2024-06-28T07:46:24Z DEBUG ================================================================================
2024-06-28T07:46:24Z INFO IPA to IPA migration starting ...
2024-06-28T07:46:24Z DEBUG Migration options:
2024-06-28T07:46:24Z DEBUG --mode=stage-mode
2024-06-28T07:46:24Z DEBUG --hostname=remote.ipa1.test
2024-06-28T07:46:24Z DEBUG --verbose=False
2024-06-28T07:46:24Z DEBUG --bind-dn=cn=Directory manager
2024-06-28T07:46:24Z DEBUG --bind-pw-file=None
2024-06-28T07:46:24Z DEBUG --cacertfile=None
2024-06-28T07:46:24Z DEBUG --subtree=[]
2024-06-28T07:46:24Z DEBUG --log-file=/var/log/ipa-migrate.log
2024-06-28T07:46:24Z DEBUG --skip-schema=False
2024-06-28T07:46:24Z DEBUG --skip-config=False
2024-06-28T07:46:24Z DEBUG --migrate-dns=False
2024-06-28T07:46:24Z DEBUG --dryrun=True
2024-06-28T07:46:24Z DEBUG --dryrun-record=None
2024-06-28T07:46:24Z DEBUG --force=False
2024-06-28T07:46:24Z DEBUG --version=False
2024-06-28T07:46:24Z DEBUG --quiet=False
2024-06-28T07:46:24Z DEBUG --schema-overwrite=False
2024-06-28T07:46:24Z DEBUG --reset-range=False
2024-06-28T07:46:24Z DEBUG --db-ldif=None
2024-06-28T07:46:24Z DEBUG --schema-ldif=None
2024-06-28T07:46:24Z DEBUG --config-ldif=None
2024-06-28T07:46:24Z DEBUG --no-prompt=True
2024-06-28T07:46:24Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA1-TEST.socket from SchemaCache
2024-06-28T07:46:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA1-TEST.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f75e6f238e0>
2024-06-28T07:46:25Z DEBUG retrieving schema for SchemaCache url=ldap://remote.ipa1.test conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f75e0bf5df0>
2024-06-28T07:46:25Z DEBUG Found realm from remote server: IPA1.TEST
2024-06-28T07:46:25Z INFO Migrating schema ...
2024-06-28T07:46:25Z DEBUG Getting schema from the remote server ...
2024-06-28T07:46:25Z DEBUG Retrieved 1538 attributes and 343 objectClasses
2024-06-28T07:46:27Z DEBUG Migrated 0 attributes and 0 objectClasses
2024-06-28T07:46:27Z DEBUG Skipped 1538 attributes and 343 objectClasses
2024-06-28T07:46:27Z INFO Migrating configuration ...
2024-06-28T07:46:27Z DEBUG Getting config from the remote server ...
2024-06-28T07:46:27Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA1-TEST.socket from SchemaCache
2024-06-28T07:46:27Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA1-TEST.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f75e6f238e0>
2024-06-28T07:46:27Z DEBUG Config setting 'dnaMaxValue' replaced '['1417999999']' with '817399999' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config'
2024-06-28T07:46:27Z DEBUG Config setting 'dnaNextValue' replaced '['1417800002']' with '817200004' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config'
2024-06-28T07:46:27Z INFO Migrating database ... (this make take a while)
2024-06-28T07:46:27Z DEBUG Resetting the DNA range for: uid=admin,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:27Z DEBUG Resetting the DNA range for: uid=admin,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:27Z DEBUG Resetting the DNA range for: cn=admins,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:27Z DEBUG Resetting the DNA range for: cn=editors,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:27Z DEBUG Skipping remote host 'fqdn=remote.ipa1.test,cn=computers,cn=accounts,dc=ipa1,dc=test' from 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa1,dc=test'
2024-06-28T07:46:27Z DEBUG Entry is different and will be updated: 'uid=sudo,cn=sysaccounts,cn=etc,dc=ipa1,dc=test' attribute 'userPassword' add val '{PBKDF2-SHA512}10000$/skBa395mOtLf6TSakXxFedUwLGw4KCa$Rxs9BBqQzSuCJcBr/Lk/qcLFNYy6EOsqvzSjfibhd6olkTB0NNv11xWeZRToayNw8KiMx9nOWcwMLzIV075Pxg==' not in ['{PBKDF2-SHA512}10000$VQFvYvb0KO/jFf93YCTs7V77TnLIbNAN$q5bF02FVHYMcxYUOHScbtieNjRzKj+jwi1Fvpsfm4HCtazh4NJZ6ur+wxhmr8njtbLW7H1FZe+tb1lX3GPVLFg==']
2024-06-28T07:46:27Z DEBUG Add db entry 'ipaUniqueID=4f246672-351f-11ef-b442-fa163ebf3770,cn=hbac,dc=ipa1,dc=test - hbac_rules'
2024-06-28T07:46:27Z DEBUG Add db entry 'ipaUniqueID=4f28ddc4-351f-11ef-ac74-fa163ebf3770,cn=hbac,dc=ipa1,dc=test - hbac_rules'
