[13/Apr/2017:16:10:03.080120138 +0200] conn=908 op=2 DEL dn="uid=*****,cn=users,cn=accounts,dc=***,dc=***,dc=***" [13/Apr/2017:16:10:03.725620828 +0200] conn=909 fd=166 slot=166 connection from 192.168.206.101 to 10.33.112.3 [13/Apr/2017:16:10:03.735204990 +0200] conn=909 op=0 BIND dn="uid=otrs,cn=sysaccounts,cn=etc,dc=***,dc=***,dc=***" method=128 version=3 [13/Apr/2017:16:10:04.626960193 +0200] conn=909 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=$USER,cn=sysaccounts,cn=etc,dc=***,dc=***,dc=***" [13/Apr/2017:16:10:04.652372756 +0200] conn=909 op=1 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(uid=changelog-generator)" attrs="1.1" [13/Apr/2017:16:10:05.247092721 +0200] conn=881 op=7 SRCH base="cn=accounts,dc=***,dc=***,dc=***" scope=2 filter="(&(uid=postfix)(objectClass=posixAccount)(&(uidNumber=*)(!(uidNumber=0))))" attrs="objectClass uid userPassword uidNumber gidNumber gecos homeDirectory loginShell krbPrincipalName cn memberOf ipaUniqueID ipaNTSecurityIdentifier modifyTimestamp entryusn shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag krbLastPwdChange krbPasswordExpiration pwdattribute authorizedService accountexpires useraccountcontrol nsAccountLock host logindisabled loginexpirationtime loginallowedtimemap ipaSshPubKey ipaUserAuthType" [13/Apr/2017:16:10:05.980306364 +0200] conn=805 op=108 SRCH base="cn=accounts,dc=***,dc=***,dc=***" scope=2 filter="(&(uid=apache)(objectClass=posixAccount)(&(uidNumber=*)(!(uidNumber=0))))" attrs="objectClass uid userPassword uidNumber gidNumber gecos homeDirectory loginShell krbPrincipalName cn memberOf ipaUniqueID ipaNTSecurityIdentifier modifyTimestamp entryusn shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag krbLastPwdChange krbPasswordExpiration pwdattribute authorizedService accountexpires useraccountcontrol nsAccountLock host logindisabled loginexpirationtime loginallowedtimemap ipaSshPubKey ipaUserAuthType usercertificate;binary" [13/Apr/2017:16:10:06.439597747 +0200] conn=805 op=109 SRCH base="cn=accounts,dc=***,dc=***,dc=***" scope=2 filter="(&(uid=changelog-generator)(objectClass=posixAccount)(&(uidNumber=*)(!(uidNumber=0))))" attrs="objectClass uid userPassword uidNumber gidNumber gecos homeDirectory loginShell krbPrincipalName cn memberOf ipaUniqueID ipaNTSecurityIdentifier modifyTimestamp entryusn shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag krbLastPwdChange krbPasswordExpiration pwdattribute authorizedService accountexpires useraccountcontrol nsAccountLock host logindisabled loginexpirationtime loginallowedtimemap ipaSshPubKey ipaUserAuthType usercertificate;binary" [13/Apr/2017:16:10:06.752913783 +0200] conn=805 op=110 SRCH base="cn=accounts,dc=***,dc=***,dc=***" scope=2 filter="(&(uid=postfix)(objectClass=posixAccount)(&(uidNumber=*)(!(uidNumber=0))))" attrs="objectClass uid userPassword uidNumber gidNumber gecos homeDirectory loginShell krbPrincipalName cn memberOf ipaUniqueID ipaNTSecurityIdentifier modifyTimestamp entryusn shadowLastChange shadowMin shadowMax shadowWarning shadowInactive shadowExpire shadowFlag krbLastPwdChange krbPasswordExpiration pwdattribute authorizedService accountexpires useraccountcontrol nsAccountLock host logindisabled loginexpirationtime loginallowedtimemap ipaSshPubKey ipaUserAuthType usercertificate;binary" [13/Apr/2017:16:10:11.253159398 +0200] conn=881 op=8 ABANDON targetop=7 msgid=8 nentries=0 etime=6 [13/Apr/2017:16:10:11.253289703 +0200] conn=881 op=9 UNBIND [13/Apr/2017:16:10:11.253317589 +0200] conn=881 op=9 fd=76 closed - U1 [13/Apr/2017:16:10:11.255837373 +0200] conn=910 fd=167 slot=167 connection from 192.168.206.101 to 10.33.112.3 [13/Apr/2017:16:10:11.256118953 +0200] conn=910 op=0 SRCH base="" scope=0 filter="(objectClass=*)" attrs="* altServer namingContexts supportedControl supportedExtension supportedFeatures supportedLDAPVersion supportedSASLMechanisms domaincontrollerfunctionality defaultnamingcontext lastusn highestcommittedusn aci" [13/Apr/2017:16:10:11.258708769 +0200] conn=910 op=0 RESULT err=0 tag=101 nentries=1 etime=0 [13/Apr/2017:16:10:11.267414810 +0200] conn=26 op=235 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/***.