Hello,
I am using SSSD with LDAP directory which provides public keys for each user entry to SSSD. I am not sure if it is possible to configure SSSD not just to accept the private key (provided by the user during the login) and authenticate the user from LDAP (where his public ke is stored), but also to check the: - trust (validation of the CA used for signing the user's certificate i.e. public key) - validity of a user certificate with its public key (its "from" - "to" dates) - revocation status (configuration of SSSD with CRL lists or OCSP) or should I manage this on the LDAP side or on application level or somewhere else? I would be grateful if you share your ideas about the possible solutions of this situation!
BR, Hristina
On Wed, Feb 26, 2020 at 09:38:21AM -0000, Hristina Marosevic wrote:
Hello,
I am using SSSD with LDAP directory which provides public keys for each user entry to SSSD. I am not sure if it is possible to configure SSSD not just to accept the private key (provided by the user during the login) and authenticate the user from LDAP (where his public ke is stored), but also to check the:
- trust (validation of the CA used for signing the user's certificate i.e. public key)
- validity of a user certificate with its public key (its "from" - "to" dates)
- revocation status (configuration of SSSD with CRL lists or OCSP)
or should I manage this on the LDAP side or on application level or somewhere else? I would be grateful if you share your ideas about the possible solutions of this situation!
Hi,
if you are thinking of using ssh to log in then SSSD can already handle this.
SSSD can read the certificate for the user form the LDAP entry, validate it and if valid make the derived ssh-key available to sshd with the help of the sss_ssh_authorizedkeys utility.
Please check the option 'certificate_verification' and it's sub-options in the sssd.conf man page for details. Also check the 'SSH configuration options' section about how to configure SSSD's ssh responder. The sss_ssh_authorizedkeys man page explains how to make sshd use the utility.
HTH
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
Thank you for information. I can use this options (OCSP URL, trust cert location) once I make SSSD derive public keys from user certificate which is a problem that I can not solve, so far. The default mapping of the user certificate is from userCertificate;binary LDAP attribute to SSSD option ldap_user_certificate, but when I have only the certificate in the LDAP entry (and not the public key, also - as a value of another attribute of the entry - later configured in sssd), the key is not derived. Another combination that I have tried is storing the user certificate in the userCertificate;binary attribute and storing the exported public key as a value of another LDAP attribute but it didn't prove to be a solution - this is like that because I experimented cases with different public key and user certificate for one user and the user was accepted without problem - which means that SSSD did not validated the public key against the user certificate provided by LDAP
Can you please give me instructions on how to configure SSSD to derive the publiy key from a user certificate (I would like to store only the user certificate in LDAP, not the user certificate and the exported public key - if possible)?
BR, Hristina
On Tue, Mar 03, 2020 at 04:38:16PM -0000, Hristina Marosevic wrote:
Hello,
Thank you for information. I can use this options (OCSP URL, trust cert location) once I make SSSD derive public keys from user certificate which is a problem that I can not solve, so far. The default mapping of the user certificate is from userCertificate;binary LDAP attribute to SSSD option ldap_user_certificate, but when I have only the certificate in the LDAP entry (and not the public key, also - as a value of another attribute of the entry - later configured in sssd), the key is not derived. Another combination that I have tried is storing the user certificate in the userCertificate;binary attribute and storing the exported public key as a value of another LDAP attribute but it didn't prove to be a solution - this is like that because I experimented cases with different public key and user certificate for one user and the user was accepted without problem - which means that SSSD did not validated the public key against the user certificate provided by LDAP
Can you please give me instructions on how to configure SSSD to derive the publiy key from a user certificate (I would like to store only the user certificate in LDAP, not the user certificate and the exported public key - if possible)?
Hi,
just using the certificate is the expected way how to do it.
In which LDAP attribute is you certificate stored and in which format? Can you send an example of an LDAP user object with all attributes? The attribute value can be sanitized if needed but it would be helpful to see the real attribute names.
Can you send your current sssd.conf as well since this would help tp see what might be missing.
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
I forgot to mention the LDAP implementation I am using - it is OUD (Oracle Unified Directory). Object class "strongAuthenticationUser" was added to the users for PKI based authentication. The mandatory attribute od this object class is "userCertificate" or "userCertificate;binary" in which I would store the value of the public key or the certificate. Case 1. I stored the certificate in the userCertificate;binary LDAP attribute as this was the default configuration Case 2. I also tried to store the certificate as a value of the LDAP attribute userCertificate and changed "ldap_user_certificate" to "userCertificate" in SSSD configuration (commented in the SSSD configuration bellow) Both of the cases resulted in password based authentication, instead of PKI based authentication. Also in the log I saw that SSSD mapped userCertificate(;binary) value to userCertificate parameter of the entry but I didn't see a derived public key in the logs. I am using x509 base64 encoded value od the certificate (also I tried with pkcs#7 but the result was the same)
# SSSD configuration at this moment: I am using only public key stored as a value of the attribute "userCertificate" for authentication of the user which works fine - but this way, there is no certificate shown to SSSD client, hence - no certificate validation/verification mechanisms can be used (correct me if I am wrong) [sssd] config_file_version = 2 domains = LDAP services = nss, pam, autofs, ssh reconnection_retries = 3
[nss] reconnection_retries = 3 debug_level = 2 filter_users = root, oracle filter_groups = root
[pam] reconnection_retries = 3 debug_level = 2
[domain/LDAP] id_provider = ldap access_provider = ldap chpass_provider = ldap ldap_schema = rfc2307 ldap_uri = ldaps://<OUD_instance>:<LDAPs_port> ldap_default_bind_dn = <directory_manager> ldap_default_authtok = <password> ldap_default_authtok_type = password ldap_search_base = <suffix> ldap_user_search_base = <users_branch,suffix> ldap_group_search_base = <groups_branch,suffix> ldap_access_filter = isMemberOf=<access_filter_group> cache_credentials = true enumerate = false debug_level = 9 ldap_id_use_start_tls = false ldap_tls_reqcert = demand ldap_tls_cacert = /etc/sssd/cacerts/<CA_cert.pem> ldap_tls_cacertdir = /etc/sssd/cacerts ldap_user_name = employeeNumber ldap_user_ssh_public_key = userCertificate #ldap_user_certificate = userCertificate
# LDAP entry at this moment (only with public key value stored in "userCertificate" attribute) dn: uid=32000000001,<users_branch,suffix> givenName: testUser7 objectClass: strongAuthenticationUser objectClass: person objectClass: inetOrgPerson objectClass: organizationalPerson objectClass: posixAccount objectClass: top uid: 32000000001 cn: 32000000001 sn: test loginShell: /bin/bash userPassword: {SSHA512}0QAWd8NQNpN5bVS/sS0CDjHzctpy54X/JflWRSzIk/zpgSEgm5IE003RX v35iEyt2LfqaXd5HGAwYrCaRbM7ylrg0syFXrLU homeDirectory: /ssh_users/32000000001 ou: <directoy_manager> uidNumber: 1234567890 userCertificate: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCPZF7auTI3Tj/urnpX7YbG3jh Qq4z0HcqW8JA4CKGrNOeBSbyh4H1/WqVR72zKzSu/2rRTG3679YMWy6hZBz7Of7tnQ6OBlmZmAxyFkk UU1ZVRKFRyVWBzmT8YqOjetdaYEr4f9cjOV22EStPJCheZmyyMRMOtlTA32dQ7rWBLcjpkLFQZhInbn H5JUEEuiVTKXZ5xDRzpLCVNx/VFyLxHgPjfv0mWOGp3tVCBRYnmW/82pOcvYGQtSJbsL9LyIsuJWVNz JWQa2v4grNf3OCuWO6wIiPaJcnYNtvRtNHCtexPicJ7iaCmgjxgWsUKCyaVIFNn+STgR81zl59lrmfD D gidNumber: 9999 employeeNumber: <employee_number>
When using certificate only or certificate and public key stored in the LDAP entry, the value of the certificate stored in the userCertificate;binary attribute is: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCC sGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z 6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=
Thank you! BR, Hristina
On Wed, Mar 04, 2020 at 07:29:14AM -0000, Hristina Marosevic wrote:
Hello,
I forgot to mention the LDAP implementation I am using - it is OUD (Oracle Unified Directory). Object class "strongAuthenticationUser" was added to the users for PKI based authentication. The mandatory attribute od this object class is "userCertificate" or "userCertificate;binary" in which I would store the value of the public key or the certificate. Case 1. I stored the certificate in the userCertificate;binary LDAP attribute as this was the default configuration Case 2. I also tried to store the certificate as a value of the LDAP attribute userCertificate and changed "ldap_user_certificate" to "userCertificate" in SSSD configuration (commented in the SSSD configuration bellow) Both of the cases resulted in password based authentication, instead of PKI based authentication. Also in the log I saw that SSSD mapped userCertificate(;binary) value to userCertificate parameter of the entry but I didn't see a derived public key in the logs. I am using x509 base64 encoded value od the certificate (also I tried with pkcs#7 but the result was the same)
# SSSD configuration at this moment: I am using only public key stored as a value of the attribute "userCertificate" for authentication of the user which works fine - but this way, there is no certificate shown to SSSD client, hence - no certificate validation/verification mechanisms can be used (correct me if I am wrong) [sssd] config_file_version = 2 domains = LDAP services = nss, pam, autofs, ssh reconnection_retries = 3
[nss] reconnection_retries = 3 debug_level = 2 filter_users = root, oracle filter_groups = root
[pam] reconnection_retries = 3 debug_level = 2
[domain/LDAP] id_provider = ldap access_provider = ldap chpass_provider = ldap ldap_schema = rfc2307 ldap_uri = ldaps://<OUD_instance>:<LDAPs_port> ldap_default_bind_dn = <directory_manager> ldap_default_authtok = <password> ldap_default_authtok_type = password ldap_search_base = <suffix> ldap_user_search_base = <users_branch,suffix> ldap_group_search_base = <groups_branch,suffix> ldap_access_filter = isMemberOf=<access_filter_group> cache_credentials = true enumerate = false debug_level = 9 ldap_id_use_start_tls = false ldap_tls_reqcert = demand ldap_tls_cacert = /etc/sssd/cacerts/<CA_cert.pem> ldap_tls_cacertdir = /etc/sssd/cacerts ldap_user_name = employeeNumber ldap_user_ssh_public_key = userCertificate #ldap_user_certificate = userCertificate
# LDAP entry at this moment (only with public key value stored in "userCertificate" attribute) dn: uid=32000000001,<users_branch,suffix> givenName: testUser7 objectClass: strongAuthenticationUser objectClass: person objectClass: inetOrgPerson objectClass: organizationalPerson objectClass: posixAccount objectClass: top uid: 32000000001 cn: 32000000001 sn: test loginShell: /bin/bash userPassword: {SSHA512}0QAWd8NQNpN5bVS/sS0CDjHzctpy54X/JflWRSzIk/zpgSEgm5IE003RX v35iEyt2LfqaXd5HGAwYrCaRbM7ylrg0syFXrLU homeDirectory: /ssh_users/32000000001 ou: <directoy_manager> uidNumber: 1234567890 userCertificate: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCPZF7auTI3Tj/urnpX7YbG3jh Qq4z0HcqW8JA4CKGrNOeBSbyh4H1/WqVR72zKzSu/2rRTG3679YMWy6hZBz7Of7tnQ6OBlmZmAxyFkk UU1ZVRKFRyVWBzmT8YqOjetdaYEr4f9cjOV22EStPJCheZmyyMRMOtlTA32dQ7rWBLcjpkLFQZhInbn H5JUEEuiVTKXZ5xDRzpLCVNx/VFyLxHgPjfv0mWOGp3tVCBRYnmW/82pOcvYGQtSJbsL9LyIsuJWVNz JWQa2v4grNf3OCuWO6wIiPaJcnYNtvRtNHCtexPicJ7iaCmgjxgWsUKCyaVIFNn+STgR81zl59lrmfD D gidNumber: 9999 employeeNumber: <employee_number>
Hi,
with 'ldap_user_ssh_public_key = userCertificate' this should work, i.e. calling 'sss_ssh_authorizedkeys testUser7' should return the ssh key from above. If there is no output I need the SSSD ssh and domain logs to understand why this fails.
