwdfile.txt'
Process finished, return code=0
stdout=
stderr=
flushing ldap://ipa.hq.example.com:389 from SchemaCache
retrieving schema for SchemaCache url=ldap://ipa.hq.example.com:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7ff5d4951638>
Adding CA certificates to the IPA NSS database.
Starting external process
args='/usr/bin/certutil' '-d' '/etc/ipa/nssdb' '-A' '-n' 'HQ.EXAMPLE.COM IPA CA' '-t' 'CT,C,C'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/usr/bin/update-ca-trust'
Process finished, return code=0
stdout=
stderr=
Systemwide CA database updated.
Attempting to add CA certificates to the default NSS database.
Starting external process
args='/usr/bin/certutil' '-d' '/etc/pki/nssdb' '-A' '-n' 'HQ.EXAMPLE.COM IPA CA' '-t' 'CT,C,C'
Process finished, return code=0
stdout=
stderr=
Added CA certificates to the default NSS database.
Hostname (meson.hq.example.com) not found in DNS
Writing nsupdate commands to /etc/ipa/.dns_update.txt:

debug
update delete meson.hq.example.com. IN A
show
send
update add meson.hq.example.com. 1200 IN A 192.168.0.207
show
send

Starting external process
args='/usr/bin/nsupdate' '-g' '/etc/ipa/.dns_update.txt'
Process finished, return code=1
stdout=Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id:      0
;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
meson.hq.example.com.	0	ANY	A	

Outgoing update query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id:  38141
;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; QUESTION SECTION:
;2184687456.sig-ipa.hq.example.com. ANY TKEY

;; ADDITIONAL SECTION:
2184687456.sig-ipa.hq.example.com. 0 ANY TKEY gss-tsig. 1426793595 1426793595 3 NOERROR 660 YIICkAYJKoZIhvcSAQICAQBuggJ/MIICe6ADAgEFoQMCAQ6iBwMFACAA AACjggF7YYIBdzCCAXOgAwIBBaEQGw5IUS5TUElOUVVFLkNPTaIqMCig AwIBAaEhMB8bA0ROUxsYc3BpbnF1ZTA0LmhxLnNwaW5xdWUuY29to4IB LDCCASigAwIBEqEDAgECooIBGgSCARbjVJxkLC1QfM6lBDT8d2mUW7a9 vjHIavW/xV+w8w/3pvW/uSCYoDcZQVWcfRU7yJ4TRfRwD2P8kUpQ+aMM cY7c416KmmzCNVRjfbDqYympXuOP7HTyAiFl38u+at1o3kWVchOTPfcn 2db2+patGBcruElJtmsEarHBUnzbyQ+dWilFYC2RRpPU36a14lj+ukAB m6dn331GsXNDhNt7QM72yU/w6DjotQHNGlIb13+yMrdBNzn1hY9LcE9N Xo5nOan95qceBisr+dcuVr1dujn9qfGDwePCyOhWn+2rkObXCZuIhpDi uU9EsFr/KjVYkLY4HcTX9RJLoIbESB4Zh11C93oOisQkAtECzCJXUd/U eBa5MMRgyKSB5jCB46ADAgESooHbBIHYrT0jqUe/XHJ13j2WYWfG0HHf AZyaoB8oJEZSSFYOdHMHXlncA2ksCiSGVN7ej7wuOJR1kpv8Yjt7nG6S tl+4qlMFVoCPUVL44PScjfuhFRtts2aCqu6NIRruoGSsHfl4pypwaoBO Yp6z2uZXnrTxsFPYOMIwQx5Gqu//BWPPi3aVfBimo9DgLFV4xuQgYLTe H9xvOj4zJpWD0iuvp3/Hl3Fm+g9vW2wOqLYSeXWhkinGWT2G+WPXIBrT Zv6BiJOvskKRVnLSQpzYmSppACibwyh5hiqq0Sue 0


stderr=Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id:  61947
;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;meson.hq.example.com.		IN	SOA

;; AUTHORITY SECTION:
hq.example.com.		0	IN	SOA	ipa.hq.example.com. hostmaster.hq.example.com. 1426793143 3600 900 1209600 3600

Found zone name: hq.example.com
The master is: ipa.hq.example.com
start_gssrequest
Found realm from ticket: HQ.EXAMPLE.COM
send_gssrequest
; Communication with 192.168.0.72#53 failed: operation canceled
could not reach any name server

