1
|
Script started on mer 02 ago 2017 17:06:23 CEST
|
2
|
|
3
|
root@250905waula05:~# fuss-client -av
|
4
|
INFO Adding the machine
|
5
|
|
6
|
Authenticating on the server.
|
7
|
|
8
|
We are now going to let the server know that this client
|
9
|
is authorized; do to so we will have to enter the root
|
10
|
password for the server twice.
|
11
|
|
12
|
Depending on the server load there could be a long
|
13
|
delay; this is perfectly normal.
|
14
|
|
15
|
The authenticity of host 'proxy (192.168.1.1)' can't be established.
|
16
|
ECDSA key fingerprint is 62:11:8b:9e:be:80:fe:be:0a:1d:58:17:2c:d2:c8:0e.
|
17
|
Are you sure you want to continue connecting (yes/no)? yes
|
18
|
Warning: Permanently added 'proxy,192.168.1.1' (ECDSA) to the list of known hosts.
|
19
|
|
20
|
root@proxy's password:
|
21
|
Authenticating as principal root/admin@VERDI.SLR with password.
|
22
|
kadmin.local: addprinc -randkey nfs/250905waula05.verdi.slr@VERDI.SLR
|
23
|
WARNING: no policy specified for nfs/250905waula05.verdi.slr@VERDI.SLR; defaulting to no policy
|
24
|
Principal "nfs/250905waula05.verdi.slr@VERDI.SLR" created.
|
25
|
kadmin.local: ktadd -k /root/250905waula05.keytab nfs/250905waula05.verdi.sl
|
26
|
<ot/250905waula05.keytab nfs/250905waula05.verdi.slr @VERDI.SLR
|
27
|
Entry for principal nfs/250905waula05.verdi.slr@VERDI.SLR with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/root/250905waula05.keytab.
|
28
|
Entry for principal nfs/250905waula05.verdi.slr@VERDI.SLR with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/root/250905waula05.keytab.
|
29
|
Entry for principal nfs/250905waula05.verdi.slr@VERDI.SLR with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/root/250905waula05.keytab.
|
30
|
Entry for principal nfs/250905waula05.verdi.slr@VERDI.SLR with kvno 2, encryption type des-cbc-crc added to keytab WRFILE:/root/250905waula05.keytab.
|
31
|
kadmin.local: ktutil: read_kt /root/250905waula05.keytab
|
32
|
ktutil: write_kt /etc/krb5.keytab
|
33
|
ktutil: quit
|
34
|
root@proxy's password:
|
35
|
|
36
|
250905waula05.keytab 0% 0 0.0KB/s --:-- ETA
|
37
|
250905waula05.keytab 100% 322 0.3KB/s 00:00
|
38
|
root@proxy's password:
|
39
|
|
40
|
PLAY [Connect a Fuss client] ***************************************************
|
41
|
|
42
|
TASK [setup] *******************************************************************
|
43
|
[0;32mok: [localhost][0m
|
44
|
|
45
|
TASK [network : Configure interfaces] ******************************************
|
46
|
[0;33mchanged: [localhost][0m
|
47
|
|
48
|
TASK [network : save /etc/network/interfaces] **********************************
|
49
|
[0;36mincluded: /usr/share/fuss-client/includes/list-backup.yml for localhost[0m
|
50
|
|
51
|
TASK [network : list backup] ***************************************************
|
52
|
[0;33mchanged: [localhost] => (item={u'src': u'/root/.ansible/tmp/ansible-tmp-1501686401.91-211242844314707/source', 'changed': True, u'backup_file': u'/etc/network/interfaces.959.2017-08-02@17:06:42~', u'uid': 0, u'dest': u'/etc/network/interfaces', u'checksum': u'02f9e1abb20b45f10a23b79eac50635a3546b819', u'md5sum': u'1db88d44505efb89121b4056bbb6e986', u'state': u'file', u'gid': 0, u'mode': u'0644', u'owner': u'root', u'group': u'root', u'size': 64})[0m
|
53
|
|
54
|
TASK [network : Set proxy for wget] ********************************************
|
55
|
[0;33mchanged: [localhost][0m
|
56
|
|
57
|
TASK [network : save /etc/wgetrc] **********************************************
|
58
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
59
|
|
60
|
TASK [network : find existing backups] *****************************************
|
61
|
[0;32mok: [localhost][0m