When using certificate only or certificate and public key stored in the LDAP entry, the value of the certificate stored in the userCertificate;binary attribute is: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCC sGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z 6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=
Are the line break added by you or is this the real output? For certificates you have to user 'userCertificate;binary' and store the certificates as binaries in LDAP. When you use the ldapsearch command the output should be:
userCertificate;binary:: MIIGMTCC....
Please note the '::' which indicates that the attribute value is a binary and that it is encoded in base64 to be able to print the output.
bye, Sumit
Thank you! BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Wed, Mar 04, 2020 at 07:29:14AM -0000, Hristina Marosevic wrote:
Hi,
with 'ldap_user_ssh_public_key = userCertificate' this should work, i.e. calling 'sss_ssh_authorizedkeys testUser7' should return the ssh key from above. If there is no output I need the SSSD ssh and domain logs to understand why this fails.
Yes, this is working, but this is only an exported private key and no certificate is sither stored in the LDAP's entry or used by SSSD.
Are the line break added by you or is this the real output? For certificates you have to user 'userCertificate;binary' and store the certificates as binaries in LDAP. When you use the ldapsearch command the output should be:
userCertificate;binary:: MIIGMTCC....
Please note the '::' which indicates that the attribute value is a binary and that it is encoded in base64 to be able to print the output.
The lines don't exist in the LDAP entry. Is the .cer x509 compatible format for storing into LDAP's attribute userCertificate;binary? As I know, so far this is Base64 encoded format (pls correct me if I am wrong) And should I manually add "::" or the LDAP should do that after modifying the entry by adding the binary format of the user certificate? (when user certificate is added without "::" ldapsearch retrieves the user certificate only with "userCertificate;binary: MIIGMTCC...."
BR, Hristina
On Wed, Mar 04, 2020 at 02:12:30PM -0000, Hristina Marosevic wrote:
On Wed, Mar 04, 2020 at 07:29:14AM -0000, Hristina Marosevic wrote:
Hi,
with 'ldap_user_ssh_public_key = userCertificate' this should work, i.e. calling 'sss_ssh_authorizedkeys testUser7' should return the ssh key from above. If there is no output I need the SSSD ssh and domain logs to understand why this fails.
Yes, this is working, but this is only an exported private key and no certificate is sither stored in the LDAP's entry or used by SSSD.
Are the line break added by you or is this the real output? For certificates you have to user 'userCertificate;binary' and store the certificates as binaries in LDAP. When you use the ldapsearch command the output should be:
userCertificate;binary:: MIIGMTCC....
Please note the '::' which indicates that the attribute value is a binary and that it is encoded in base64 to be able to print the output.
The lines don't exist in the LDAP entry. Is the .cer x509 compatible format for storing into LDAP's attribute userCertificate;binary? As I know, so far this is Base64 encoded format (pls correct me if I am wrong) And should I manually add "::" or the LDAP should do that after modifying the entry by adding the binary format of the user certificate? (when user certificate is added without "::" ldapsearch retrieves the user certificate only with "userCertificate;binary: MIIGMTCC...."
Hi,
how do you add the certificate to the LDAP entry?
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
By using ldapmodify command and ldif file as input.
# ldif file: dn: uid=32000000001,<users_branch,suffix> changetype: modify add: userCertificate;binary userCertificate;binary: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMF UwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM 922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=
BR, Hristina
So, I am not sure if I should use
userCertificate;binary:: MIIGMT..
in the ldif file.
Also, should I add the -----BEGIN CERTIFICATE-----/-----END CERTIFICATE----- (now I am adding only the content between these lines as a value of the userCertificate;binary attribute) ? and if yes, should they be base64 encoded, too?
I added the content between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- from the base64 user certificate and during authentication in the logs I saw that the user certificate was stored in the user certificate SSSD option but there was no public key derived. This time I deleted the public key and during authentication I was using only userCertificate;binary attrbiute wit hthe default SSSD configuration for mapping the certificate.
This is from the SSSD_LDAP.log
(Thu Mar 5 15:16:19 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [0\82\0610\82\04\19\A0\03\02\01\02\02\14}\85\99\DB]\B02\D7\8A\D28\E7\9Dwzv\A9j\90\890\0D\06\09\2A\86H\86\F7\0D\01\01\0B\05\000-1\0B0\09\06\03U\04\06\13\02KZ1\1E0\1C\06\03U\04\03\0C\15\D2\B0\D0\9A\D0\9E\203.0\20\28RSA\20TEST\290\1E\17\0D190404085454Z\17\0D210403085454Z0\81\AF1\220\20\06\03U\04\03\0C\19\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\20\D0\A2\D0\95\D0\A1\D0\A2\D0\A21\170\15\06\03U\04\04\0C\0E\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\921\180\16\06\03U\04\05\13\0FIIN1234567890121\0B0\09\06\03U\04\06\13\02KZ1\150\13\06\03U\04\07\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\150\13\06\03U\04\08\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\1B0\19\06\03U\04\2A\0C\12\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\D0\98\D0\A70\82\01\220\0D\06\09\2A\86H\86\F7\0D\01\01\01\05\00\03\82\01\0F\000\82\01\0A\02\82\01\01\00\8Fd^\DA\B927N?\EE\AEzW\ED\86\C6\DE8P\AB\8C\F4\1D\CA\96\F0\908\08\A1\AB4\E7\81I \BC\A1\E0}\7FZ\A5Q\EFl\CA\CD+\BF\DA\B4S\1B~\BB\F5\83\16\CB\A8Y\07>\CE\7F\BBgC\A3\81\96ff\03\1C\85\92E\14\D5\95Q\28TrU`s\99?\18\A8\E8\DE\B5\D6\98\12\BE\1F\F5\C8\CEWm\84J\D3\C9\0A\17\99\9B,\8CD\C3\AD\9507\D9\D4;\AD`Kr:d,T\19\84\89\DB\9C~IPA.\89T\CA]\9Eq\0D\1C\E9,%M\C7\F5E\C8\BCG\80\F8\DF\BFI\968jw\B5P\81E\89\E6[\FF6\A4\E7/`d-H\96\EC/\D2\F2\22\CB\89YSs%d\1A\DA\FE\20\AC\D7\F78+\96;\AC\08\88\F6\89rv\0D\B6\F4m4p\AD{\13\E2p\9E\E2h\29\A0\8F\18\16\B1B\82\C9\A5H\14\D9\FEI8\11\F3\5C\E5\E7\D9k\99\F0\C3\02\03\01\00\01\A3\82\01\C40\82\01\C00\0E\06\03U\1D\0F\01\01\FF\04\04\03\02\05\A00\1D\06\03U\1D%\04\160\14\06\08+\06\01\05\05\07\03\02\06\08\2A\83\0E\03\03\04\01\010\1F\06\03U\1D#\04\180\16\80\14\A6\8C\163\7C\B8\E85g\06>^AWU\A2\AF4Ph0\1D\06\03U\1D\0E\04\16\04\14\BA\09\EF~j\9DMP\E3/\00\12\D3\DD$\8D\A5\A9\05_0^\06\03U\1D\20\04W0U0S\06\07\2A\83\0E\03\03\02\040H0\21\06\08+\06\01\05\05\07\02\01\16\15http://pki.gov.kz/cps0#%5C06%5C08+%5C06%5C01%5C05%5C05%5C07%5C02%5C020%5C17%...<\06\03U\1D\1F\045030 1\A0/\A0-\86+http://test.pki.gov.kz/crl/nca_rsa_test.crl0%3E%5C06%5C03U%5C1D.%5C0470503%5... E8\C0\13\92\2Ae\19\AB\8F\D7GL\97^\1AS\0E\D8\A2G\05\E4B\035\A7\84\8A\13_[\06\A1\AEs\BE\A5\0E\09\9F\7C\F3\CF\8F\80~\DCvjj\9A\C8\201\B7`\0D\FF[\8A\F0R\85\81@\F1\86\09zN\06\F1\84B\9BD\1C\8Bq\E1\88\84e4.\BD\D0\AD\95n\7C\E6E2\A2]\FD\B0\AB\F6\B8\8A?\16\0C\9C\05\DF\0D\B9\F3\88\9C`\8BR\0AYy\CE3T\B6M\F5\28c\F8\CD\B4\04\C5\21\F9\28\86\A0\BF\E4$\08\B6]\D3=\DBe7\A6\8FZ\D8V\D4.\F2_:[\05cfz\9F\E4\D4e\95W\04%\08\10N\84\93\8BS\20h\C7Z>\EEAQ\8B\8F\0D\0Fpw\F5\D4+k1\93\BBc\E3\93\05\BF\D8\D2\8C\94c\D2N\CB4\AA\86>+\B7\89\CD\934u\BC\C1\95`\C3HJ\85\DB\0E\06\01h\02\AE\BFj\12\A4n\B2A\D9n}/\0C\FD\85\B1\01l] to attributes of [IIN32000000001@ldap].
before, the content of the certificate was not like this, but:
(Tue Mar 3 17:08:15 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUp owWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZT QuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] to attributes of [IIN32000000001@ldap].
Regarding this I think that now the format stored in userCertificate;binary attribute is ok. Am I right? Wat remains is to make sssd derive the public key from it...
BR, Hristina
On Thu, Mar 05, 2020 at 02:24:25PM -0000, Hristina Marosevic wrote:
I added the content between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- from the base64 user certificate and during authentication in the logs I saw that the user certificate was stored in the user certificate SSSD option but there was no public key derived. This time I deleted the public key and during authentication I was using only userCertificate;binary attrbiute wit hthe default SSSD configuration for mapping the certificate.