nsupdate failed: Command ''/usr/bin/nsupdate' '-g' '/etc/ipa/.dns_update.txt'' returned non-zero exit status 1
Failed to update DNS records.
Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub
Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
Forwarding 'host_mod' to json server 'https://ipa.hq.example.com/ipa/json'
NSSConnection init ipa.hq.example.com
Connecting: 192.168.0.72:0
auth_certificate_callback: check_sig=True is_server=False
Data:
        Version:       3 (0x2)
        Serial Number: 9 (0x9)
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Issuer: CN=Certificate Authority,O=HQ.EXAMPLE.COM
        Validity:
            Not Before: ma mrt 16 18:45:29 2015 UTC
            Not After:  do mrt 16 18:45:29 2017 UTC
        Subject: CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM
        Subject Public Key Info:
            Public Key Algorithm:
                Algorithm: PKCS #1 RSA Encryption
            RSA Public Key:
                Modulus:
                    e4:20:e2:17:30:f8:c4:10:a5:ed:19:3e:b5:31:22:8e:
                    97:10:92:b9:3d:b9:08:76:09:8f:87:8a:e9:e1:6d:30:
                    c1:5e:92:1b:aa:51:95:ec:85:63:90:5e:a4:ff:e9:97:
                    be:0b:74:37:e6:0c:80:83:1c:56:82:69:78:39:b3:2b:
                    65:64:d6:91:40:52:6e:77:41:4a:53:3b:0c:9a:be:dc:
                    85:09:c3:0b:25:7f:76:72:bb:cc:24:94:48:21:88:ed:
                    33:bc:87:31:66:9c:95:3c:2b:05:2a:39:ad:96:5c:7f:
                    02:27:0a:c9:86:48:b5:89:c2:f6:1f:9d:86:a7:98:ee:
                    df:2d:b1:f0:1d:ef:1a:53:28:81:6e:f0:8b:3a:0a:93:
                    87:a1:2d:80:f9:a0:b5:26:75:0e:77:15:28:5d:b3:f4:
                    2c:57:a4:7e:a3:54:af:5d:4a:0c:bc:8c:d9:f7:93:15:
                    fd:c7:78:aa:f4:1a:a4:49:19:e6:7f:76:73:4e:66:6f:
                    65:c0:48:84:e7:d6:74:e4:78:56:83:d3:97:46:1d:84:
                    98:c0:e6:2f:0d:81:5c:98:a8:e1:bb:5f:6b:b8:ac:1f:
                    79:d5:d4:00:39:21:28:6a:ec:83:b5:d3:ca:23:db:5f:
                    a5:30:f1:51:c7:20:4e:78:94:4b:5b:a3:75:2e:90:8d
                Exponent:
                    65537 (0x10001)
    Signed Extensions: (6 total)
        Name:     Certificate Authority Key Identifier
        Critical: False
        Key ID:
            a5:ae:1d:c8:7c:19:c6:2b:47:ad:00:27:c5:67:8a:40:
            bb:a2:48:2d
        Serial Number: None
        General Names: [0 total]

        Name:     Authority Information Access
        Critical: False
        Authority Information Access: [1 total]
            Info [1]:
                Method:   PKIX Online Certificate Status Protocol
                Location: URI: http://ipa-ca.hq.example.com/ca/ocsp

        Name:     Certificate Key Usage
        Critical: True
        Usages:
            Digital Signature
            Non-Repudiation
            Key Encipherment
            Data Encipherment

        Name:     Extended Key Usage
        Critical: False
        Usages:
            TLS Web Server Authentication Certificate
            TLS Web Client Authentication Certificate

        Name:     CRL Distribution Points
        Critical: False
        CRL Distribution Points: [1 total]
            Point [1]:
                General Names: [1 total]
                    http://ipa-ca.hq.example.com/ipa/crl/MasterCRL.bin
                Issuer:  Directory Name: CN=Certificate Authority,O=ipaca
                Reasons: ()

        Name:     Certificate Subject Key ID
        Critical: False
        Data:
            1e:83:e1:54:20:17:4b:67:85:91:d2:a0:d9:48:0b:cf:
            51:e4:c6:4c

    Signature:
        Signature Algorithm:
            Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Signature:
            41:d8:b7:83:6b:64:59:8b:06:77:41:3b:ed:a9:59:a9:
            cb:d6:9d:9a:61:ea:d8:67:8c:02:4a:ad:51:7b:4a:3e:
            4e:12:b6:2e:b5:ee:8c:46:16:22:a7:b5:06:d4:f1:de:
            01:92:7a:c1:1c:e9:fe:46:62:14:23:5f:08:75:1b:f5:
            9c:1d:b2:2c:f7:b8:69:dc:da:91:ce:da:a4:0f:30:9e:
            76:fc:bb:ff:12:a5:c6:d4:8c:a9:c4:ca:d1:d0:df:8d:
            03:56:3f:da:78:4a:f4:31:d0:57:0d:72:91:37:d9:a2:
            bb:3e:0e:03:00:91:a3:76:41:76:df:7a:3c:87:53:02:
            45:d7:3e:4b:b1:8b:19:d2:2a:84:b8:fd:6c:e5:59:29:
            df:6d:5b:a1:33:8a:8a:25:db:85:b1:f6:27:80:9c:a1:
            5f:ef:66:ec:b2:70:98:97:da:ed:a2:0b:bf:f8:ed:34:
            d7:9d:85:e2:c4:09:b7:59:d3:03:01:f7:ff:bb:64:ff:
            cb:a2:27:a2:1f:9a:36:6e:35:2b:37:4b:e1:d7:6a:31:
            95:69:d6:72:31:31:17:64:e9:dc:c6:91:43:14:87:af:
            1d:b9:06:77:4b:39:80:7d:8e:8e:5d:7d:7d:6f:b0:c4:
            83:8f:15:6f:d8:c7:2a:88:3e:c8:cf:33:d2:56:c4:bf
        Fingerprint (MD5):
            68:33:01:f8:b0:ac:7c:c5:c7:a8:2e:3c:fd:ad:c5:8f
        Fingerprint (SHA1):
            d7:37:35:ff:c5:4d:0b:19:1f:16:33:c0:5c:fd:7f:86:
            8e:12:64:98
approved_usage = SSL Server intended_usage = SSL Server
cert valid True for "CN=ipa.hq.example.com,O=HQ.EXAMPLE.COM"
handshake complete, peer = 192.168.0.72:443
Protocol: TLS1.2
Cipher: TLS_RSA_WITH_AES_128_CBC_SHA
received Set-Cookie 'ipa_session=37bf2f3480c7b16c2609dc4e6a117659; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:15 GMT; Secure; HttpOnly'
storing cookie 'ipa_session=37bf2f3480c7b16c2609dc4e6a117659; Domain=ipa.hq.example.com; Path=/ipa; Expires=Thu, 19 Mar 2015 19:53:15 GMT; Secure; HttpOnly' for principal host/meson.hq.example....@hq.example.com
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=645769519

stderr=
Starting external process
args='keyctl' 'search' '@s' 'user' 'ipa_session_cookie:host/meson.hq.example....@hq.example.com'
Process finished, return code=0
stdout=645769519