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/***.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:11.986215003 +0200] conn=805 op=111 ABANDON targetop=108 msgid=109 nentries=0 etime=6 [13/Apr/2017:16:10:11.988339332 +0200] conn=911 fd=168 slot=168 connection from 192.168.206.69 to 10.33.112.3 [13/Apr/2017:16:10:11.988749725 +0200] conn=911 op=0 SRCH base="" scope=0 filter="(objectClass=*)" attrs="* altServer namingContexts supportedControl supportedExtension supportedFeatures supportedLDAPVersion supportedSASLMechanisms domaincontrollerfunctionality defaultnamingcontext lastusn highestcommittedusn aci" [13/Apr/2017:16:10:11.991409872 +0200] conn=911 op=0 RESULT err=0 tag=101 nentries=1 etime=0 [13/Apr/2017:16:10:12.001527404 +0200] conn=30 op=227 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/£HOST.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/$HOST.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:12.269347823 +0200] conn=122 op=33 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/$HOST.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/$HOST.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:12.440724666 +0200] conn=805 op=112 ABANDON targetop=109 msgid=110 nentries=0 etime=6 [13/Apr/2017:16:10:12.754345445 +0200] conn=805 op=113 ABANDON targetop=110 msgid=111 nentries=0 etime=6 [13/Apr/2017:16:10:12.754499473 +0200] conn=805 op=114 UNBIND [13/Apr/2017:16:10:12.754529381 +0200] conn=805 op=114 fd=101 closed - U1 [13/Apr/2017:16:10:13.443867441 +0200] conn=849 op=169 EXT oid="2.16.840.1.113730.3.5.12" name="replication-multimaster-extop" [13/Apr/2017:16:10:13.444484397 +0200] conn=849 op=169 RESULT err=0 tag=120 nentries=0 etime=0 [13/Apr/2017:16:10:13.449900673 +0200] conn=849 op=170 EXT oid="2.16.840.1.113730.3.5.5" name="replication-multimaster-extop" [13/Apr/2017:16:10:15.272334464 +0200] conn=75 op=78 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/***.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/***.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:17.272724641 +0200] conn=17 op=440 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/***.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/***.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:17.997088447 +0200] conn=911 op=1 UNBIND [13/Apr/2017:16:10:17.997117297 +0200] conn=911 op=1 fd=168 closed - U1 [13/Apr/2017:16:10:18.274081725 +0200] conn=11 op=254 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/***.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/***.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:21.277873876 +0200] conn=223 op=97 SRCH base="dc=***,dc=***,dc=***" scope=2 filter="(&(|(objectClass=krbprincipalaux)(objectClass=krbprincipal)(objectClass=ipakrbprincipal))(|(ipaKrbPrincipalAlias=host/***.$DOMAIN@$REALM)(krbPrincipalName:caseIgnoreIA5Match:=host/***.$DOMAIN@$REALM)))" attrs="krbPrincipalName krbCanonicalName krbUPEnabled krbPrincipalKey krbTicketPolicyReference krbPrincipalExpiration krbPasswordExpiration krbPwdPolicyReference krbPrincipalType krbPwdHistory krbLastPwdChange krbPrincipalAliases krbLastSuccessfulAuth krbLastFailedAuth krbLoginFailedCount krbPrincipalAuthInd krbExtraData krbLastAdminUnlock krbObjectReferences krbTicketFlags krbMaxTicketLife krbMaxRenewableAge nsAccountLock passwordHistory ipaKrbAuthzData ipaUserAuthType ipatokenRadiusConfigLink objectClass" [13/Apr/2017:16:10:23.559283165 +0200] conn=910 op=1 BIND dn="" method=sasl version=3 mech=GSSAPI [13/Apr/2017:16:10:23.565088097 +0200] conn=910 op=1 RESULT err=14 tag=97 nentries=0 etime=0, SASL bind in progress [13/Apr/2017:16:10:23.567461005 +0200] conn=910 op=2 BIND dn="" method=sasl version=3 mech=GSSAPI [13/Apr/2017:16:10:23.570063057 +0200] conn=910 op=2 RESULT err=14 tag=97 nentries=0 etime=0, SASL bind in progress [13/Apr/2017:16:10:23.570806475 +0200] conn=910 op=3 BIND dn="" method=sasl version=3 mech=GSSAPI