This is from the SSSD_LDAP.log
(Thu Mar 5 15:16:19 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [0\82\0610\82\04\19\A0\03\02\01\02\02\14}\85\99\DB]\B02\D7\8A\D28\E7\9Dwzv\A9j\90\890\0D\06\09\2A\86H\86\F7\0D\01\01\0B\05\000-1\0B0\09\06\03U\04\06\13\02KZ1\1E0\1C\06\03U\04\03\0C\15\D2\B0\D0\9A\D0\9E\203.0\20\28RSA\20TEST\290\1E\17\0D190404085454Z\17\0D210403085454Z0\81\AF1\220\20\06\03U\04\03\0C\19\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\20\D0\A2\D0\95\D0\A1\D0\A2\D0\A21\170\15\06\03U\04\04\0C\0E\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\921\180\16\06\03U\04\05\13\0FIIN1234567890121\0B0\09\06\03U\04\06\13\02KZ1\150\13\06\03U\04\07\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\150\13\06\03U\04\08\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\1B0\19\06\03U\04\2A\0C\12\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\D0\98\D0\A70\82\01\220\0D\06\09\2A\86H\86\F7\0D\01\01\01\05\00\03\82\01\0F\000\82\01\0A\02\82\01\01\00\8Fd^\DA\B927N?\EE\AEzW\ED\86\C6\DE8P\AB\8C\F4\1D\CA\96\F0\908\08\A1\AB4\E7\81I \BC\A1\E0}\7FZ\A5Q\EFl\CA\CD+\BF\DA\B4S\1B~\BB\F5\83\16\CB\A8Y\07>\CE\7F\BBgC\A3\81\96ff\03\1C\85\92E\14\D5\95Q\28TrU`s\99?\18\A8\E8\DE\B5\D6\98\12\BE\1F\F5\C8\CEWm\84J\D3\C9\0A\17\99\9B,\8CD\C3\AD\9507\D9\D4;\AD`Kr:d,T\19\84\89\DB\9C~IPA.\89T\CA]\9Eq\0D\1C\E9,%M\C7\F5E\C8\BCG\80\F8\DF\BFI\968jw\B5P\81E\89\E6[\FF6\A4\E7/`d-H\96\EC/\D2\F2\22\CB\89YSs%d\1A\DA\FE\20\AC\D7\F78+\96;\AC\08\88\F6\89rv\0D\B6\F4m4p\AD{\13\E2p\9E\E2h\29\A0\8F\18\16\B1B\82\C9\A5H\14\D9\FEI8\11\F3\5C\E5\E7\D9k\99\F0\C3\02\03\01\00\01\A3\82\01\C40\82\01\C00\0E\06\03U\1D\0F\01\01\FF\04\04\03\02\05\A00\1D\06\03U\1D%\04\160\14\06\08+\06\01\05\05\07\03\02\06\08\2A\83\0E\03\03\04\01\010\1F\06\03U\1D#\04\180\16\80\14\A6\8C\163\7C\B8\E85g\06>^AWU\A2\AF4Ph0\1D\06\03U\1D\0E\04\16\04\14\BA\09\EF~j\9DMP\E3/\00\12\D3\DD$\8D\A5\A9\05_0^\06\03U\1D\20\04W0U0S\06\07\2A\83\0E\03\03\02\040H0\21\06\08+\06\01\05\05\07\02\01\16\15http://pki.gov.kz/cps0#%5C06%5C08+%5C06%5C01%5C05%5C05%5C07%5C02%5C020%5C17%...<\06\03U\1D\1F\045030 1\A0/\A0-\86+http://test.pki.gov.kz/crl/nca_rsa_test.crl0%3E%5C06%5C03U%5C1D.%5C0470503%5... E8\C0\13\92\2Ae\19\AB\8F\D7GL\97^\1AS\0E\D8\A2G\05\E4B\035\A7\84\8A\13_[\06\A1\AEs\BE\A5\0E\09\9F\7C\F3\CF\8F\80~\DCvjj\9A\C8\201\B7`\0D\FF[\8A\F0R\85\81@\F1\86\09zN\06\F1\84B\9BD\1C\8Bq\E1\88\84e4.\BD\D0\AD\95n\7C\E6E2\A2]\FD\B0\AB\F6\B8\8A?\16\0C\9C\05\DF\0D\B9\F3\88\9C`\8BR\0AYy\CE3T\B6M\F5\28c\F8\CD\B4\04\C5\21\F9\28\86\A0\BF\E4$\08\B6]\D3=\DBe7\A6\8FZ\D8V\D4.\F2_:[\05cfz\9F\E4\D4e\95W\04%\08\10N\84\93\8BS\20h\C7Z>\EEAQ\8B\8F\0D\0Fpw\F5\D4+k1\93\BBc\E3\93\05\BF\D8\D2\8C\94c\D2N\CB4\AA\86>+\B7\89\CD\934u\BC\C1\95`\C3HJ\85\DB\0E\06\01h\02\AE\BFj\12\A4n\B2A\D9n}/\0C\FD\85\B1\01l] to attributes of [IIN32000000001@ldap].
Hi,
yes, this looks better, please add 'debug_level = 9' to the [ssh] section of sssd.conf, restart sssd and call sss_ssh_authorizedkeys for the user and check sssd_ssh.log.
HTH
bye, Sumit
before, the content of the certificate was not like this, but:
(Tue Mar 3 17:08:15 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUp owWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZT QuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] to attributes of [IIN32000000001@ldap].
Regarding this I think that now the format stored in userCertificate;binary attribute is ok. Am I right? Wat remains is to make sssd derive the public key from it...
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Some more info (another prove that sssd does not derive the public key from the user certificate): /usr/bin/sss_ssh_authorizedkeys IIN32000000001 when I am using only userCertificate;binary attribute (with the binary value of the certificate) is not giving any output, while when I am using the userCertificate attribute associated with the value of the public key (when the PKI authentication works fine) /usr/bin/sss_ssh_authorizedkeys IIN32000000001 outputs the public key of the user which proves the oposite situation when using public key (wether used along with certificate or not; in cases when user certificate is used along with public key it gets mapped in sssd but it is not validated or compared to the public key - I already mentioned this, and the authentication using the private/public key pair work fine which is not fine :) )
I am just trying to give as much information in order to solve this problem. Sorry for the spam.
BR, Hristina
On Thu, Mar 05, 2020 at 02:34:42PM -0000, Hristina Marosevic wrote:
Some more info (another prove that sssd does not derive the public key from the user certificate): /usr/bin/sss_ssh_authorizedkeys IIN32000000001 when I am using only userCertificate;binary attribute (with the binary value of the certificate) is not giving any output, while when I am using the userCertificate attribute associated with the value of the public key (when the PKI authentication works fine) /usr/bin/sss_ssh_authorizedkeys IIN32000000001 outputs the public key of the user which proves the oposite situation when using public key (wether used along with certificate or not; in cases when user certificate is used along with public key it gets mapped in sssd but it is not validated or compared to the public key - I already mentioned this, and the authentication using the private/public key pair work fine which is not fine :) )
I am just trying to give as much information in order to solve this problem. Sorry for the spam.
Hi,
the best information would be the SSSD logs files with 'debug_level = 9'.
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
I got an error message: "Certificate is not valid"
So, I am not sure what should this mean? Is it because the trust (path to CA cert) isn't stored in the sssd configuration? Here I have a root CA and an intermediate CA. This can be the only option I can think of, so far because it is still valid considering expiration time, and it is not revoked (there is also no change in sssd configuration regarding OCSP (should I do something about this or sssd will by default check the provided CRL list given by URL in the certificate?), but there is a link of the CRL in the certificate provided by LDAP to sssd which - maybe can not be reached because this machine is not connected to Internet - in this case is it possible to use offlice copy of the CRL list on the local machine? )
sssd_ssh.log: .... (Fri Mar 6 08:50:11 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is not valid. ....
Once again, the certificate is stored in LDAP like: .. userCertificate;binary:: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZ IhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw 0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQo tCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEy MQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JA xGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCgg EBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1g xbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxE w62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZ b/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGB axQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEF jAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYD VR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQU FBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3 ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2Ffd GVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2Rf cnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmd vdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3 Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK 6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h 4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuz oV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DP X06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR 0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpO BvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M2 0BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw 0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdluf S8M/YWxAWw=
and SSSD sees it as: (from sssd_LDAP.log)
(Fri Mar 6 08:58:10 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [0\82\0610\82\04\19\A0\03\02\01\02\02\14}\85\99\DB]\B02\D7\8A\D28\E7\9Dwzv\A9j\90\890\0D\06\09\2A\86H\86\F7\0D\01\01\0B\05\000-1\0B0\09\06\03U\04\06\13\02KZ1\1E0\1C\06\03U\04\03\0C\15\D2\B0\D0\9A\D0\9E\203.0\20\28RSA\20TEST\290\1E\17\0D190404085454Z\17\0D210403085454Z0\81\AF1\220\20\06\03U\04\03\0C\19\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\20\D0\A2\D0\95\D0\A1\D0\A2\D0\A21\170\15\06\03U\04\04\0C\0E\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\921\180\16\06\03U\04\05\13\0FIIN1234567890121\0B0\09\06\03U\04\06\13\02KZ1\150\13\06\03U\04\07\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\150\13\06\03U\04\08\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\1B0\19\06\03U\04\2A\0C\12\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\D0\98\D0\A70\82\01\220\0D\06\09\2A\86H\86\F7\0D\01\01\01\05\00\03\82\01\0F\000\82\01\0A\02\82\01\01\00\8Fd^\DA\B927N?\EE\AEzW\ED\86\C6\DE8P\AB\8C\F4\1D\CA\96\F0\908\08\A1\AB4\E7\81I \BC\A1\E0}\7FZ\A5Q\EFl\CA\CD+\BF\DA\B4S\1B~\BB\F5\83\16\CB\A8Y\07>\CE\7F\BBgC\A3\81\96ff\03\1C\85\92E\14\D5\95Q\28TrU`s\99?\18\A8\E8\DE\B5\D6\98\12\BE\1F\F5\C8\CEWm\84J\D3\C9\0A\17\99\9B,\8CD\C3\AD\9507\D9\D4;\AD`Kr:d,T\19\84\89\DB\9C~IPA.\89T\CA]\9Eq\0D\1C\E9,%M\C7\F5E\C8\BCG\80\F8\DF\BFI\968jw\B5P\81E\89\E6[\FF6\A4\E7/`d-H\96\EC/\D2\F2\22\CB\89YSs%d\1A\DA\FE\20\AC\D7\F78+\96;\AC\08\88\F6\89rv\0D\B6\F4m4p\AD{\13\E2p\9E\E2h\29\A0\8F\18\16\B1B\82\C9\A5H\14\D9\FEI8\11\F3\5C\E5\E7\D9k\99\F0\C3\02\03\01\00\01\A3\82\01\C40\82\01\C00\0E\06\03U\1D\0F\01\01\FF\04\04\03\02\05\A00\1D\06\03U\1D%\04\160\14\06\08+\06\01\05\05\07\03\02\06\08\2A\83\0E\03\03\04\01\010\1F\06\03U\1D#\04\180\16\80\14\A6\8C\163\7C\B8\E85g\06>^AWU\A2\AF4Ph0\1D\06\03U\1D\0E\04\16\04\14\BA\09\EF~j\9DMP\E3/\00\12\D3\DD$\8D\A5\A9\05_0^\06\03U\1D\20\04W0U0S\06\07\2A\83\0E\03\03\02\040H0\21\06\08+\06\01\05\05\07\02\01\16\15http://pki.gov.kz/cps0#%5C06%5C08+%5C06%5C01%5C05%5C05%5C07%5C02%5C020%5C17%...<\06\03U\1D\1F\045030 1\A0/\A0-\86+http://test.pki.gov.kz/crl/nca_rsa_test.crl0%3E%5C06%5C03U%5C1D.%5C0470503%5... E8\C0\13\92\2Ae\19\AB\8F\D7GL\97^\1AS\0E\D8\A2G\05\E4B\035\A7\84\8A\13_[\06\A1\AEs\BE\A5\0E\09\9F\7C\F3\CF\8F\80~\DCvjj\9A\C8\201\B7`\0D\FF[\8A\F0R\85\81@\F1\86\09zN\06\F1\84B\9BD\1C\8Bq\E1\88\84e4.\BD\D0\AD\95n\7C\E6E2\A2]\FD\B0\AB\F6\B8\8A?\16\0C\9C\05\DF\0D\B9\F3\88\9C`\8BR\0AYy\CE3T\B6M\F5\28c\F8\CD\B4\04\C5\21\F9\28\86\A0\BF\E4$\08\B6]\D3=\DBe7\A6\8FZ\D8V\D4.\F2_:[\05cfz\9F\E4\D4e\95W\04%\08\10N\84\93\8BS\20h\C7Z>\EEAQ\8B\8F\0D\0Fpw\F5\D4+k1\93\BBc\E3\93\05\BF\D8\D2\8C\94c\D2N\CB4\AA\86>+\B7\89\CD\934u\BC\C1\95`\C3HJ\85\DB\0E\06\01h\02\AE\BFj\12\A4n\B2A\D9n}/\0C\FD\85\B1\01l] to attributes of [IIN32000000001@ldap].