|
62
|
|
63
|
TASK [network : get right backup] **********************************************
|
64
|
[0;32mok: [localhost][0m
|
65
|
|
66
|
TASK [network : list backup] ***************************************************
|
67
|
[0;33mchanged: [localhost][0m
|
68
|
|
69
|
TASK [network : Set proxy for environment] *************************************
|
70
|
[0;33mchanged: [localhost][0m
|
71
|
|
72
|
TASK [network : save /etc/environment] *****************************************
|
73
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
74
|
|
75
|
TASK [network : find existing backups] *****************************************
|
76
|
[0;32mok: [localhost][0m
|
77
|
|
78
|
TASK [network : get right backup] **********************************************
|
79
|
[0;32mok: [localhost][0m
|
80
|
|
81
|
TASK [network : list backup] ***************************************************
|
82
|
[0;33mchanged: [localhost][0m
|
83
|
|
84
|
TASK [network : Make sure that lightdm is loading environment variables] *******
|
85
|
[0;33mchanged: [localhost][0m
|
86
|
|
87
|
TASK [network : save /etc/pam.d/lightdm] ***************************************
|
88
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
89
|
|
90
|
TASK [network : find existing backups] *****************************************
|
91
|
[0;32mok: [localhost][0m
|
92
|
|
93
|
TASK [network : get right backup] **********************************************
|
94
|
[0;32mok: [localhost][0m
|
95
|
|
96
|
TASK [network : list backup] ***************************************************
|
97
|
[0;33mchanged: [localhost][0m
|
98
|
|
99
|
TASK [network : Set proxy for apt] *********************************************
|
100
|
[0;33mchanged: [localhost][0m
|
101
|
|
102
|
TASK [network : save /etc/apt/apt.conf] ****************************************
|
103
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
104
|
|
105
|
TASK [network : find existing backups] *****************************************
|
106
|
[0;36mskipping: [localhost][0m
|
107
|
|
108
|
TASK [network : get right backup] **********************************************
|
109
|
[0;36mskipping: [localhost][0m
|
110
|
|
111
|
TASK [network : list backup] ***************************************************
|
112
|
[0;36mskipping: [localhost][0m
|
113
|
|
114
|
TASK [network : Configure timesyncd to use our server] *************************
|
115
|
[0;33mchanged: [localhost][0m
|
116
|
|
117
|
TASK [network : save /etc/systemd/timesyncd.conf] ******************************
|
118
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
119
|
|
120
|
TASK [network : find existing backups] *****************************************
|
121
|
[0;32mok: [localhost][0m
|
122
|
|
123
|
TASK [network : get right backup] **********************************************
|
124
|
[0;32mok: [localhost][0m
|
125
|
|
126
|
TASK [network : list backup] ***************************************************
|
127
|
[0;33mchanged: [localhost][0m
|
128
|
|
129
|
TASK [network : enable timesyncd] **********************************************
|
130
|
[0;33mchanged: [localhost][0m
|
131
|
|
132
|
TASK [homes : Configure local home directories] ********************************
|
133
|
[0;36mskipping: [localhost][0m
|
134
|
|
135
|
TASK [homes : Do not configure local home directories] *************************
|
136
|
[0;32mok: [localhost][0m
|
137
|
|
138
|
TASK [homes : save /etc/pam.d/common-session] **********************************
|
139
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
140
|
|
141
|
TASK [homes : find existing backups] *******************************************
|
142
|
[0;36mskipping: [localhost][0m
|
143
|
|
144