2024-06-28T07:46:27Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=ldap/remote.ipa1.test@IPA1.TEST,cn=services,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:27Z DEBUG Skipping remote certificate entry: 'cn=IPA1.TEST IPA CA,cn=certificates,cn=ipa,cn=etc,dc=ipa1,dc=test' Issuer: CN=Certificate Authority,O=IPA1.TEST
2024-06-28T07:46:27Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=HTTP/remote.ipa1.test@IPA1.TEST,cn=services,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:28Z DEBUG Entry is different and will be updated: 'cn=ipa1.test,cn=ad,cn=etc,dc=ipa1,dc=test' attribute 'ipaNTDomainGUID' replaced with val '27462636-63fa-4461-8ffc-9fd8f36c16a9' old value: ['8fab2c1a-724e-4b8e-b2a6-d3323d8a0ea3']
2024-06-28T07:46:28Z DEBUG Resetting the DNA range for: cn=Default SMB Group,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:28Z DEBUG Resetting DNA range for new entry: uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:28Z DEBUG Resetting DNA range for new entry: uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:28Z DEBUG Add db entry 'uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test - users'
2024-06-28T07:46:28Z DEBUG Resetting DNA range for new entry: cn=user1,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:28Z DEBUG Add db entry 'cn=user1,cn=groups,cn=accounts,dc=ipa1,dc=test - groups'
2024-06-28T07:46:28Z INFO Running ipa-server-upgrade ... (this make take a while)
2024-06-28T07:46:28Z INFO Skipping ipa-server-upgrade in dryrun mode.
2024-06-28T07:46:28Z INFO Running SIDGEN task ...
2024-06-28T07:46:28Z INFO Skipping SIDGEN task in dryrun mode.
2024-06-28T07:46:28Z INFO Migration complete!
2024-06-28T07:46:28Z INFO
Dry Run Summary:
2024-06-28T07:46:28Z INFO ===============================================================================
2024-06-28T07:46:28Z INFO
General Information
2024-06-28T07:46:28Z INFO -------------------
2024-06-28T07:46:28Z INFO  - Remote Host:             remote.ipa1.test
2024-06-28T07:46:28Z INFO  - Migration Duration:      0:00:04
2024-06-28T07:46:28Z INFO  - Migration Log:           /var/log/ipa-migrate.log
2024-06-28T07:46:28Z INFO  - Remote Host:             remote.ipa1.test
2024-06-28T07:46:28Z INFO  - Remote Domain:           ipa1.test
2024-06-28T07:46:28Z INFO  - Local Host:              local.ipa1.test
2024-06-28T07:46:28Z INFO  - Local Domain:            ipa1.test
2024-06-28T07:46:28Z INFO  - Remote Suffix:           dc=ipa1,dc=test
2024-06-28T07:46:28Z INFO  - Local Suffix:            dc=ipa1,dc=test
2024-06-28T07:46:28Z INFO  - Remote Realm:            IPA1.TEST
2024-06-28T07:46:28Z INFO  - Local Realm:             IPA1.TEST
2024-06-28T07:46:28Z INFO  - Schema Analyzed:         1881 definitions
2024-06-28T07:46:28Z INFO  - Config Analyzed:         1 entries
2024-06-28T07:46:28Z INFO  - Database Anaylzed:       531 entries
2024-06-28T07:46:28Z INFO
Schema Migration (migrated 0 definitions)
2024-06-28T07:46:28Z INFO -----------------------------------------
2024-06-28T07:46:28Z INFO  - Attributes:              0
2024-06-28T07:46:28Z INFO  - Objectclasses:           0
2024-06-28T07:46:28Z INFO
DS Configuration Migration (migrated 1 entries)
2024-06-28T07:46:28Z INFO -----------------------------------------------
2024-06-28T07:46:28Z INFO  - DNA Plugin:              1
2024-06-28T07:46:28Z INFO
Database Migration (migrated 11 entries)
2024-06-28T07:46:28Z INFO ----------------------------------------
2024-06-28T07:46:28Z INFO  - Sysaccounts:             1
2024-06-28T07:46:28Z INFO  - Admin:                   1
2024-06-28T07:46:28Z INFO  - Users:                   1
2024-06-28T07:46:28Z INFO  - Groups:                  5
2024-06-28T07:46:28Z INFO  - AD:                      1
2024-06-28T07:46:28Z INFO  - HBAC Rules:              2
2024-06-28T07:46:28Z INFO
Action Items (3 items)
2024-06-28T07:46:28Z INFO ----------------------
2024-06-28T07:46:28Z INFO  - You will have to manually migrate IDM related configuration files.  Here are some, but not all, of the configuration files to look into:
    - /etc/ipa/*
    - /etc/sssd/sssd.conf
    - /etc/named.conf
    - /etc/named/*
    - ...