BR, Hristina
On Fri, Mar 06, 2020 at 08:09:59AM -0000, Hristina Marosevic wrote:
Hello,
I got an error message: "Certificate is not valid"
So, I am not sure what should this mean? Is it because the trust (path to CA cert) isn't stored in the sssd configuration? Here I have a root CA and an intermediate CA. This can be the only option I can think of, so far because it is still valid considering expiration time, and it is not revoked (there is also no change in sssd configuration regarding OCSP (should I do something about this or sssd will by default check the provided CRL list given by URL in the certificate?), but there is a link of the CRL in the certificate provided by LDAP to sssd which - maybe can not be reached because this machine is not connected to Internet - in this case is it possible to use offlice copy of the CRL list on the local machine? )
sssd_ssh.log: .... (Fri Mar 6 08:50:11 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is not valid. ....
Hi,
this looks like some progress. Please check p11_child.log which might contain detail why SSSD thinks the certificate is not valid. By default SSSD will check the certificate with the help of the CA certificates and does OCSP if the certificate contains the needed OCSP data.
To disable OCSP, since your system cannot reach the OCSP responder, please add
certificate_verification = no_ocsp
to the [sssd] section of sssd.conf and restart SSSD. For testing you can even use 'no_verification' but this is should not be used in production (see man sssd.conf for details).
Which version of SSSD are you using? Depending on the version you might have to add the CA certificates to different locations, please check the 'ca_db' option described in man sssd.conf for details as well.
bye, Sumit
Once again, the certificate is stored in LDAP like: .. userCertificate;binary:: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZ IhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw 0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQo tCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEy MQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JA xGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCgg EBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1g xbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxE w62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZ b/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGB axQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEF jAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYD VR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQU FBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3 ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2Ffd GVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2Rf cnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmd vdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3 Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK 6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h 4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuz oV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DP X06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR 0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpO BvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M2 0BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw 0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdluf S8M/YWxAWw=
and SSSD sees it as: (from sssd_LDAP.log)
(Fri Mar 6 08:58:10 2020) [sssd[be[LDAP]]] [sdap_attrs_add_ldap_attr] (0x2000): Adding userCertificate [0\82\0610\82\04\19\A0\03\02\01\02\02\14}\85\99\DB]\B02\D7\8A\D28\E7\9Dwzv\A9j\90\890\0D\06\09\2A\86H\86\F7\0D\01\01\0B\05\000-1\0B0\09\06\03U\04\06\13\02KZ1\1E0\1C\06\03U\04\03\0C\15\D2\B0\D0\9A\D0\9E\203.0\20\28RSA\20TEST\290\1E\17\0D190404085454Z\17\0D210403085454Z0\81\AF1\220\20\06\03U\04\03\0C\19\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\20\D0\A2\D0\95\D0\A1\D0\A2\D0\A21\170\15\06\03U\04\04\0C\0E\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\921\180\16\06\03U\04\05\13\0FIIN1234567890121\0B0\09\06\03U\04\06\13\02KZ1\150\13\06\03U\04\07\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\150\13\06\03U\04\08\0C\0C\D0\90\D0\A1\D0\A2\D0\90\D0\9D\D0\901\1B0\19\06\03U\04\2A\0C\12\D0\A2\D0\95\D0\A1\D0\A2\D0\A2\D0\9E\D0\92\D0\98\D0\A70\82\01\220\0D\06\09\2A\86H\86\F7\0D\01\01\01\05\00\03\82\01\0F\000\82\01\0A\02\82\01\01\00\8Fd^\DA\B927N?\EE\AEzW\ED\86\C6\DE8P\AB\8C\F4\1D\CA\96\F0\908\08\A1\AB4\E7\81I \BC\A1\E0}\7FZ\A5Q\EFl\CA\CD+\BF\DA\B4S\1B~\BB\F5\83\16\CB\A8Y\07>\CE\7F\BBgC\A3\81\96ff\03\1C\85\92E\14\D5\95Q\28TrU`s\99?\18\A8\E8\DE\B5\D6\98\12\BE\1F\F5\C8\CEWm\84J\D3\C9\0A\17\99\9B,\8CD\C3\AD\9507\D9\D4;\AD`Kr:d,T\19\84\89\DB\9C~IPA.\89T\CA]\9Eq\0D\1C\E9,%M\C7\F5E\C8\BCG\80\F8\DF\BFI\968jw\B5P\81E\89\E6[\FF6\A4\E7/`d-H\96\EC/\D2\F2\22\CB\89YSs%d\1A\DA\FE\20\AC\D7\F78+\96;\AC\08\88\F6\89rv\0D\B6\F4m4p\AD{\13\E2p\9E\E2h\29\A0\8F\18\16\B1B\82\C9\A5H\14\D9\FEI8\11\F3\5C\E5\E7\D9k\99\F0\C3\02\03\01\00\01\A3\82\01\C40\82\01\C00\0E\06\03U\1D\0F\01\01\FF\04\04\03\02\05\A00\1D\06\03U\1D%\04\160\14\06\08+\06\01\05\05\07\03\02\06\08\2A\83\0E\03\03\04\01\010\1F\06\03U\1D#\04\180\16\80\14\A6\8C\163\7C\B8\E85g\06>^AWU\A2\AF4Ph0\1D\06\03U\1D\0E\04\16\04\14\BA\09\EF~j\9DMP\E3/\00\12\D3\DD$\8D\A5\A9\05_0^\06\03U\1D\20\04W0U0S\06\07\2A\83\0E\03\03\02\040H0\21\06\08+\06\01\05\05\07\02\01\16\15http://pki.gov.kz/cps0#%5C06%5C08+%5C06%5C01%5C05%5C05%5C07%5C02%5C020%5C17%...<\06\03U\1D\1F\045030 1\A0/\A0-\86+http://test.pki.gov.kz/crl/nca_rsa_test.crl0%3E%5C06%5C03U%5C1D.%5C0470503%5... E8\C0\13\92\2Ae\19\AB\8F\D7GL\97^\1AS\0E\D8\A2G\05\E4B\035\A7\84\8A\13_[\06\A1\AEs\BE\A5\0E\09\9F\7C\F3\CF\8F\80~\DCvjj\9A\C8\201\B7`\0D\FF[\8A\F0R\85\81@\F1\86\09zN\06\F1\84B\9BD\1C\8Bq\E1\88\84e4.\BD\D0\AD\95n\7C\E6E2\A2]\FD\B0\AB\F6\B8\8A?\16\0C\9C\05\DF\0D\B9\F3\88\9C`\8BR\0AYy\CE3T\B6M\F5\28c\F8\CD\B4\04\C5\21\F9\28\86\A0\BF\E4$\08\B6]\D3=\DBe7\A6\8FZ\D8V\D4.\F2_:[\05cfz\9F\E4\D4e\95W\04%\08\10N\84\93\8BS\20h\C7Z>\EEAQ\8B\8F\0D\0Fpw\F5\D4+k1\93\BBc\E3\93\05\BF\D8\D2\8C\94c\D2N\CB4\AA\86>+\B7\89\CD\934u\BC\C1\95`\C3HJ\85\DB\0E\06\01h\02\AE\BFj\12\A4n\B2A\D9n}/\0C\FD\85\B1\01l] to attributes of [IIN32000000001@ldap].
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
I added: "certificate_verification = no_ocsp, no_verification" in [sssd] part of the sssd configuration and I didn't add the CA certs because the certification validation is disabled, but I am getting the same error "certificate is not valid" in the sssd_ssh.log SSSD version that I am using is (yum package version): 1.16.4-21.0.1.el7_7.1 Somewhere on the internet, I saw this in the [pam] part of the sssd configuration: "pam_cert_auth = True" - should I add this line in my config file? and I found the following command for the p11_child log (by you): /usr/libexec/sssd/p11_child -d 10 --debug-fd=1 --pre --nssdb=/etc/pki/nssdb
The output on my machine was: $ /usr/libexec/sssd/p11_child -d 10 --debug-fd=1 --pre --nssdb=/etc/pki/nssdb (Fri Mar 6 13:33:30:652007 2020) [[sssd[p11_child[8855]]]] [main] (0x0400): p11_child started. (Fri Mar 6 13:33:30:652310 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running in [pre-auth] mode. (Fri Mar 6 13:33:30:652517 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running with effective IDs: [0][0]. (Fri Mar 6 13:33:30:652758 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running with real IDs [0][0]. (Fri Mar 6 13:33:30:710650 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Default Module List: (Fri Mar 6 13:33:30:710904 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [NSS Internal PKCS #11 Module]. (Fri Mar 6 13:33:30:711013 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711116 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Dead Module List: (Fri Mar 6 13:33:30:711218 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): DB Module List: (Fri Mar 6 13:33:30:711320 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [NSS Internal Module]. (Fri Mar 6 13:33:30:711434 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711564 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [Policy File]. (Fri Mar 6 13:33:30:711768 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711890 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Description [NSS User Private Key and Certificate Services Mozilla Foundation ] Manufacturer [Mozilla Foundation ] flags [1]. (Fri Mar 6 13:33:30:712016 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Description [NSS Internal Cryptographic Services Mozilla Foundation ] Manufacturer [Mozilla Foundation ] flags [9]. (Fri Mar 6 13:33:30:712335 2020) [[sssd[p11_child[8855]]]] [do_card] (0x0040): No removable slots found. (Fri Mar 6 13:33:30:712448 2020) [[sssd[p11_child[8855]]]] [main] (0x0040): do_work failed. (Fri Mar 6 13:33:30:712595 2020) [[sssd[p11_child[8855]]]] [main] (0x0020): p11_child failed!
BR, Hristina
On Fri, Mar 06, 2020 at 12:44:35PM -0000, Hristina Marosevic wrote:
Hello,
I added: "certificate_verification = no_ocsp, no_verification" in [sssd] part of the sssd configuration and I didn't add the CA certs because the certification validation is disabled, but I am getting the same error "certificate is not valid" in the sssd_ssh.log SSSD version that I am using is (yum package version): 1.16.4-21.0.1.el7_7.1 Somewhere on the internet, I saw this in the [pam] part of the sssd configuration: "pam_cert_auth = True" - should I add this line in my config file?
Hi,
no [pam] is not needed for your use case, access via ssh.
and I found the following command for the p11_child log (by you): /usr/libexec/sssd/p11_child -d 10 --debug-fd=1 --pre --nssdb=/etc/pki/nssdb
This command looks for certificates from a Smartcard connected to the local system. However p11_child is used to validate the certificates for the ssh key generation as well. You should add debug_level = 9 to the [ssh] section of sssd.conf and then check sssd_ssh.log and p11_child.log after calling sss_ssh_authorized_keys.
HTH
bye, Sumit
The output on my machine was: $ /usr/libexec/sssd/p11_child -d 10 --debug-fd=1 --pre --nssdb=/etc/pki/nssdb (Fri Mar 6 13:33:30:652007 2020) [[sssd[p11_child[8855]]]] [main] (0x0400): p11_child started. (Fri Mar 6 13:33:30:652310 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running in [pre-auth] mode. (Fri Mar 6 13:33:30:652517 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running with effective IDs: [0][0]. (Fri Mar 6 13:33:30:652758 2020) [[sssd[p11_child[8855]]]] [main] (0x2000): Running with real IDs [0][0]. (Fri Mar 6 13:33:30:710650 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Default Module List: (Fri Mar 6 13:33:30:710904 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [NSS Internal PKCS #11 Module]. (Fri Mar 6 13:33:30:711013 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711116 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Dead Module List: (Fri Mar 6 13:33:30:711218 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): DB Module List: (Fri Mar 6 13:33:30:711320 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [NSS Internal Module]. (Fri Mar 6 13:33:30:711434 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711564 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): common name: [Policy File]. (Fri Mar 6 13:33:30:711768 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): dll name: [(null)]. (Fri Mar 6 13:33:30:711890 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Description [NSS User Private Key and Certificate Services Mozilla Foundation ] Manufacturer [Mozilla Foundation ] flags [1]. (Fri Mar 6 13:33:30:712016 2020) [[sssd[p11_child[8855]]]] [do_card] (0x4000): Description [NSS Internal Cryptographic Services Mozilla Foundation ] Manufacturer [Mozilla Foundation ] flags [9]. (Fri Mar 6 13:33:30:712335 2020) [[sssd[p11_child[8855]]]] [do_card] (0x0040): No removable slots found. (Fri Mar 6 13:33:30:712448 2020) [[sssd[p11_child[8855]]]] [main] (0x0040): do_work failed. (Fri Mar 6 13:33:30:712595 2020) [[sssd[p11_child[8855]]]] [main] (0x0020): p11_child failed!