|
TASK [homes : get right backup] ************************************************
|
145
|
[0;36mskipping: [localhost][0m
|
146
|
|
147
|
TASK [homes : list backup] *****************************************************
|
148
|
[0;36mskipping: [localhost][0m
|
149
|
|
150
|
TASK [homes : Check if kerberos has already been configured] *******************
|
151
|
[0;32mok: [localhost][0m
|
152
|
|
153
|
TASK [homes : Remove kerberos packages if installed but not configured] ********
|
154
|
[0;33mchanged: [localhost][0m
|
155
|
|
156
|
TASK [homes : Set a default domain name if needed] *****************************
|
157
|
[0;36mskipping: [localhost][0m
|
158
|
|
159
|
TASK [homes : Stop if no domain is available] **********************************
|
160
|
[0;36mskipping: [localhost][0m
|
161
|
|
162
|
TASK [homes : Preseed kerberos server] *****************************************
|
163
|
[0;33mchanged: [localhost][0m
|
164
|
|
165
|
TASK [homes : Preseed kerberos admin server] ***********************************
|
166
|
[0;33mchanged: [localhost][0m
|
167
|
|
168
|
TASK [homes : Preseed kerberos default realm] **********************************
|
169
|
[0;33mchanged: [localhost][0m
|
170
|
|
171
|
TASK [homes : install kerberos client packages] ********************************
|
172
|
[0;36mincluded: /usr/share/fuss-client/includes/install-package-apt.yml for localhost[0m
|
173
|
|
174
|
TASK [homes : Install package nfs-common,krb5-user,krb5-config,libpam-krb5 by apt] ***
|
175
|
[0;33mchanged: [localhost][0m
|
176
|
|
177
|
TASK [homes : Configure kerberos realm] ****************************************
|
178
|
[0;33mchanged: [localhost][0m
|
179
|
|
180
|
TASK [homes : enable idmapd] ***************************************************
|
181
|
[0;33mchanged: [localhost][0m
|
182
|
|
183
|
TASK [homes : save /etc/default/nfs-common] ************************************
|
184
|
[0;36mincluded: /usr/share/fuss-client/includes/find-and-list-backup.yml for localhost[0m
|
185
|
|
186
|
TASK [homes : find existing backups] *******************************************
|
187
|
[0;32mok: [localhost][0m
|
188
|
|
189
|
TASK [homes : get right backup] ************************************************
|
190
|
[0;32mok: [localhost][0m
|
191
|
|
192
|
TASK [homes : list backup] *****************************************************
|
193
|
[0;33mchanged: [localhost][0m
|
194
|
|
195
|
TASK [homes : enable gssd] *****************************************************
|
196
|
[0;33mchanged: [localhost][0m
|
197
|
|
198
|
TASK [homes : check if we already have a key for this client] ******************
|
199
|
[0;32mok: [localhost][0m
|
200
|
|
201
|
TASK [homes : install the existing client key] *********************************
|
202
|
[0;33mchanged: [localhost][0m
|
203
|
|
204
|
TASK [homes : Password required] ***********************************************
|
205
|
[0;32mok: [localhost] => {
|
206
|
"msg": "The following task will ask you for the server root password, twice,\nto create a key for this host on the server and then to copy it\non this machine.\n"
|
207
|
}[0m
|
208
|
|
209
|
TASK [homes : Generate a key for this client on the server (root)] *************
|
210
|
[0;32mok: [localhost][0m
|
211
|
|
212
|
TASK [homes : check permissions on /etc/krb5.keytab] ***************************
|
213
|
[0;32mok: [localhost][0m
|
214
|
|
215
|
TASK [homes : Configure user mapping in /etc/idmapd.conf] **********************
|
216
|
[0;33mchanged: [localhost][0m
|
217
|
|
218
|
TASK [homes : save /etc/idmapd.conf] *******************************************
|
219
|
[0;36mincluded: /usr/share/fuss-client/includes/list-backup.yml for localhost[0m