stderr=
Starting external process
args='keyctl' 'pupdate' '645769519'
Process finished, return code=0
stdout=
stderr=
Writing nsupdate commands to /etc/ipa/.dns_update.txt:
debug
update delete meson.hq.example.com. IN SSHFP
show
send
update add meson.hq.example.com. 1200 IN SSHFP 3 1 B154E3DBA25157056494B9A88ACBC9DA9E1A63C7
update add meson.hq.example.com. 1200 IN SSHFP 3 2 0C4074529831FDD9CC4C53967ECCF95348B4AC1347B7BC1F2C6715A0EA31B41B
update add meson.hq.example.com. 1200 IN SSHFP 1 1 724D48E71E35F10CA1B335BDD31915C26D2D740C
update add meson.hq.example.com. 1200 IN SSHFP 1 2 ADD64626F0823D3A2BC05FF6391F3A69974E2F93C54580A836C8DE29743C72C9
show
send

Starting external process
args='/usr/bin/nsupdate' '-g' '/etc/ipa/.dns_update.txt'
Process finished, return code=1
stdout=Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id:      0
;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
meson.hq.example.com.	0	ANY	SSHFP	

Outgoing update query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id:  58379
;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; QUESTION SECTION:
;597112677.sig-ipa.hq.example.com.	ANY TKEY

;; ADDITIONAL SECTION:
597112677.sig-ipa.hq.example.com.	0 ANY TKEY gss-tsig. 1426793595 1426793595 3 NOERROR 660 YIICkAYJKoZIhvcSAQICAQBuggJ/MIICe6ADAgEFoQMCAQ6iBwMFACAA AACjggF7YYIBdzCCAXOgAwIBBaEQGw5IUS5TUElOUVVFLkNPTaIqMCig AwIBAaEhMB8bA0ROUxsYc3BpbnF1ZTA0LmhxLnNwaW5xdWUuY29to4IB LDCCASigAwIBEqEDAgECooIBGgSCARbjVJxkLC1QfM6lBDT8d2mUW7a9 vjHIavW/xV+w8w/3pvW/uSCYoDcZQVWcfRU7yJ4TRfRwD2P8kUpQ+aMM cY7c416KmmzCNVRjfbDqYympXuOP7HTyAiFl38u+at1o3kWVchOTPfcn 2db2+patGBcruElJtmsEarHBUnzbyQ+dWilFYC2RRpPU36a14lj+ukAB m6dn331GsXNDhNt7QM72yU/w6DjotQHNGlIb13+yMrdBNzn1hY9LcE9N Xo5nOan95qceBisr+dcuVr1dujn9qfGDwePCyOhWn+2rkObXCZuIhpDi uU9EsFr/KjVYkLY4HcTX9RJLoIbESB4Zh11C93oOisQkAtECzCJXUd/U eBa5MMRgyKSB5jCB46ADAgESooHbBIHYjAY31F2almmMvbHPMBur5A4z kWXZrFYEzCfD6oE3WzJrusbja2Y5REbKHVo1Qtb3bfUjyezPjAvjF7s1 MYdZoB+KqOTsOz/pYpjEme2HS6Oed43nm3BPQtPRdfmj2b39nVjNXfpz a2yBTS9OPGYE/djRHZQAVCv/u84wI3NWUB3005IXglYl1rRzUaZrvJ4N RMyO+uCauofWmPp7FZbJBBsJKpmRFItyHs2wx+mh1NqwQlaVN5Xn4HHE CfQ2W+XyQJYvPf/gczuMjE3DsF/3LgCtYJVn6nj9 0


stderr=Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id:  36434
;; flags: qr aa rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;meson.hq.example.com.		IN	SOA

;; AUTHORITY SECTION:
hq.example.com.		0	IN	SOA	ipa.hq.example.com. hostmaster.hq.example.com. 1426793143 3600 900 1209600 3600

Found zone name: hq.example.com
The master is: ipa.hq.example.com
start_gssrequest
Found realm from ticket: HQ.EXAMPLE.COM
send_gssrequest
; Communication with 192.168.0.72#53 failed: operation canceled
could not reach any name server