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Fri, Mar 06, 2020 at 12:44:35PM -0000, Hristina Marosevic wrote:
Hi,
no [pam] is not needed for your use case, access via ssh.
This command looks for certificates from a Smartcard connected to the local system. However p11_child is used to validate the certificates for the ssh key generation as well. You should add debug_level = 9 to the [ssh] section of sssd.conf and then check sssd_ssh.log and p11_child.log after calling sss_ssh_authorized_keys.
HTH
bye, Sumit
I can not find a file named p11_child.log (i searched everything from the root directory) The only thing related to p11_child is executable /usr/libexec/sssd/p11_child - should I use it to generate log? Can you please help me with this?
BR, Hristina
On Thu, Mar 12, 2020 at 03:13:57PM -0000, Hristina Marosevic wrote:
On Fri, Mar 06, 2020 at 12:44:35PM -0000, Hristina Marosevic wrote:
Hi,
no [pam] is not needed for your use case, access via ssh.
This command looks for certificates from a Smartcard connected to the local system. However p11_child is used to validate the certificates for the ssh key generation as well. You should add debug_level = 9 to the [ssh] section of sssd.conf and then check sssd_ssh.log and p11_child.log after calling sss_ssh_authorized_keys.
HTH
bye, Sumit
I can not find a file named p11_child.log (i searched everything from the root directory) The only thing related to p11_child is executable /usr/libexec/sssd/p11_child - should I use it to generate log? Can you please help me with this?
Hi,
the file should be in the SSSD log directory, so typically /var/log/sssd/p11_child.log.
Since it does not exists, p11_child was not called to validate the certificates. In this case sssd_ssh.log is the only source of information. Feel free to send the file or the part of the log file which covers the time where sss_ssh_authorized_keys was called.
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Thu, Mar 12, 2020 at 4:52 PM Sumit Bose sbose@redhat.com wrote:
Hi,
the file should be in the SSSD log directory, so typically /var/log/sssd/p11_child.log.
Since it does not exists, p11_child was not called to validate the certificates. In this case sssd_ssh.log is the only source of information. Feel free to send the file or the part of the log file which covers the time where sss_ssh_authorized_keys was called.
bye, Sumit
Just for the record, there was a bug that caused not creating p11_child
log file and the records were actually stored in parent process log.
Fixed in commit 30d0ccd49
On Thu, Mar 12, 2020 at 4:52 PM Sumit Bose <sbose(a)redhat.com> wrote:
log file and the records were actually stored in parent process log.
Fixed in commit 30d0ccd49
Hello Tomas,
Can you please send me link of the commit? About the paret p11 log file - I am not sure, which log process is the parent process? Where should I look for p11 child logs?
BR, Hristina
On Thu, Mar 12, 2020 at 03:13:57PM -0000, Hristina Marosevic wrote:
Hi,
the file should be in the SSSD log directory, so typically /var/log/sssd/p11_child.log.
Since it does not exists, p11_child was not called to validate the certificates. In this case sssd_ssh.log is the only source of information. Feel free to send the file or the part of the log file which covers the time where sss_ssh_authorized_keys was called.
bye, Sumit
Hello,
command: /usr/bin/sss_ssh_authorizedkeys IIN32000000001
output: (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [get_client_cred] (0x4000): Client creds: euid[0] egid[0] pid[24441]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [get_client_cred] (0x0080): The following failure is expected to happen in case SELinux is disabled: SELINUX_getpeercon failed [92][Protocol not available]. Please, consider enabling SELinux in your system. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x55e6a3217350][18] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [accept_fd_handler] (0x0400): Client connected! (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Received client version [0]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Offered version [0]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_protocol_parse_request] (0x0400): Requested domain [<ALL>] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_cmd_get_user_pubkeys] (0x0400): Requesting SSH user public keys for [IIN32000000001] from [<ALL>] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_set_plugin] (0x2000): CR #0: Setting "User by name" plugin (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_send] (0x0400): CR #0: New request 'User by name' (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_process_input] (0x0400): CR #0: Parsing input name [IIN32000000001] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_parse_name_for_domains] (0x0200): name 'IIN32000000001' matched without domain, user is IIN32000000001 (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_set_name] (0x0400): CR #0: Setting name [IIN32000000001] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_select_domains] (0x0400): CR #0: Performing a multi-domain search (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_domains] (0x0400): CR #0: Search will check the cache and check the data provider (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_validate_domain_type] (0x2000): Request type POSIX-only for domain LDAP type POSIX is valid (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_set_domain] (0x0400): CR #0: Using domain [LDAP] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_prepare_domain_data] (0x0400): CR #0: Preparing input data for domain [LDAP] rules (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #0: Looking up IIN32000000001@ldap (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #0: Checking negative cache for [IIN32000000001@ldap] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_ncache_check_str] (0x2000): Checking negative cache for [NCE/USER/LDAP/IIN32000000001@ldap] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #0: [IIN32000000001@ldap] is not present in negative cache (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_cache] (0x0400): CR #0: Looking up [IIN32000000001@ldap] in cache (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a321fcd0
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a321fda0
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a321fcd0 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a321fda0 "ltdb_timeout"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a321fcd0 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a321fc00
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a321fcd0
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a321fc00 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a321fcd0 "ltdb_timeout"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a321fc00 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #0: Returning [IIN32000000001@ldap] from cache (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_search_ncache_filter] (0x0400): CR #0: This request type does not support filtering result by negative cache (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_create_and_add_result] (0x0400): CR #0: Found 1 entries in domain LDAP (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cache_req_done] (0x0400): CR #0: Finished: Success (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3223080
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3223150
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223150 "ltdb_timeout"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3223080
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3223150
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223150 "ltdb_timeout"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3223080
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3223150
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223150 "ltdb_timeout"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3223080 "ltdb_callback"
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Setting up signal handler up for pid [24442] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Signal handler set up for pid [24442] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [24442]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_sig_handler] (0x0020): child [24442] failed with status [1]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0040): /usr/libexec/sssd/p11_child failed with status [256] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is not valid. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected! (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x55e6a3217350][18]
In /etc/sssd/sssd.conf certificate verification and ocsp are disabled: "certificate_verification = no_ocsp, no_verification" is added in [sssd] section of sssd configuration file
BR, Hristina
On Tue, Mar 17, 2020 at 09:41:16AM -0000, Hristina Marosevic wrote:
On Thu, Mar 12, 2020 at 03:13:57PM -0000, Hristina Marosevic wrote:
Hi,
the file should be in the SSSD log directory, so typically /var/log/sssd/p11_child.log.
Since it does not exists, p11_child was not called to validate the certificates. In this case sssd_ssh.log is the only source of information. Feel free to send the file or the part of the log file which covers the time where sss_ssh_authorized_keys was called.
bye, Sumit
Hello,
command: /usr/bin/sss_ssh_authorizedkeys IIN32000000001
output: (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [get_client_cred] (0x4000): Client creds: euid[0] egid[0] pid[24441]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [get_client_cred] (0x0080): The following failure is expected to happen in case SELinux is disabled: SELINUX_getpeercon failed [92][Protocol not available]. Please, consider enabling SELinux in your system. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x55e6a3217350][18] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [accept_fd_handler] (0x0400): Client connected! (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Received client version [0]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Offered version [0]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_protocol_parse_request] (0x0400): Requested domain [<ALL>] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_cmd_get_user_pubkeys] (0x0400): Requesting SSH user public keys for [IIN32000000001] from [<ALL>]
....
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Setting up signal handler up for pid [24442] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Signal handler set up for pid [24442] (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [24442]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [child_sig_handler] (0x0020): child [24442] failed with status [1]. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0040): /usr/libexec/sssd/p11_child failed with status [256]
Hi,
so p11_child is really called but as you said earlier there are no logs.
This might e.g. be a permission issue, please check the permissions on /var/log/sssd if you see anything odd. For me it looks like:
drwxr-x---. 2 root root system_u:object_r:sssd_var_log_t:s0 4096 Mar 17 09:09 . drwxr-xr-x. 12 root root system_u:object_r:var_log_t:s0 4096 Mar 15 03:27 .. -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 221452 Mar 17 09:19 krb5_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 1069023 Mar 17 11:16 ldap_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 p11_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 14816 Mar 17 09:19 selinux_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 623 Mar 16 10:31 sssd.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_nss.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_pac.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 490679 Mar 17 11:18 sssd_pam.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 6723166 Mar 17 11:18 sssd_ipa.devel.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_ssh.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_sudo.log
The next step would be to check what failed with strace. For this call
mkdir /tmp/strace_data strace -ff -s 1024 -o /tmp/strace_data/strace_ -p $(pidof /usr/libexec/sssd/sssd_ssh)
in one terminal can call 'sss_ssh_authorizedkeys IIN32000000001' in a different terminal. After calling sss_ssh_authorizedkeys you can stop the strace command with CTRL-C. In /tmp/strace_data there should be at least 2 files, one of the main sssd_ssh process and the other for p11_child, please send both (if there are more than 2 please send all).
bye, Sumit
(Tue Mar 17 10:39:34 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is not valid. (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected! (Tue Mar 17 10:39:34 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x55e6a3217350][18]
In /etc/sssd/sssd.conf certificate verification and ocsp are disabled: "certificate_verification = no_ocsp, no_verification" is added in [sssd] section of sssd configuration file
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Tue, Mar 17, 2020 at 09:41:16AM -0000, Hristina Marosevic wrote: ....
Hi,
so p11_child is really called but as you said earlier there are no logs.