|
220
|
|
221
|
TASK [homes : list backup] *****************************************************
|
222
|
[0;33mchanged: [localhost] => (item={u'src': u'/root/.ansible/tmp/ansible-tmp-1501686436.64-257774400038181/source', 'changed': True, u'backup_file': u'/etc/idmapd.conf.2486.2017-08-02@17:07:16~', u'uid': 0, u'dest': u'/etc/idmapd.conf', u'checksum': u'a680e8de1d2b92e026b7818dbc7db93235152bde', u'md5sum': u'6514f938192f2c9a3e317959d378836f', u'state': u'file', u'gid': 0, u'mode': u'0644', u'owner': u'root', u'group': u'root', u'size': 258})[0m
|
223
|
|
224
|
TASK [homes : Configure pam common auth] ***************************************
|
225
|
[0;33mchanged: [localhost][0m
|
226
|
|
227
|
TASK [homes : save /etc/pam.d/common-auth] *************************************
|
228
|
[0;36mincluded: /usr/share/fuss-client/includes/list-backup.yml for localhost[0m
|
229
|
|
230
|
TASK [homes : list backup] *****************************************************
|
231
|
[0;33mchanged: [localhost] => (item={u'src': u'/root/.ansible/tmp/ansible-tmp-1501686437.14-211261024926360/source', 'changed': True, u'backup_file': u'/etc/pam.d/common-auth.2542.2017-08-02@17:07:17~', u'uid': 0, u'dest': u'/etc/pam.d/common-auth', u'checksum': u'7999bcb80ef7ad9cb6b82a7a8f6f6d8e3a63044e', u'md5sum': u'5975dcf3c0964844253b2a7f7a3f2295', u'state': u'file', u'gid': 0, u'mode': u'0644', u'owner': u'root', u'group': u'root', u'size': 1458})[0m
|
232
|
|
233
|
TASK [homes : Configure pam common password] ***********************************
|
234
|
[0;33mchanged: [localhost][0m
|
235
|
|
236
|
TASK [homes : save /etc/pam.d/common-password] *********************************
|
237
|
[0;36mincluded: /usr/share/fuss-client/includes/list-backup.yml for localhost[0m
|
238
|
|
239
|
TASK [homes : list backup] *****************************************************
|
240
|
[0;33mchanged: [localhost] => (item={u'src': u'/root/.ansible/tmp/ansible-tmp-1501686437.94-88161645941112/source', 'changed': True, u'backup_file': u'/etc/pam.d/common-password.2598.2017-08-02@17:07:18~', u'uid': 0, u'dest': u'/etc/pam.d/common-password', u'checksum': u'7070606bfbd54eecd57274c9dbc47c7824b361bb', u'md5sum': u'6e0df55c99b76201e65aa4c7501dd91d', u'state': u'file', u'gid': 0, u'mode': u'0644', u'owner': u'root', u'group': u'root', u'size': 1844})[0m
|
241
|
|
242
|
RUNNING HANDLER [network : restart networking] *********************************
|
243
|
[0;33mchanged: [localhost][0m
|
244
|
|
245
|
RUNNING HANDLER [homes : restart nfs-common] ***********************************
|
246
|
[0;33mchanged: [localhost][0m
|
247
|
|
248
|
TASK [homes : Configure nfs home directories] **********************************
|
249
|
[0;33mchanged: [localhost][0m
|
250
|
|
251
|
TASK [homes : Install home.mount] **********************************************
|
252
|
[0;33mchanged: [localhost][0m
|
253
|
|
254
|
TASK [homes : Remount /home] ***************************************************
|
255
|
[0;33mchanged: [localhost][0m
|
256
|
|
257
|
TASK [ldap : Install needed auth-related programs] *****************************
|
258
|
[0;36mincluded: /usr/share/fuss-client/includes/install-package-apt.yml for localhost[0m
|
259
|
[0;36mincluded: /usr/share/fuss-client/includes/install-package-apt.yml for localhost[0m
|
260
|
|
261
|
TASK [ldap : Install package libpam-foreground,libpam-cracklib by apt] *********
|
262
|
[0;32mok: [localhost][0m
|
263
|
|
264
|
TASK [ldap : Install package ldap-utils by apt] ********************************
|
265
|
[0;32mok: [localhost][0m
|
266
|
|
267
|
TASK [ldap : Remove packages that require preseeding] **************************
|
268
|