2024-06-28T07:46:28Z INFO  - SSSD should be restarted after a successful migration
2024-06-28T07:46:28Z INFO  - The admin password is not migrated from the remote server. Reset it manually if needed.
2024-06-28T07:46:28Z INFO ===============================================================================
2024-06-28T07:46:37Z DEBUG ================================================================================
2024-06-28T07:46:37Z INFO IPA to IPA migration starting ...
2024-06-28T07:46:37Z DEBUG Migration options:
2024-06-28T07:46:37Z DEBUG --mode=stage-mode
2024-06-28T07:46:37Z DEBUG --hostname=remote.ipa1.test
2024-06-28T07:46:37Z DEBUG --verbose=False
2024-06-28T07:46:37Z DEBUG --bind-dn=cn=Directory manager
2024-06-28T07:46:37Z DEBUG --bind-pw-file=None
2024-06-28T07:46:37Z DEBUG --cacertfile=None
2024-06-28T07:46:37Z DEBUG --subtree=[]
2024-06-28T07:46:37Z DEBUG --log-file=/var/log/ipa-migrate.log
2024-06-28T07:46:37Z DEBUG --skip-schema=False
2024-06-28T07:46:37Z DEBUG --skip-config=False
2024-06-28T07:46:37Z DEBUG --migrate-dns=False
2024-06-28T07:46:37Z DEBUG --dryrun=False
2024-06-28T07:46:37Z DEBUG --dryrun-record=None
2024-06-28T07:46:37Z DEBUG --force=False
2024-06-28T07:46:37Z DEBUG --version=False
2024-06-28T07:46:37Z DEBUG --quiet=False
2024-06-28T07:46:37Z DEBUG --schema-overwrite=False
2024-06-28T07:46:37Z DEBUG --reset-range=False
2024-06-28T07:46:37Z DEBUG --db-ldif=None
2024-06-28T07:46:37Z DEBUG --schema-ldif=None
2024-06-28T07:46:37Z DEBUG --config-ldif=None
2024-06-28T07:46:37Z DEBUG --no-prompt=True
2024-06-28T07:46:37Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA1-TEST.socket from SchemaCache
2024-06-28T07:46:37Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA1-TEST.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7fa26bbf88b0>
2024-06-28T07:46:37Z DEBUG retrieving schema for SchemaCache url=ldap://remote.ipa1.test conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7fa2658dea60>
2024-06-28T07:46:38Z DEBUG update_entry modlist [(2, 'ipamigrationenabled', [b'TRUE'])]
2024-06-28T07:46:38Z DEBUG Found realm from remote server: IPA1.TEST
2024-06-28T07:46:38Z INFO Migrating schema ...
2024-06-28T07:46:38Z DEBUG Getting schema from the remote server ...
2024-06-28T07:46:38Z DEBUG Retrieved 1538 attributes and 343 objectClasses
2024-06-28T07:46:39Z DEBUG Migrated 0 attributes and 0 objectClasses
2024-06-28T07:46:39Z DEBUG Skipped 1538 attributes and 343 objectClasses
2024-06-28T07:46:39Z INFO Migrating configuration ...
2024-06-28T07:46:39Z DEBUG Getting config from the remote server ...