This might e.g. be a permission issue, please check the permissions on /var/log/sssd if you see anything odd. For me it looks like:
drwxr-x---. 2 root root system_u:object_r:sssd_var_log_t:s0 4096 Mar 17 09:09 . drwxr-xr-x. 12 root root system_u:object_r:var_log_t:s0 4096 Mar 15 03:27 .. -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 221452 Mar 17 09:19 krb5_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 1069023 Mar 17 11:16 ldap_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 p11_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 14816 Mar 17 09:19 selinux_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 623 Mar 16 10:31 sssd.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_nss.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_pac.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 490679 Mar 17 11:18 sssd_pam.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 6723166 Mar 17 11:18 sssd_ipa.devel.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_ssh.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_sudo.log
The next step would be to check what failed with strace. For this call
mkdir /tmp/strace_data strace -ff -s 1024 -o /tmp/strace_data/strace_ -p $(pidof /usr/libexec/sssd/sssd_ssh)
in one terminal can call 'sss_ssh_authorizedkeys IIN32000000001' in a different terminal. After calling sss_ssh_authorizedkeys you can stop the strace command with CTRL-C. In /tmp/strace_data there should be at least 2 files, one of the main sssd_ssh process and the other for p11_child, please send both (if there are more than 2 please send all).
bye, Sumit
There are two files:
after executing strace -ff -s 1024 -o /tmp/strace_data/strace_ -p $(pidof /usr/libexec/sssd/sssd_ssh) strace_.24180 was generated. It's content: epoll_wait(0, 0x7ffe7209f430, 1, 1418) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=-865456032, ptr=0x7f04cc6a3060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, [], 1, 402) = 0 epoll_wait(0, 0x7ffe7209f430, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=-865456032, ptr=0x7f04cc6a3060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, [], 1, 403) = 0 epoll_wait(0, [{EPOLLIN, {u32=2736880848, u64=94449067719888}}], 1, 10000) = 1 accept(17, {sa_family=AF_LOCAL, NULL}, [2]) = 18 getsockopt(18, SOL_SOCKET, SO_PEERCRED, {pid=5538, uid=0, gid=0}, [12]) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [get_client_cred] (0x4000): Client creds: euid[0] egid[0] pid[5538].\n", 108) = 108 getsockopt(18, SOL_SOCKET, SO_PEERSEC, 0x55e6a3221410, 0x7ffe7209f264) = -1 ENOPROTOOPT (Protocol not available) stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [get_client_cred] (0x0080): The following failure is expected to happen in case SELinux is disabled:\nSELINUX_getpeercon failed [92][Protocol not available].\nPlease, consider enabling SELinux in your system.\n", 246) = 246 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=2736856736, u64=94449067695776}}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x55e6a32224f0][18]\n", 125) = 125 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [accept_fd_handler] (0x0400): Client connected!\n", 87) = 87 epoll_wait(0, [{EPOLLIN, {u32=2736856736, u64=94449067695776}}], 1, 7572) = 1 recvfrom(18, "\24\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0", 1536, 0, NULL, NULL) = 16 epoll_wait(0, [{EPOLLIN, {u32=2736856736, u64=94449067695776}}], 1, 7572) = 1 recvfrom(18, "\0\0\0\0", 4, 0, NULL, NULL) = 4 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7209f350) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Received client version [0].\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Offered version [0].\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=2736856736, u64=94449067695776}}) = 0 epoll_wait(0, [{EPOLLOUT, {u32=2736856736, u64=94449067695776}}], 1, 7571) = 1 sendto(18, "\24\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 20, 0, NULL, 0) = 20 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7209f350) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=2736856736, u64=94449067695776}}) = 0 epoll_wait(0, [{EPOLLIN, {u32=2736856736, u64=94449067695776}}], 1, 7571) = 1 recvfrom(18, "+\0\0\0\341\0\0\0\0\0\0\0\0\0\0\0", 1536, 0, NULL, NULL) = 16 epoll_wait(0, [{EPOLLIN, {u32=2736856736, u64=94449067695776}}], 1, 7571) = 1 recvfrom(18, "\2\0\0\0\17\0\0\0IIN32000000001\0\0\0\0\0", 27, 0, NULL, NULL) = 27 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7209f350) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ssh_protocol_parse_request] (0x0400): Requested domain [<ALL>]\n", 103) = 103 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ssh_cmd_get_user_pubkeys] (0x0400): Requesting SSH user public keys for [IIN32000000001] from [<ALL>]\n", 142) = 142 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_set_plugin] (0x2000): CR #3: Setting "User by name" plugin\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_send] (0x0400): CR #3: New request 'User by name'\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_process_input] (0x0400): CR #3: Parsing input name [IIN32000000001]\n", 118) = 118 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [sss_parse_name_for_domains] (0x0200): name 'IIN32000000001' matched without domain, user is IIN32000000001\n", 147) = 147 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_set_name] (0x0400): CR #3: Setting name [IIN32000000001]\n", 107) = 107 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_select_domains] (0x0400): CR #3: Performing a multi-domain search\n", 116) = 116 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_domains] (0x0400): CR #3: Search will check the cache and check the data provider\n", 139) = 139 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_validate_domain_type] (0x2000): Request type POSIX-only for domain LDAP type POSIX is valid\n", 142) = 142 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_set_domain] (0x0400): CR #3: Using domain [LDAP]\n", 99) = 99 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_prepare_domain_data] (0x0400): CR #3: Preparing input data for domain [LDAP] rules\n", 133) = 133 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #3: Looking up IIN32000000001@ldap\n", 111) = 111 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #3: Checking negative cache for [IIN32000000001@ldap]\n", 132) = 132 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [sss_ncache_check_str] (0x2000): Checking negative cache for [NCE/USER/LDAP/IIN32000000001@ldap]\n", 136) = 136 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #3: [IIN32000000001@ldap] is not present in negative cache\n", 137) = 137 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_cache] (0x0400): CR #3: Looking up [IIN32000000001@ldap] in cache\n", 123) = 123 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(14, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(14, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3237ab0\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3237b80\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3237ab0 "ltdb_callback"\n\n", 107) = 107 fcntl(14, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237b80 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237ab0 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(16, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(16, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3237a10\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3237ae0\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3237a10 "ltdb_callback"\n\n", 107) = 107 fcntl(16, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237ae0 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237a10 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #3: Returning [IIN32000000001@ldap] from cache\n", 123) = 123 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_search_ncache_filter] (0x0400): CR #3: This request type does not support filtering result by negative cache\n", 159) = 159 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_create_and_add_result] (0x0400): CR #3: Found 1 entries in domain LDAP\n", 121) = 121 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cache_req_done] (0x0400): CR #3: Finished: Success\n", 91) = 91 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3220d70\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3237950\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3220d70 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237950 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3220d70 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3237950\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3237a20\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3237950 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237a20 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237950 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55e6a3237950\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55e6a3237a20\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55e6a3237950 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237a20 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55e6a3237950 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 pipe([19, 20]) = 0 pipe([21, 22]) = 0 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f04cc89db50) = 5539 close(20) = 0 fcntl(19, F_GETFL) = 0 (flags O_RDONLY) fcntl(19, F_SETFL, O_RDONLY|O_NONBLOCK) = 0 close(21) = 0 fcntl(22, F_GETFL) = 0x1 (flags O_WRONLY) fcntl(22, F_SETFL, O_WRONLY|O_NONBLOCK) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Setting up signal handler up for pid [5539]\n", 115) = 115 rt_sigaction(SIGCHLD, {0x7f04c9b1bdd0, [], SA_RESTORER|SA_SIGINFO, 0x7f04c808b630}, {SIG_DFL, [], SA_RESTORER, 0x7f04c808b630}, 8) = 0 rt_sigprocmask(SIG_BLOCK, [CHLD], [INT FPE USR1 USR2 PIPE], 8) = 0 rt_sigprocmask(SIG_SETMASK, [INT FPE USR1 USR2 PIPE], NULL, 8) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Signal handler set up for pid [5539]\n", 108) = 108 epoll_wait(0, 0x7ffe7209f430, 1, 7556) = -1 EINTR (Interrupted system call) --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=5539, si_uid=0, si_status=1, si_utime=0, si_stime=0} --- write(3, "\1\0\0\0\0\0\0\0", 8) = 8 rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [5539].\n", 95) = 95 wait4(5539, [{WIFEXITED(s) && WEXITSTATUS(s) == 1}], WNOHANG, NULL) = 5539 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [child_sig_handler] (0x0020): child [5539] failed with status [1].\n", 106) = 106 close(19) = 0 close(22) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0040): /usr/libexec/sssd/p11_child failed with status [256]\n", 125) = 125 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DV nBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735"..., 2221) = 2221 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=2736856736, u64=94449067695776}}) = 0 rt_sigaction(SIGCHLD, {SIG_DFL, [], SA_RESTORER, 0x7f04c808b630}, NULL, 8) = 0 epoll_wait(0, [{EPOLLIN, {u32=2736794800, u64=94449067633840}}], 1, 7518) = 1 read(3, "\1\0\0\0\0\0\0\0", 8) = 8 epoll_wait(0, [{EPOLLOUT, {u32=2736856736, u64=94449067695776}}], 1, 7518) = 1 sendto(18, "\30\0\0\0\341\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 24, 0, NULL, 0) = 24 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7209f350) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=2736856736, u64=94449067695776}}) = 0 epoll_wait(0, [{EPOLLIN|EPOLLHUP, {u32=2736856736, u64=94449067695776}}], 1, 7517) = 1 recvfrom(18, "", 1536, 0, NULL, NULL) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected!\n", 84) = 84 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7209f2f0) = 0 close(18) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 12:09:26 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x55e6a32224f0][18]\n", 106) = 106 epoll_wait(0, <detached ...>