nsupdate failed: Command ''/usr/bin/nsupdate' '-g' '/etc/ipa/.dns_update.txt'' returned non-zero exit status 1
Could not update DNS SSHFP records.
Starting external process
args='/bin/systemctl' 'list-unit-files' '--full'
Process finished, return code=0
stdout=UNIT FILE                                   STATE   
proc-sys-fs-binfmt_misc.automount           static  
dev-hugepages.mount                         static  
dev-mqueue.mount                            static  
proc-fs-nfsd.mount                          static  
proc-sys-fs-binfmt_misc.mount               static  
sys-fs-fuse-connections.mount               static  
sys-kernel-config.mount                     static  
sys-kernel-debug.mount                      static  
tmp.mount                                   static  
var-lib-nfs-rpc_pipefs.mount                static  
cups.path                                   enabled 
systemd-ask-password-console.path           static  
systemd-ask-password-plymouth.path          static  
systemd-ask-password-wall.path              static  
session-1.scope                             static  
session-c1.scope                            static  
abrt-ccpp.service                           enabled 
abrt-oops.service                           enabled 
abrt-pstoreoops.service                     disabled
abrt-vmcore.service                         enabled 
abrt-xorg.service                           enabled 
abrtd.service                               enabled 
accounts-daemon.service                     enabled 
alsa-restore.service                        static  
alsa-state.service                          static  
alsa-store.service                          static  
anaconda-direct.service                     static  
anaconda-noshell.service                    static  
anaconda-shell@.service                     static  
anaconda-sshd.service                       static  
anaconda-tmux@.service                      static  
anaconda.service                            static  
arp-ethers.service                          disabled
atd.service                                 enabled 
auditd.service                              enabled 
auth-rpcgss-module.service                  static  
autofs.service                              disabled
autovt@.service                             disabled
avahi-daemon.service                        enabled 
blk-availability.service                    disabled
bluetooth.service                           enabled 
brltty.service                              disabled
canberra-system-bootup.service              disabled
canberra-system-shutdown-reboot.service     disabled
canberra-system-shutdown.service            disabled
certmonger.service                          disabled
chrony-wait.service                         disabled
chronyd.service                             enabled 
colord.service                              static  
configure-printer@.service                  static  
console-getty.service                       disabled
console-shell.service                       disabled
container-getty@.service                    static  
corosync-notifyd.service                    disabled
corosync.service                            disabled
crond.service                               enabled 
cups-browsed.service                        disabled
cups.service                                enabled 
dbus-org.bluez.service                      enabled 
dbus-org.fedoraproject.FirewallD1.service   enabled 
dbus-org.freedesktop.Avahi.service          enabled 
dbus-org.freedesktop.hostname1.service      static  
dbus-org.freedesktop.locale1.service        static  
dbus-org.freedesktop.login1.service         static  
dbus-org.freedesktop.machine1.service       static  
dbus-org.freedesktop.ModemManager1.service  enabled 
dbus-org.freedesktop.NetworkManager.service enabled 
dbus-org.freedesktop.nm-dispatcher.service  enabled 
dbus-org.freedesktop.resolve1.service       disabled
dbus-org.freedesktop.timedate1.service      static  
dbus.service                                static  
debug-shell.service                         disabled
display-manager.service                     enabled 
dm-event.service                            disabled
dmraid-activation.service                   enabled 
dnf-makecache.service                       static  
dnsmasq.service                             disabled
dracut-cmdline.service                      static  
dracut-initqueue.service                    static  
dracut-mount.service                        static  
dracut-pre-mount.service                    static  
dracut-pre-pivot.service                    static  
dracut-pre-trigger.service                  static  
dracut-pre-udev.service                     static  
dracut-shutdown.service                     static  
ebtables.service                            disabled
emergency.service                           static  
fancontrol.service                          disabled
fcoe.service                                disabled
fedora-autorelabel-mark.service             static  
fedora-autorelabel.service                  static  
fedora-domainname.service                   disabled
fedora-import-state.service                 static  
fedora-loadmodules.service                  static  
fedora-readonly.service                     static  
firewalld.service                           enabled 
fprintd.service                             static  
fstrim.service                              static  
gdm.service                                 enabled 
geoclue.service                             static  
getty@.service                              enabled 
gssproxy.service                            disabled
halt-local.service                          static  
htcacheclean.service                        static  
httpd.service                               disabled
initrd-cleanup.service                      static  
initrd-parse-etc.service                    static  
initrd-switch-root.service                  static  
initrd-udevadm-cleanup-db.service           static  
instperf.service                            static  
ipsec.service                               disabled
irda.service                                disabled
irqbalance.service                          enabled 
iscsi.service                               enabled 
iscsid.service                              disabled
iscsiuio.service                            disabled
kdump.service                               disabled
kmod-static-nodes.service                   static  
ldconfig.service                            static  
libvirt-guests.service                      disabled
libvirtd.service                            enabled 
lldpad.service                              disabled
lm_sensors.service                          enabled 
lvm2-lvmetad.service                        disabled
lvm2-monitor.service                        enabled 
lvm2-pvscan@.service                        static  
mcelog.service                              enabled 
mdadm-grow-continue@.service                static  
mdadm-last-resort@.service                  static  
mdmon@.service                              static  
mdmonitor.service                           enabled 
messagebus.service                          static  
ModemManager.service                        enabled 
multipathd.service                          enabled 
netcf-transaction.service                   enabled 
NetworkManager-dispatcher.service           enabled 
NetworkManager-wait-online.service          disabled
NetworkManager.service                      enabled 
nfs-blkmap.service                          static  
nfs-config.service                          static  
nfs-idmap.service                           static  
nfs-idmapd.service                          static  
nfs-lock.service                            static  
nfs-mountd.service                          static  
nfs-secure-server.service                   static  
nfs-secure.service                          static  
nfs-server.service                          disabled
nfs-utils.service                           static  
nfs.service                                 disabled
ntpd.service                                disabled
ntpdate.service                             disabled
numad.service                               disabled
oddjobd.service                             enabled 
openvpn@.service                            disabled
packagekit-offline-update.service           static  
packagekit.service                          static  
plymouth-halt.service                       disabled
plymouth-kexec.service                      disabled
plymouth-poweroff.service                   disabled
plymouth-quit-wait.service                  disabled
plymouth-quit.service                       disabled
plymouth-read-write.service                 disabled
plymouth-reboot.service                     disabled
plymouth-start.service                      disabled
plymouth-switch-root.service                static  
polkit.service                              static  
powertop.service                            disabled
pppoe-server.service                        disabled
psacct.service                              disabled
qemu-guest-agent.service                    static  
quotaon.service                             static  
radvd.service                               disabled
rc-local.service                            static  
rdisc.service                               disabled
realmd.service                              static  
redis-sentinel.service                      disabled
redis.service                               disabled
rescue.service                              static  
rngd.service                                enabled 
rpc-gssd.service                            static  