[0;33mchanged: [localhost][0m
|
269
|
|
270
|
TASK [ldap : Preseed libnss-ldapd for NSS switch service to configure] *********
|
271
|
[0;32mok: [localhost][0m
|
272
|
|
273
|
TASK [ldap : Preseed nslcd LDAP server URI] ************************************
|
274
|
[0;33mchanged: [localhost][0m
|
275
|
|
276
|
TASK [ldap : Preseed debconf LDAP base DN] *************************************
|
277
|
[0;33mchanged: [localhost][0m
|
278
|
|
279
|
TASK [ldap : Install ldap packages] ********************************************
|
280
|
[0;36mincluded: /usr/share/fuss-client/includes/install-package-apt.yml for localhost[0m
|
281
|
|
282
|
TASK [ldap : Install package nslcd,libpam-ldapd,libnss-ldapd by apt] ***********
|
283
|
[0;31mfatal: [localhost]: FAILED! => {"cache_update_time": 1501686362, "cache_updated": false, "changed": false, "failed": true, "msg": "'/usr/bin/apt-get -y -o \"Dpkg::Options::=--force-confdef\" -o \"Dpkg::Options::=--force-confold\" install 'nslcd' 'libpam-ldapd' 'libnss-ldapd'' failed: E: There are problems and -y was used without --force-yes\n", "stderr": "E: There are problems and -y was used without --force-yes\n", "stdout": "Reading package lists...\nBuilding dependency tree...\nReading state information...\nThe following packages were automatically installed and are no longer required:\n libck-connector0 libpam-ck-connector libpam-cracklib libpam-foreground\n octofuss-client python3-cffi python3-characteristic python3-cryptography\n python3-dbus python3-netifaces python3-openssl python3-ply python3-psutil\n python3-pyasn1 python3-pyasn1-modules python3-pycparser\n python3-service-identity python3-twisted python3-yaml python3-zope.interface\n ssh\nUse 'apt-get autoremove' to remove them.\nThe following extra packages will be installed:\n nscd nslcd-utils\nSuggested packages:\n kstart\nThe following NEW packages will be installed:\n libnss-ldapd libpam-ldapd nscd nslcd nslcd-utils\n0 upgraded, 5 newly installed, 0 to remove and 207 not upgraded.\nNeed to get 653 kB of archives.\nAfter this operation, 1146 kB of additional disk space will be used.\nWARNING: The following packages cannot be authenticated!\n nscd\n", "stdout_lines": ["Reading package lists...", "Building dependency tree...", "Reading state information...", "The following packages were automatically installed and are no longer required:", " libck-connector0 libpam-ck-connector libpam-cracklib libpam-foreground", " octofuss-client python3-cffi python3-characteristic python3-cryptography", " python3-dbus python3-netifaces python3-openssl python3-ply python3-psutil", " python3-pyasn1 python3-pyasn1-modules python3-pycparser", " python3-service-identity python3-twisted python3-yaml python3-zope.interface", " ssh", "Use 'apt-get autoremove' to remove them.", "The following extra packages will be installed:", " nscd nslcd-utils", "Suggested packages:", " kstart", "The following NEW packages will be installed:", " libnss-ldapd libpam-ldapd nscd nslcd nslcd-utils", "0 upgraded, 5 newly installed, 0 to remove and 207 not upgraded.", "Need to get 653 kB of archives.", "After this operation, 1146 kB of additional disk space will be used.", "WARNING: The following packages cannot be authenticated!", " nscd"]}[0m
|
284
|
to retry, use: --limit @/usr/share/fuss-client/connect.retry
|
285
|
|
286
|
PLAY RECAP *********************************************************************
|
287
|
[0;31mlocalhost[0m : [0;32mok=71 [0m [0;33mchanged=36 [0m unreachable=0 [0;31mfailed=1 [0m
|
288
|
|
289
|
root@250905waula05:~# date
|
290
|
mer 2 ago 2017, 17.11.18, CEST
|
291
|
root@250905waula05:~# exit
|
292
|
exit
|
293
|
|
294
|
Script done on mer 02 ago 2017 17:11:27 CEST
|