After calling /usr/bin/sss_ssh_authorizedkeys IIN32000000001 file strace_.5539 was generated. It's content: set_robust_list(0x7f04cc89db60, 24) = 0 close(22) = 0 dup2(21, 0) = 0 close(19) = 0 dup2(20, 1) = 1 execve("/usr/libexec/sssd/p11_child", ["/usr/libexec/sssd/p11_child", "--debug-microseconds=0", "--debug-timestamps=1", "--debug-fd=2", "--debug-level=0xf7f0", "--verification", "--verify", "no_ocsp, no_verification", "--nssdb", "/home/oracle", "--certificate", "MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAi I9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtp"...], [/* 6 vars */]) = 0 brk(NULL) = 0x5647a7f10000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f508000 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/tls/x86_64/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/tls/x86_64", 0x7ffdb254ebe0) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/tls/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/tls", 0x7ffdb254ebe0) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/x86_64/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/x86_64", 0x7ffdb254ebe0) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/libsss_debug.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\23\0\0\0\0\0\0@\0\0\0\0\0\0\0hF\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<6\0\0\0\0\0\0<6\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0x=\0\0\0\0\0\0x= \0\0\0\0\0x= \0\0\0\0\0\330\3\0\0\0\0\0\0\370\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\230=\0\0\0\0\0\0\230= \0\0\0\0\0\230= \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0L2\0\0\0\0\0\0L2\0\0\0\0\0\0L2\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0x=\0\0\0\0\0\0x= \0\0\0\0\0x= \0\0\0\0\0\210\2\0\0\0\0\0\0\210\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0w\221\0%\247\326~\210\326\26\341\277\252\275\350\222\217 \360yy\0\0\0\0\21\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0\10\1\220\20H\10\234\21(\2\0\31@p \200\n\240\0\3\f\0\20)\n"\270\3\2026\6\25\34\0\0\0\35\0\0\0\36\0\0\0 \0\0\0%\0\0\0)\0\0\0+\0\0\0-\0\0\0\0\0\0\0.\0\0\0/\0\0\0000\0\0\0002\0\0\0005\0\0\0007\0\0\0\0\0\0\0:\0\0\0Yu\32\\353\323\357\16\216\31\37)\271\215\361\16\200\342\256\2118s\203:f\356?\241\330qX\34\363\315\307\276\324\252\36\376\3101\330\332\354xl\20\273\343\222|2\367T\271\375\351Yol\t1\32+\224\254UCE\325\354\3\246\251\v\177\34\301\254\34\327\255G\327A\22\337\10#45\340Y\2078\275\3\303\20\264\230M\3305<\333|\354\347v\301l\33\337\352\325\303f\250\351:\\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0=\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\251\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19816, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34f0e3000 mprotect(0x7fd34f0e7000, 2093056, PROT_NONE) = 0 mmap(0x7fd34f2e6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7fd34f2e6000 close(4) = 0 open("/usr/lib64/sssd/libpopt.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=49694, ...}) = 0 mmap(NULL, 49694, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7fd34f4fb000 close(4) = 0 open("/lib64/libpopt.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\34\0\0\0\0\0\0@\0\0\0\0\0\0\0\310\231\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\354\203\0\0\0\0\0\0\354\203\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\240\215\0\0\0\0\0\0\240\215 \0\0\0\0\0\240\215 \0\0\0\0\0@\6\0\0\0\0\0\0\220\6\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300\215\0\0\0\0\0\0\300\215 \0\0\0\0\0\300\215 \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0008u\0\0\0\0\0\0008u\0\0\0\0\0\0008u\0\0\0\0\0\0\264\1\0\0\0\0\0\0\264\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\240\215\0\0\0\0\0\0\240\215 \0\0\0\0\0\240\215 \0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0G NU\0\310hy\351\335\317X\236M\ri\1\221TC,\205N\371\233\0\0\0\0\21\0\0\0:\0\0\0\4\0\0\0\10\0\0\0\200@\4A\214@\341,\0! H%\4\221\4 \2A\2\225\4\r\200!(\0\311\314\0\f:\0\0\0;\0\0\0=\0\0\0?\0\0\0@\0\0\0D\0\0\0E\0\0\0H\0\0\0\0\0\0\0L\0\0\0\0\0\0\0O\0\0\0Q\0\0\0R\0\0\0T\0\0\0W\0\0\0\0\0\0\0y\225{\313\352\323\357\16\273\315\340\37\346f\377\t\271\215\361\16\307\353\t\2\356\323\252@~\343A\370\240\354G\224;\230\236\305g\315\206\364\202\362\311\350\324z,V]\210\36\316h<\250\354\252\250Fm\16\7\267~\315\373|\2154\347\300\263\342\373\230\345#w\356\241"\266ug\341\310\334\204\271\257\233\10\352\256\\257]rB\203j\255\375<<\322\214\v\273Q\0005\236\3308\3050;\324\23\37n\r1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\n\0\350\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0001\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\33\3\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=41224, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4fa000 mmap(NULL, 2135088, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34eed9000 mprotect(0x7fd34eee2000, 2093056, PROT_NONE) = 0 mmap(0x7fd34f0e1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x8000) = 0x7fd34f0e1000 close(4) = 0 open("/usr/lib64/sssd/libsss_crypt.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240!\0\0\0\0\0\0@\0\0\0\0\0\0\0\0h\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\364Z\0\0\0\0\0\0\364Z\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\320\\0\0\0\0\0\0\320\ \0\0\0\0\0\320\ \0\0\0\0\0\360\5\0\0\0\0\0\0\370\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\360\\0\0\0\0\0\0\360\ \0\0\0\0\0\360\ \0\0\0\0\0\300\2\0\0\0\0\0\0\300\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0hU\0\0\0\0\0\0hU\0\0\0\0\0\0hU\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\320\\0\0\0\0\0\0\320\ \0\0\0\0\0\320\ \0\0\0\0\0000\3\0\0\0\0\0\0000\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\f\2232\251\372\17\244\31\ 354\214vv)\246\351S\366gV?\0\0\0\0\21\0\0\0I\0\0\0\4\0\0\0\10\0\0\0\4\0 \4,2\20\0=\4!\0@\250(\7 \0\0\34\0\0\v\0\4\210\1\24D\2\0I\0\0\0K\0\0\0L\0\0\0O\0\0\0S\0\0\0\0\0\0\0\0\0\0\0U\0\0\0V\0\0\0W\0\0\0X\0\0\0Y\0\0\0\\0\0\0\0\0\0\0^\0\0\0_\0\0\0`\0\0\0x\0\225\254Q\355\206]\353\323\357\16\356\312|\20\312W\326M\271\215\361\16@\263\352\212\342\244\264\v,"!\350\331qX\34(\355b\2\273\343\222|CE\325\354E\246k\301U\204\354\17uzG\364\204\271\223|4\2\317\257#\225\201Yx\372\273\251\243dj\253\33\345}\262C\n\336}o\253c\304\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\235\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\267\4\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0P\4\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0I\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=28416, ...}) = 0 mmap(NULL, 2122440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ecd2000 mprotect(0x7fd34ecd8000, 2093056, PROT_NONE) = 0 mmap(0x7fd34eed7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x5000) = 0x7fd34eed7000 close(4) = 0 open("/usr/lib64/sssd/libcrypto.so.10", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcrypto.so.10", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\321\6\0\0\0\0\0@\0\0\0\0\0\0\0\370p&\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224_#\0\0\0\0\0\224_#\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\0l#\0\0\0\0\0\0lC\0\0\0\0\0\0lC\0\0\0\0\0\240v\2\0\0\0\0\0H\267\2\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0p\35%\0\0\0\0\0p\35E\0\0\0\0\0p\35E\0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0`r\37\0\0\0\0\0`r\37\0\0\0\0\0`r\37\0\0\0\0\0\274\235\0\0\0\0\0\0\274\235\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\0l#\0\0\0\0\0\0lC\0\0\0\0\0\0lC\0\0\0\0\0\0\264\1\0\0\0\0\0\0\264\1\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0L\361\223\237f\0\10\317\250i\3306FQ\363\32\254\322\3 01\304\0\0\0\0\3\20\0\0}\0\0\0\0\2\0\0\17\0\0\0\1\0\30\205D\4\201\200a\200\2\0%L\4\200\201\0\0\10\30\206\4\200\10\2!\300\220\0@\0\201\204\3\21\204\244`\0F\10\fH\0\3\200\24\201\0\212\4\t\3\311\204\10\2l\30\200B\5\261\10H\1\204\10\0 \0\254\24t\201\22\10T\4\0\22BE\t@\340\20\f\224\34\0\0Q\0\300 A\0H(\f\300C\10D\231\2\0\35\0\0\301\2 \212\21Ql\264\205\200\0D\10\350"\16\0\0\0\0\4@\0\0\0\6\220\16\0\0(\5\7\0f\0b\244\0\2\4\200\200@\0P2\10\0\0\0\0\340\0\0\1\1\t\34\202T#\10\n\10\0A\200\2 \4\202;\4@\27\25\2\37@\242`\33\24\24\201\2E\306\2\0\210\21\0\0'\200\2\302!\f\304\0\2\1 \340\10\10\0\240 \262\0\2240\201\204\21\0a\f\302\f\34\10\260\21\r\0@\4 "\4\4\0@\204\263\201\f\200\320\31\25p4\200\2\200\6Ta\0\224D!\3\244\200@A\20@i@\n\240\240\223\0\23$\354\2D&\270\10\20\0C\1 H$\0\0C\204\2B\254\21@\4 "@\22\16 \200A\5\221Q", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=2521144, ...}) = 0 mmap(NULL, 4596552, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34e86f000 mprotect(0x7fd34eaa5000, 2097152, PROT_NONE) = 0 mmap(0x7fd34eca5000, 167936, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x236000) = 0x7fd34eca5000 mmap(0x7fd34ecce000, 13128, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34ecce000 close(4) = 0 open("/usr/lib64/sssd/libdhash.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdhash.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\n\0\0\0\0\0\0@\0\0\0\0\0\0\0\3205\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L$\0\0\0\0\0\0L$\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310-\0\0\0\0\0\0\310- \0\0\0\0\0\310- \0\0\0\0\0\260\2\0\0\0\0\0\0\270\2\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\350-\0\0\0\0\0\0\350- \0\0\0\0\0\350- \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\314\36\0\0\0\0\0\0\314\36\0\0\0\0\0\0\314\36\0\0\0\0\0\0\324\0\0\0\0\0\0\0\324\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310-\0\0\0\0\0\0\310- \0\0\0\0\0\310- \0\0\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\202+\273\247\313u\263* \350"\356\333\251\373::\6\363s\331\0\0\0\0\21\0\0\0\r\0\0\0\2\0\0\0\7\0\0\0\31\22"\200\200\3\10\20B\220%\205\34\0@\r\r\0\0\0\16\0\0\0\17\0\0\0\0\0\0\0\20\0\0\0\22\0\0\0\0\0\0\0\25\0\0\0\0\0\0\0\27\0\0\0\30\0\0\0\31\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\34\0\0\0\0\0\0\0w\251\371;\307\0WI\343\252\232\204<\340\314o\373\261:qbR!\373XhCg\323's\227\236Sm/\251\371,|\221a3Iym\357\232\205j\221WM}\240\303\2114\354\353\322\317\27\231\215\371GR\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0>\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\t\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\276\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0u\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=15632, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f9000 mmap(NULL, 2109568, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34e66b000 mprotect(0x7fd34e66e000, 2093056, PROT_NONE) = 0 mmap(0x7fd34e86d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7fd34e86d000 close(4) = 0 open("/usr/lib64/sssd/libtalloc.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libtalloc.