rpc-statd-notify.service                    static  
rpc-statd.service                           static  
rpc-svcgssd.service                         static  
rpcbind.service                             static  
rsyncd.service                              disabled
rsyncd@.service                             static  
rtkit-daemon.service                        enabled 
saslauthd.service                           disabled
serial-getty@.service                       disabled
sheepdog.service                            disabled
speech-dispatcherd.service                  disabled
spice-vdagentd.service                      enabled 
sshd-keygen.service                         static  
sshd.service                                enabled 
sshd@.service                               static  
sssd.service                                disabled
stunnel.service                             disabled
svnserve.service                            disabled
syslog.service                              enabled 
systemd-ask-password-console.service        static  
systemd-ask-password-plymouth.service       static  
systemd-ask-password-wall.service           static  
systemd-backlight@.service                  static  
systemd-binfmt.service                      static  
systemd-firstboot.service                   static  
systemd-fsck-root.service                   static  
systemd-fsck@.service                       static  
systemd-halt.service                        static  
systemd-hibernate-resume@.service           static  
systemd-hibernate.service                   static  
systemd-hostnamed.service                   static  
systemd-hybrid-sleep.service                static  
systemd-initctl.service                     static  
systemd-journal-catalog-update.service      static  
systemd-journal-flush.service               static  
systemd-journal-remote.service              static  
systemd-journal-upload.service              disabled
systemd-journald.service                    static  
systemd-kexec.service                       static  
systemd-localed.service                     static  
systemd-logind.service                      static  
systemd-machined.service                    static  
systemd-modules-load.service                static  
systemd-networkd-wait-online.service        disabled
systemd-networkd.service                    disabled
systemd-nspawn@.service                     disabled
systemd-poweroff.service                    static  
systemd-quotacheck.service                  static  
systemd-random-seed.service                 static  
systemd-readahead-collect.service           enabled 
systemd-readahead-done.service              static  
systemd-readahead-drop.service              enabled 
systemd-readahead-replay.service            enabled 
systemd-reboot.service                      static  
systemd-remount-fs.service                  static  
systemd-resolved.service                    disabled
systemd-rfkill@.service                     static  
systemd-shutdownd.service                   static  
systemd-suspend.service                     static  
systemd-sysctl.service                      static  
systemd-sysusers.service                    static  
systemd-timedated.service                   static  
systemd-timesyncd.service                   disabled
systemd-tmpfiles-clean.service              static  
systemd-tmpfiles-setup-dev.service          static  
systemd-tmpfiles-setup.service              static  
systemd-udev-hwdb-update.service            static  
systemd-udev-settle.service                 static  
systemd-udev-trigger.service                static  
systemd-udevd.service                       static  
systemd-update-done.service                 static  
systemd-update-utmp-runlevel.service        static  
systemd-update-utmp.service                 static  
systemd-user-sessions.service               static  
systemd-vconsole-setup.service              static  
tcsd.service                                disabled
teamd@.service                              static  
tomcat.service                              disabled
tomcat@.service                             disabled
udisks2.service                             static  
upgrade-plymouth-switch-root.service        disabled
upgrade-prep.service                        disabled
upgrade-switch-root.service                 static  
upower.service                              disabled
usbmuxd.service                             static  
user@.service                               static  
virtlockd.service                           static  
vmtoolsd.service                            enabled 
wacom-inputattach@.service                  static  
wpa_supplicant.service                      disabled
xl2tpd.service                              disabled
yum-makecache.service                       static  
zram.service                                static  
-.slice                                     static  
machine.slice                               static  
system.slice                                static  
user.slice                                  static  
avahi-daemon.socket                         enabled 
cups.socket                                 enabled 
dbus.socket                                 static  
dm-event.socket                             enabled 
httpd.socket                                disabled
iscsid.socket                               enabled 
iscsiuio.socket                             enabled 
libvirtd.socket                             static  
lldpad.socket                               disabled
lvm2-lvmetad.socket                         enabled 
rpcbind.socket                              enabled 
rsyncd.socket                               disabled
sshd.socket                                 disabled
syslog.socket                               static  
systemd-initctl.socket                      static  
systemd-journal-remote.socket               disabled
systemd-journald-dev-log.socket             static  
systemd-journald.socket                     static  
systemd-shutdownd.socket                    static  
systemd-udevd-control.socket                static  
systemd-udevd-kernel.socket                 static  
virtlockd.socket                            disabled
anaconda.target                             static  
basic.target                                static  
bluetooth.target                            static  
cryptsetup-pre.target                       static  
cryptsetup.target                           static  
ctrl-alt-del.target                         disabled
default.target                              enabled 
emergency.target                            static  
final.target                                static  
getty.target                                static  
graphical.target                            enabled 
halt.target                                 disabled
hibernate.target                            static  
hybrid-sleep.target                         static  
initrd-fs.target                            static  
initrd-root-fs.target                       static  
initrd-switch-root.target                   static  
initrd.target                               static  
kexec.target                                disabled
local-fs-pre.target                         static  
local-fs.target                             static  
multi-user.target                           static  
network-online.target                       static  
network-pre.target                          static  
network.target                              static  
nfs-blkmap.target                           disabled
nfs-client.target                           enabled 
nss-lookup.target                           static  
nss-user-lookup.target                      static  
paths.target                                static  
poweroff.target                             disabled
printer.target                              static  
reboot.target                               disabled
remote-fs-pre.target                        static  
remote-fs.target                            enabled 
rescue.target                               disabled
rpcbind.target                              static  
runlevel0.target                            disabled
runlevel1.target                            disabled
runlevel2.target                            static  
runlevel3.target                            static  
runlevel4.target                            static  
runlevel5.target                            static  
runlevel6.target                            disabled
shutdown.target                             static  
sigpwr.target                               static  
sleep.target                                static  
slices.target                               static  
smartcard.target                            static  
sockets.target                              static  
sound.target                                static  
spice-vdagentd.target                       static  
suspend.target                              static  
swap.target                                 static  
sysinit.target                              static  
system-update.target                        static  
system-upgrade.target                       static  
time-sync.target                            static  
timers.target                               static  
umount.target                               static  
upgrade-switch-root.target                  static  
dnf-makecache.timer                         enabled 
fstrim.timer                                disabled
mdadm-last-resort@.timer                    static  
systemd-readahead-done.timer                static  
systemd-tmpfiles-clean.timer                static  
yum-makecache.timer                         disabled