2024-06-28T07:46:39Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA1-TEST.socket from SchemaCache
2024-06-28T07:46:39Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA1-TEST.socket conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7fa26bbf88b0>
2024-06-28T07:46:39Z DEBUG Config setting 'dnaMaxValue' replaced '['1417999999']' with '817399999' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config'
2024-06-28T07:46:39Z DEBUG Config setting 'dnaNextValue' replaced '['1417800002']' with '817200004' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config'
2024-06-28T07:46:39Z DEBUG update_entry modlist [(2, 'dnaNextValue', [b'817200004']), (2, 'dnaMaxValue', [b'817399999'])]
2024-06-28T07:46:40Z INFO Migrating database ... (this make take a while)
2024-06-28T07:46:40Z DEBUG Resetting the DNA range for: uid=admin,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG Resetting the DNA range for: uid=admin,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG update_entry modlist [(2, 'gidNumber', [b'-1']), (2, 'uidNumber', [b'-1'])]
2024-06-28T07:46:40Z DEBUG Resetting the DNA range for: cn=admins,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG update_entry modlist [(2, 'gidNumber', [b'-1'])]
2024-06-28T07:46:40Z DEBUG update_entry modlist [(2, 'member', [b'uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test'])]
2024-06-28T07:46:40Z DEBUG Resetting the DNA range for: cn=editors,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG update_entry modlist [(2, 'gidNumber', [b'-1'])]
2024-06-28T07:46:40Z DEBUG Skipping remote host 'fqdn=remote.ipa1.test,cn=computers,cn=accounts,dc=ipa1,dc=test' from 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa1,dc=test'
2024-06-28T07:46:40Z DEBUG Entry is different and will be updated: 'uid=sudo,cn=sysaccounts,cn=etc,dc=ipa1,dc=test' attribute 'userPassword' add val '{PBKDF2-SHA512}10000$/skBa395mOtLf6TSakXxFedUwLGw4KCa$Rxs9BBqQzSuCJcBr/Lk/qcLFNYy6EOsqvzSjfibhd6olkTB0NNv11xWeZRToayNw8KiMx9nOWcwMLzIV075Pxg==' not in ['{PBKDF2-SHA512}10000$VQFvYvb0KO/jFf93YCTs7V77TnLIbNAN$q5bF02FVHYMcxYUOHScbtieNjRzKj+jwi1Fvpsfm4HCtazh4NJZ6ur+wxhmr8njtbLW7H1FZe+tb1lX3GPVLFg==']
2024-06-28T07:46:40Z DEBUG update_entry modlist [(0, 'userPassword', [b'{PBKDF2-SHA512}10000$/skBa395mOtLf6TSakXxFedUwLGw4KCa$Rxs9BBqQzSuCJcBr/Lk/qcLFNYy6EOsqvzSjfibhd6olkTB0NNv11xWeZRToayNw8KiMx9nOWcwMLzIV075Pxg=='])]
2024-06-28T07:46:40Z DEBUG Added entry: ipaUniqueID=4f246672-351f-11ef-b442-fa163ebf3770,cn=hbac,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG Added entry: ipaUniqueID=4f28ddc4-351f-11ef-ac74-fa163ebf3770,cn=hbac,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=ldap/remote.ipa1.test@IPA1.TEST,cn=services,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:40Z DEBUG Skipping remote certificate entry: 'cn=IPA1.TEST IPA CA,cn=certificates,cn=ipa,cn=etc,dc=ipa1,dc=test' Issuer: CN=Certificate Authority,O=IPA1.TEST
2024-06-28T07:46:40Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=HTTP/remote.ipa1.test@IPA1.TEST,cn=services,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG Entry is different and will be updated: 'cn=ipa1.test,cn=ad,cn=etc,dc=ipa1,dc=test' attribute 'ipaNTDomainGUID' replaced with val '27462636-63fa-4461-8ffc-9fd8f36c16a9' old value: ['8fab2c1a-724e-4b8e-b2a6-d3323d8a0ea3']
2024-06-28T07:46:41Z DEBUG update_entry modlist [(2, 'ipaNTDomainGUID', [b'27462636-63fa-4461-8ffc-9fd8f36c16a9'])]
2024-06-28T07:46:41Z DEBUG Resetting the DNA range for: cn=Default SMB Group,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG update_entry modlist [(2, 'gidNumber', [b'-1'])]
2024-06-28T07:46:41Z DEBUG Resetting DNA range for new entry: uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG Resetting DNA range for new entry: uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG Added entry: uid=user1,cn=users,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG Resetting the DNA range for: cn=user1,cn=groups,cn=accounts,dc=ipa1,dc=test
2024-06-28T07:46:41Z DEBUG update_entry modlist [(2, 'gidNumber', [b'-1'])]
2024-06-28T07:46:41Z ERROR Failed to update "cn=user1,cn=groups,cn=accounts,dc=ipa1,dc=test" error: Server is unwilling to perform: Modifying a mapped attribute  in a managed entry is not allowed. The "gidNumber" attribute is mapped for this entry.