366 unit files listed.

stderr=
Starting external process
args='/bin/systemctl' 'list-unit-files' '--full'
Process finished, return code=0
stdout=UNIT FILE                                   STATE   
proc-sys-fs-binfmt_misc.automount           static  
dev-hugepages.mount                         static  
dev-mqueue.mount                            static  
proc-fs-nfsd.mount                          static  
proc-sys-fs-binfmt_misc.mount               static  
sys-fs-fuse-connections.mount               static  
sys-kernel-config.mount                     static  
sys-kernel-debug.mount                      static  
tmp.mount                                   static  
var-lib-nfs-rpc_pipefs.mount                static  
cups.path                                   enabled 
systemd-ask-password-console.path           static  
systemd-ask-password-plymouth.path          static  
systemd-ask-password-wall.path              static  
session-1.scope                             static  
session-c1.scope                            static  
abrt-ccpp.service                           enabled 
abrt-oops.service                           enabled 
abrt-pstoreoops.service                     disabled
abrt-vmcore.service                         enabled 
abrt-xorg.service                           enabled 
abrtd.service                               enabled 
accounts-daemon.service                     enabled 
alsa-restore.service                        static  
alsa-state.service                          static  
alsa-store.service                          static  
anaconda-direct.service                     static  
anaconda-noshell.service                    static  
anaconda-shell@.service                     static  
anaconda-sshd.service                       static  
anaconda-tmux@.service                      static  
anaconda.service                            static  
arp-ethers.service                          disabled
atd.service                                 enabled 
auditd.service                              enabled 
auth-rpcgss-module.service                  static  
autofs.service                              disabled
autovt@.service                             disabled
avahi-daemon.service                        enabled 
blk-availability.service                    disabled
bluetooth.service                           enabled 
brltty.service                              disabled
canberra-system-bootup.service              disabled
canberra-system-shutdown-reboot.service     disabled
canberra-system-shutdown.service            disabled
certmonger.service                          disabled
chrony-wait.service                         disabled
chronyd.service                             enabled 
colord.service                              static  
configure-printer@.service                  static  
console-getty.service                       disabled
console-shell.service                       disabled
container-getty@.service                    static  
corosync-notifyd.service                    disabled
corosync.service                            disabled
crond.service                               enabled 
cups-browsed.service                        disabled
cups.service                                enabled 
dbus-org.bluez.service                      enabled 
dbus-org.fedoraproject.FirewallD1.service   enabled 
dbus-org.freedesktop.Avahi.service          enabled 
dbus-org.freedesktop.hostname1.service      static  
dbus-org.freedesktop.locale1.service        static  
dbus-org.freedesktop.login1.service         static  
dbus-org.freedesktop.machine1.service       static  
dbus-org.freedesktop.ModemManager1.service  enabled 
dbus-org.freedesktop.NetworkManager.service enabled 
dbus-org.freedesktop.nm-dispatcher.service  enabled 
dbus-org.freedesktop.resolve1.service       disabled
dbus-org.freedesktop.timedate1.service      static  
dbus.service                                static  
debug-shell.service                         disabled
display-manager.service                     enabled 
dm-event.service                            disabled
dmraid-activation.service                   enabled 
dnf-makecache.service                       static  
dnsmasq.service                             disabled
dracut-cmdline.service                      static  
dracut-initqueue.service                    static  
dracut-mount.service                        static  
dracut-pre-mount.service                    static  
dracut-pre-pivot.service                    static  
dracut-pre-trigger.service                  static  
dracut-pre-udev.service                     static  
dracut-shutdown.service                     static  
ebtables.service                            disabled
emergency.service                           static  
fancontrol.service                          disabled
fcoe.service                                disabled
fedora-autorelabel-mark.service             static  
fedora-autorelabel.service                  static  
fedora-domainname.service                   disabled
fedora-import-state.service                 static  
fedora-loadmodules.service                  static  
fedora-readonly.service                     static  
firewalld.service                           enabled 
fprintd.service                             static  
fstrim.service                              static  
gdm.service                                 enabled 
geoclue.service                             static  
getty@.service                              enabled 
gssproxy.service                            disabled
halt-local.service                          static  
htcacheclean.service                        static  
httpd.service                               disabled
initrd-cleanup.service                      static  
initrd-parse-etc.service                    static  
initrd-switch-root.service                  static  
initrd-udevadm-cleanup-db.service           static  
instperf.service                            static  
ipsec.service                               disabled
irda.service                                disabled
irqbalance.service                          enabled 
iscsi.service                               enabled 
iscsid.service                              disabled
iscsiuio.service                            disabled
kdump.service                               disabled
kmod-static-nodes.service                   static  
ldconfig.service                            static  
libvirt-guests.service                      disabled
libvirtd.service                            enabled 
lldpad.service                              disabled
lm_sensors.service                          enabled 
lvm2-lvmetad.service                        disabled
lvm2-monitor.service                        enabled 
lvm2-pvscan@.service                        static  
mcelog.service                              enabled 
mdadm-grow-continue@.service                static  
mdadm-last-resort@.service                  static  
mdmon@.service                              static  
mdmonitor.service                           enabled 
messagebus.service                          static  
ModemManager.service                        enabled 
multipathd.service                          enabled 
netcf-transaction.service                   enabled 
NetworkManager-dispatcher.service           enabled 
NetworkManager-wait-online.service          disabled
NetworkManager.service                      enabled 
nfs-blkmap.service                          static  
nfs-config.service                          static  
nfs-idmap.service                           static  
nfs-idmapd.service                          static  
nfs-lock.service                            static  
nfs-mountd.service                          static  
nfs-secure-server.service                   static  
nfs-secure.service                          static  
nfs-server.service                          disabled
nfs-utils.service                           static  
nfs.service                                 disabled
ntpd.service                                disabled
ntpdate.service                             disabled
numad.service                               disabled
oddjobd.service                             enabled 
openvpn@.service                            disabled
packagekit-offline-update.service           static  
packagekit.service                          static  
plymouth-halt.service                       disabled
plymouth-kexec.service                      disabled
plymouth-poweroff.service                   disabled
plymouth-quit-wait.service                  disabled
plymouth-quit.service                       disabled
plymouth-read-write.service                 disabled
plymouth-reboot.service                     disabled
plymouth-start.service                      disabled
plymouth-switch-root.service                static  
polkit.service                              static  
powertop.service                            disabled
pppoe-server.service                        disabled
psacct.service                              disabled
qemu-guest-agent.service                    static  
quotaon.service                             static  
radvd.service                               disabled
rc-local.service                            static  
rdisc.service                               disabled
realmd.service                              static  
redis-sentinel.service                      disabled
redis.service                               disabled
rescue.service                              static  
rngd.service                                enabled 
rpc-gssd.service                            static  
rpc-statd-notify.service                    static  
rpc-statd.service                           static  
rpc-svcgssd.service                         static  
rpcbind.service                             static  
rsyncd.service                              disabled
rsyncd@.service                             static  
rtkit-daemon.service                        enabled 
saslauthd.service                           disabled
serial-getty@.service                       disabled
sheepdog.service                            disabled
speech-dispatcherd.service                  disabled
spice-vdagentd.service                      enabled 
sshd-keygen.service                         static  
sshd.service                                enabled 
sshd@.service                               static  
sssd.service                                disabled
stunnel.service                             disabled
svnserve.service                            disabled
syslog.service                              enabled 
systemd-ask-password-console.service        static  
systemd-ask-password-plymouth.service       static  
systemd-ask-password-wall.service           static  
systemd-backlight@.service                  static  
systemd-binfmt.service                      static  
systemd-firstboot.service                   static  
systemd-fsck-root.service                   static  
systemd-fsck@.service                       static  
systemd-halt.service                        static  
systemd-hibernate-resume@.service           static  
systemd-hibernate.service                   static  
systemd-hostnamed.service                   static  
systemd-hybrid-sleep.service                static  
systemd-initctl.service                     static  
systemd-journal-catalog-update.service      static  
systemd-journal-flush.service               static  
systemd-journal-remote.service              static  
systemd-journal-upload.service              disabled
systemd-journald.service                    static  
systemd-kexec.service                       static  
systemd-localed.service                     static  
systemd-logind.service                      static  
systemd-machined.service                    static  
systemd-modules-load.service                static  
systemd-networkd-wait-online.service        disabled
systemd-networkd.service                    disabled
systemd-nspawn@.service                     disabled
systemd-poweroff.service                    static  
systemd-quotacheck.service                  static  
systemd-random-seed.service                 static  
systemd-readahead-collect.service           enabled 
systemd-readahead-done.service              static  
systemd-readahead-drop.service              enabled 
systemd-readahead-replay.service            enabled 
systemd-reboot.service                      static  
systemd-remount-fs.service                  static  
systemd-resolved.service                    disabled
systemd-rfkill@.service                     static  
systemd-shutdownd.service                   static  
systemd-suspend.service                     static  
systemd-sysctl.service                      static  
systemd-sysusers.service                    static  
systemd-timedated.service                   static  
systemd-timesyncd.service                   disabled
systemd-tmpfiles-clean.service              static  
systemd-tmpfiles-setup-dev.service          static  
systemd-tmpfiles-setup.service              static  
systemd-udev-hwdb-update.service            static  
systemd-udev-settle.service                 static  
systemd-udev-trigger.service                static  
systemd-udevd.service                       static  
systemd-update-done.service                 static  
systemd-update-utmp-runlevel.service        static  
systemd-update-utmp.service                 static  
systemd-user-sessions.service               static  
systemd-vconsole-setup.service              static  
tcsd.service                                disabled
teamd@.service                              static  
tomcat.service                              disabled
tomcat@.service                             disabled
udisks2.service                             static  
upgrade-plymouth-switch-root.service        disabled
upgrade-prep.service                        disabled
upgrade-switch-root.service                 static  
upower.service                              disabled
usbmuxd.service                             static  
user@.service                               static  
virtlockd.service                           static  
vmtoolsd.service                            enabled 
wacom-inputattach@.service                  static  
wpa_supplicant.service                      disabled
xl2tpd.service                              disabled
yum-makecache.service                       static  
zram.service                                static  
-.slice                                     static  
machine.slice                               static  
system.slice                                static  
user.slice                                  static  
avahi-daemon.socket                         enabled 
cups.socket                                 enabled 
dbus.socket                                 static  
dm-event.socket                             enabled 
httpd.socket                                disabled
iscsid.socket                               enabled 
iscsiuio.socket                             enabled 
libvirtd.socket                             static  
lldpad.socket                               disabled
lvm2-lvmetad.socket                         enabled 
rpcbind.socket                              enabled 
rsyncd.socket                               disabled
sshd.socket                                 disabled
syslog.socket                               static  
systemd-initctl.socket                      static  
systemd-journal-remote.socket               disabled
systemd-journald-dev-log.socket             static  
systemd-journald.socket                     static  
systemd-shutdownd.socket                    static  
systemd-udevd-control.socket                static  
systemd-udevd-kernel.socket                 static  
virtlockd.socket                            disabled
anaconda.target                             static  
basic.target                                static  
bluetooth.target                            static  
cryptsetup-pre.target                       static  
cryptsetup.target                           static  
ctrl-alt-del.target                         disabled
default.target                              enabled 
emergency.target                            static  
final.target                                static  
getty.target                                static  
graphical.target                            enabled 
halt.target                                 disabled
hibernate.target                            static  
hybrid-sleep.target                         static  
initrd-fs.target                            static  
initrd-root-fs.target                       static  
initrd-switch-root.target                   static  
initrd.target                               static  
kexec.target                                disabled
local-fs-pre.target                         static  
local-fs.target                             static  
multi-user.target                           static  
network-online.target                       static  
network-pre.target                          static  
network.target                              static  
nfs-blkmap.target                           disabled
nfs-client.target                           enabled 
nss-lookup.target                           static  
nss-user-lookup.target                      static  
paths.target                                static  
poweroff.target                             disabled
printer.target                              static  
reboot.target                               disabled
remote-fs-pre.target                        static  
remote-fs.target                            enabled 
rescue.target                               disabled
rpcbind.target                              static  
runlevel0.target                            disabled
runlevel1.target                            disabled
runlevel2.target                            static  
runlevel3.target                            static  
runlevel4.target                            static  
runlevel5.target                            static  
runlevel6.target                            disabled
shutdown.target                             static  
sigpwr.target                               static  
sleep.target                                static  
slices.target                               static  
smartcard.target                            static  
sockets.target                              static  
sound.target                                static  
spice-vdagentd.target                       static  
suspend.target                              static  
swap.target                                 static  
sysinit.target                              static  
system-update.target                        static  
system-upgrade.target                       static  
time-sync.target                            static  
timers.target                               static  
umount.target                               static  
upgrade-switch-root.target                  static  
dnf-makecache.timer                         enabled 
fstrim.timer                                disabled
mdadm-last-resort@.timer                    static  
systemd-readahead-done.timer                static  
systemd-tmpfiles-clean.timer                static  
yum-makecache.timer                         disabled

366 unit files listed.

stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Starting external process
args='/usr/sbin/authconfig' '--enablesssdauth' '--enablemkhomedir' '--update' '--enablesssd'
Process finished, return code=0
stdout=
stderr=
SSSD enabled
Starting external process
args='/bin/systemctl' 'restart' 'sssd.service'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'is-active' 'sssd.service'
Process finished, return code=0
stdout=active

stderr=
Starting external process
args='/bin/systemctl' 'enable' 'sssd.service'
Process finished, return code=0
stdout=
stderr=
Backing up system configuration file '/etc/openldap/ldap.conf'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Configured /etc/openldap/ldap.conf
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Starting external process
args='getent' 'passwd' 'ad...@hq.example.com'
Process finished, return code=2
stdout=
stderr=
Unable to find 'admin' user with 'getent passwd ad...@hq.example.com'!
Unable to reliably detect configuration. Check NSS setup manually.
Starting external process
args='/bin/systemctl' 'is-enabled' 'chronyd.service'
Process finished, return code=0
stdout=enabled

stderr=
Starting external process
args='/bin/systemctl' 'is-active' 'chronyd.service'
Process finished, return code=0
stdout=active

stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Starting external process
args='/bin/systemctl' 'stop' 'chronyd.service'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'disable' 'chronyd.service'
Process finished, return code=0
stdout=
stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/chronyd.service.

Backing up system configuration file '/etc/ntp/step-tickers'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='/usr/sbin/selinuxenabled'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/sbin/restorecon' '/etc/ntp/step-tickers'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'is-enabled' 'ntpd.service'
Process finished, return code=1
stdout=disabled

stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Backing up system configuration file '/etc/ntp.conf'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='/usr/sbin/selinuxenabled'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/sbin/restorecon' '/etc/ntp.conf'
Process finished, return code=0
stdout=
stderr=
Backing up system configuration file '/etc/sysconfig/ntpd'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='/usr/sbin/selinuxenabled'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/sbin/restorecon' '/etc/sysconfig/ntpd'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'enable' 'ntpd.service'
Process finished, return code=0
stdout=
stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/ntpd.service to /usr/lib/systemd/system/ntpd.service.

Starting external process
args='/bin/systemctl' 'restart' 'ntpd.service'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'is-active' 'ntpd.service'
Process finished, return code=0
stdout=active

stderr=
NTP enabled
Backing up system configuration file '/etc/ssh/ssh_config'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Configured /etc/ssh/ssh_config
Backing up system configuration file '/etc/ssh/sshd_config'
Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
Starting external process
args='sshd' '-t' '-f' '/dev/null' '-o' 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' '-o' 'AuthorizedKeysCommandUser=nobody'
Process finished, return code=0
stdout=
stderr=Could not load host key: /etc/ssh/ssh_host_dsa_key

Configured /etc/ssh/sshd_config
Starting external process
args='/bin/systemctl' 'is-active' 'sshd.service'
Process finished, return code=0
stdout=active

stderr=
Starting external process
args='/bin/systemctl' 'restart' 'sshd.service'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'is-active' 'sshd.service'
Process finished, return code=0
stdout=active

stderr=
Configuring hq.example.com as NIS domain.
Starting external process
args='/usr/bin/nisdomainname'
Process finished, return code=1
stdout=nisdomainname: Local domain name not set

stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Starting external process
args='/bin/systemctl' 'is-enabled' 'fedora-domainname.service'
Process finished, return code=1
stdout=disabled

stderr=
Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
Starting external process
args='/usr/sbin/authconfig' '--update' '--nisdomain' 'hq.example.com'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'enable' 'fedora-domainname.service'
Process finished, return code=0
stdout=
stderr=Created symlink from /etc/systemd/system/sysinit.target.wants/fedora-domainname.service to /usr/lib/systemd/system/fedora-domainname.service.

Starting external process
args='/bin/systemctl' 'restart' 'fedora-domainname.service'
Process finished, return code=0
stdout=
stderr=
Starting external process
args='/bin/systemctl' 'is-active' 'fedora-domainname.service'
Process finished, return code=0
stdout=active

stderr=
Client configuration complete.

Continue to configure the system with these values? [no]: User authorized to enroll computers: 
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to