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@'\0\0\0\0\0\0@\0\0\0\0\0\0\0\210\351\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\34\322\0\0\0\0\0\0\34\322\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\230\335\0\0\0\0\0\0\230\335 \0\0\0\0\0\230\335 \0\0\0\0\0T\4\0\0\0\0\0\0\230\4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300\335\0\0\0\0\0\0\300\335 \0\0\0\0\0\300\335 \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\310\272\0\0\0\0\0\0\310\272\0\0\0\0\0\0\310\272\0\0\0\0\0\0\34\3\0\0\0\0\0\0\34\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\230\335\0\0\0\0\0\0\230\335 \0\0\0\0\0\230\335 \0\0\0\0\0h\2\0\0\0\0\0\0h\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0 GNU\0\374\200E\361~\373\364\334\360\313\331Dv\361q\311iq\253e\0\0\0\0C\0\0\0&\0\0\0\10\0\0\0\t\0\0\0 \20\0\1\0101\203\0\0\240\0\220\0\4p\10v\301\370\3\224\20\4\2A\5\374\17\2<\221\4\f\20\22\250\0\4\10\0\1\0\201"\370\20\0\20\10` \30\250C\212p\36\255&\6\v\361T\7&\0\0\0'\0\0\0\0\0\0\0(\0\0\0\0\0\0\0)\0\0\0\0\0\0\0*\0\0\0,\0\0\0000\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0<\0\0\0?\0\0\0B\0\0\0D\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0\0\0\0\0G\0\0\0H\0\0\0J\0\0\0K\0\0\0\0\0\0\0L\0\0\0M\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0N\0\0\0O\0\0\0Q\0\0\0R\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0\0\0T\0\0\0V\0\0\0W\0\0\0X\0\0\0\0\0\0\0Z\0\0\0\\0\0\0]\0\0\0^\0\0\0\0\0\0\0`\0\0\0a\0\0\0e\0\0\0g\0\0\0\0\0\0\0h\0\0\0i\0\0\0\0\0\0\0k\0\0\0m\0\0\0p\0\0\0s\0\0\0u\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=61704, ...}) = 0 mmap(NULL, 2155056, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34e45c000 mprotect(0x7fd34e46a000, 2093056, PROT_NONE) = 0 mmap(0x7fd34e669000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xd000) = 0x7fd34e669000 close(4) = 0 open("/usr/lib64/sssd/libsystemd.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libsystemd.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@O\0\0\0\0\0\0@\0\0\0\0\0\0\0(\24\3\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\361\351\2\0\0\0\0\0\361\351\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\250\366\2\0\0\0\0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0\320\t\0\0\0\0\0\0008\24\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0 \370\2\0\0\0\0\0 \370"\0\0\0\0\0 \370"\0\0\0\0\0\360\2\0\0\0\0\0\0\360\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\250\366\2\0\0\0\0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0\0\0\0\0\0\0\0\0008\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0P\345td\4\0\0\0$\212\2\0\0\0\0\0$\212\2\0\0\0\0\0$\212\2\0\0\0\0\0\204\f\0\0\0\0\0\0\204\f\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\250\366\2\0\0\0\ 0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0X\t\0\0\0\0\0\0X\t\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0001\264'\262\214\20\306\01612\340"\305\225l\364\36\233\343\217\0\0\0\0a\0\0\0\205\0\0\0\20\0\0\0\n\0\0\0\24\31@\5\0\210\0\246\202\204\230\2@\20@V\0A\5\0\26J\f\34@\200\1\0\0\0\10\2\4\0202\304@\210\24@\t\0\20\340 \10\0\0\200h\2\20"\4\221\20$\300\212\304"aPo1\25H@\22\23l\10J\20\0\200\0\0 \1C@\324\10@\0\0044\r\244\20\200\304N\22P\250\24\10\210\2D",\300\0`\204i\2j\20\4\0\4E\4\4 \20\300\4\201\224\0\200\30\10\0\0\0\0\0\0\0\0\205\0\0\0\207\0\0\0\211\0\0\0\212\0\0\0\0\0\0\0\213\0\0\0\215\0\0\0\216\0\0\0\0\0\0\0\0\0\0\0\217\0\0\0\0\0\0\0\220\0\0\0\221\0\0\0\223\0\0\0\225\0\0\0\227\0\0\0\231\0\0\0\232\0\0\0\234\0\0\0\236\0\0\0\237\0\0\0\241\0\0\0\242\0\0\0\243\0\0\0\0\0\0\0\245\0\0\0\0\0\0\0\0\0\0\0\247\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=203688, ...}) = 0 mmap(NULL, 2296544, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34e22b000 mprotect(0x7fd34e25a000, 2097152, PROT_NONE) = 0 mmap(0x7fd34e45a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2f000) = 0x7fd34e45a000 close(4) = 0 open("/usr/lib64/sssd/libssl3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libssl3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\311\0\0\0\0\0\0@\0\0\0\0\0\0\0\270\240\5\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\324*\5\0\0\0\0\0\324*\5\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310:\5\0\0\0\0\0\310:%\0\0\0\0\0\310:%\0\0\0\0\0\240@\0\0\0\0\0\0@L\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0@m\5\0\0\0\0\0@m%\0\0\0\0\0@m%\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0004\200\4\0\0\0\0\0004\200\4\0\0\0\0\0004\200\4\0\0\0\0\0T\27\0\0\0\0\0\0T\27\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310:\5\0\0\0\0\0\310:%\0\0\0\0\0\310:%\0\0\0\0\00085\0\0\0\0\0\00085\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\332Z\330,\315\25q\256\22<L\347\273\251\2 15\363\310&\213;\0\0\0\0a\0\0\0\3\1\0\0\20\0\0\0\n\0\0\0'\1H\220\2R\25C\24\2\0@\10\1\0\261\224\22\2" \4J\6\0\5\262AD\0@\4A\4\0\0\211\4@A\211\20\6\0\1\200\200\1"0\0\0@1!\30\0\24\0\0!`\0\0\21)\202\204\2&$@\201\0\0\16\225\310 \10T\f\200\0\0\21\4\2\3\240\2\310\f\0\202\204\10\4-L\16A&L\205\216\240\4\0@\234\10\20\0@\241\2\0\1\0\nQ\340D\220\0\214I\3\1\0\0\0\0\0\0\0\0\0\0\5\1\0\0\6\1\0\0\t\1\0\0\n\1\0\0\16\1\0\0\20\1\0\0\21\1\0\0\23\1\0\0\25\1\0\0\32\1\0\0\34\1\0\0\35\1\0\0\37\1\0\0 \1\0\0!\1\0\0"\1\0\0#\1\0\0$\1\0\0\0\0\0\0%\1\0\0&\1\0\0\0\0\0\0(\1\0\0*\1\0\0+\1\0\0,\1\0\0\0\0\0\0-\1\0\0.\1\0\0000\1\0\0002\1\0\0003\1\0\0005\1\0\0007\1\0\0\0\0\0\0:\1\0\0<\1\0\0>\1\0\0?\1\0\0B\1\0\0C\1\0\0\0\0\0\0E\1\0\0F\1\0\0H\1\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=370680, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f8000 mmap(NULL, 2459400, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34dfd2000 mprotect(0x7fd34e025000, 2097152, PROT_NONE) = 0 mmap(0x7fd34e225000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x53000) = 0x7fd34e225000 mmap(0x7fd34e22a000, 1800, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34e22a000 close(4) = 0 open("/usr/lib64/sssd/libsmime3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libsmime3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\223\0\0\0\0\0\0@\0\0\0\0\0\0\0P\212\2\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0dA\2\0\0\0\0\0dA\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0hO\2\0\0\0\0\0hO"\0\0\0\0\0hO"\0\0\0\0\0`+\0\0\0\0\0\0\20,\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\340l\2\0\0\0\0\0\340l"\0\0\0\0\0\340l"\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24\346\1\0\0\0\0\0\24\346\1\0\0\0\0\0\24\346\1\0\0\0\0\0\314\v\0\0\0\0\0\0\314\v\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0hO\2\0\0\0\0\0hO"\0\0\0\0\0hO"\0\0\0\0\0\230 \0\0\0\0\0\0\230 \0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\226\270\313g\3045D\230\23s\366\300 \373\375\333 &\314\206\311\0\0\0\0\203\0\0\0\344\0\0\0\20\0\0\0\n\0\0\0\0\22(b\22\211\t\0 0\244\4\34\200@FD\210q !\6Fx\26\24\211I!\34\213`P\200BT`\0\214\201D\7'\6`\227\20!\0\20\240\tU\5\22\0$B\10\0B@\0\223\225\1\270\3\205\0-\00000\22\5\24\256\250(\260\220\264\261\234\0211\24\3B\0\5\200R\203r\230\v\240\200\2100\200B\314L \0i\23mf\6\20 \2\3@(\20\t\304\264\20%\6\330\3\344\0\0\0\345\0\0\0\347\0\0\0\350\0\0\0\351\0\0\0\0\0\0\0\352\0\0\0\0\0\0\0\354\0\0\0\355\0\0\0\361\0\0\0\0\0\0\0\365\0\0\0\366\0\0\0\370\0\0\0\0\0\0\0\371\0\0\0\372\0\0\0\373\0\0\0\0\0\0\0\374\0\0\0\376\0\0\0\0\1\0\0\1\1\0\0\2\1\0\0\4\1\0\0\7\1\0\0\10\1\0\0\0\0\0\0\t\1\0\0\n\1\0\0\v\1\0\0\0\0\0\0\f\1\0\0\0\0\0\0\r\1\0\0\16\1\0\0\0\0\0\0\21\1\0\0\24\1\0\0\25\1\0\0\26\1\0\0\0\0\0\0\30\1\0\0\31\1\0\0\0\0\0\0\34\1\0\0\36\1\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=168336, ...}) = 0 mmap(NULL, 2259832, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ddaa000 mprotect(0x7fd34ddcf000, 2093056, PROT_NONE) = 0 mmap(0x7fd34dfce000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x24000) = 0x7fd34dfce000 close(4) = 0 open("/usr/lib64/sssd/libnss3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnss3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\242\1\0\0\0\0\0@\0\0\0\0\0\0\0 *\23\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224S\22\0\0\0\0\0\224S\22\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310a\22\0\0\0\0\0\310a2\0\0\0\0\0\310a2\0\0\0\0\0\324l\0\0\0\0\0\0\240\204\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\253\22\0\0\0\0\0\240\2532\0\0\0\0\0\240\2532\0\0\0\0\0P\2\0\0\0\0\0\0P\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\354-\20\0\0\0\0\0\354-\20\0\0\0\0\0\354-\20\0\0\0\0\0$K\0\0\0\0\0\0$K\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310a\22\0\0\0\0\0\310a2\0\0\0\0\0\310a2\0\0\0\0\0008N\0\0\0\0\0\0008N\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\313L\213"&t\310'\334\2 02y\371j\326N`\300\2627L\0\0\0\0\t\2\0\0000\1\0\0\200\0\0\0\r\0\0\0008\240\n\2`!\20\1\20\0\0\0\200\0\0!\7\0\22\214$\220K\4\5\2\20\0\20\t\4Y8\4\302\210\0"\0\2\0(\20\0\2 2\0\200H\0\f\4\10\270@\5\30\3\300\0!\2\2\200 K&\0B \0\0\1\5\17\0\2\1\10\220\216N\30\36\200R\30\22\0\6\2\0\30\240!\0\1\4\10\20\2\0@\306\3$\205\310\0\22\2000\240\21\20\r\10$9J\210\2\374kqP\240@\0\0HP\201\200\0\343\0\232\244\16\270m \352$P\f\2\0204\n\240\3\4\0\204\24\0\2\20\0\201\202\20\0\5\4\6\206\0@\214\2\0\20\300\0\1\0\10\n`D@\20\0\0\1\0 \240\215\5X\0001\2\0\4\300H"\4 \2\0\6F\20"\f\0\t\222D\10\261\22\0e\203\1\230 \10\210\0\202\10\0@\5\3\204\1\4\4\300\3000\0@\304\220 E\220\244\0\0\0\244\0\0\0\20\200\221!x\v\0244\204\v5$+!\201\0\0 \0&``\0 \302 a\0\0\200Q\2\200\0\0\10\0\1\0\2\0\4 \0\0\0\200@\0@\0\1\200\20P\n \0@\0\3\5\4\4", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=1257824, ...}) = 0 mmap(NULL, 3335784, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34da7b000 mprotect(0x7fd34dba1000, 2097152, PROT_NONE) = 0 mmap(0x7fd34dda1000, 28672, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x126000) = 0x7fd34dda1000 mmap(0x7fd34dda8000, 5736, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34dda8000 close(4) = 0 open("/usr/lib64/sssd/libnssutil3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnssutil3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\314\0\0\0\0\0\0@\0\0\0\0\0\0\0\360\1\3\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\214\204\2\0\0\0\0\0\214\204\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\10\216\2\0\0\0\0\0\10\216"\0\0\0\0\0\10\216"\0\0\0\0\0\300g\0\0\0\0\0\0\20n\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\354\2\0\0\0\0\0\240\354"\0\0\0\0\0\240\354"\0\0\0\0\0@\2\0\0\0\0\0\0@\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0|E\2\0\0\0\0\0|E\2\0\0\0\0\0|E\2\0\0\0\0\0\34\t\0\0\0\0\0\0\34\t\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\10\216\2\0\0\0\0\0\10\216"\0\0\0\0\0\10\216"\0\0\0\0\0\370a\0\0\0\0\0\0\370a\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\213\272 y1X\343\361\330d\nI\220J\216Rs\331\311\10\307\0\0\0\0\305\0\0\0Z\0\0\0 \0\0\0\v\0\0\0\0h\0\20\0D\2\0\230\4\310\f\0\0\n\342\1@\300\320\10F\4\200\t\300H\2\17\0062!`(\4H\0A\4\0\f\0\0\vC\24\3\1\0!l\2!\201\4"\200\210\0\250P\1\4p\1\200\10\10\0A\2\0*)(% \t\10\f\230\0\0\2+\10\20Q\200\10\203\20\0\0(\0\275\2@@p\200\300\200\26AH\v \0\16\0\230\2030\17\n\26l\22\204\0C\0@\16\1\22\0\0!\310\2!\200@\0\4\10\222\0@\0\0\200\0\0\4\200\223 x\10\22\202\10\n \0@\4\200\20\0\1\33?b\240\0\356\0\30T\250\f\240\4\226\21A\30\2\0\2000\20\2\f\206\20\32\6\5dB@\0\0\0\0\202\4\200&\0\234\26\4$h\310\0\240\220!\4\20\31\221p\242\10\1A\f@\4\21\0@E\0Z\200\31`\2!\22\20\1\1\2\22\0 \0\5B(\0\0\224\342Z\0\0\0\0\0\0\0]\0\0\0^\0\0\0`\0\0\0b\0\0\0c\0\0\0\0\0\0\0e\0\0\0f\0\0\0\0\0\0\0\0\0\0\0i\0\0\0k\0\0\0\0\0\0\0m\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=198960, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f7000 mmap(NULL, 2292760, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34d84b000 mprotect(0x7fd34d874000, 2093056, PROT_NONE) = 0 mmap(0x7fd34da73000, 32768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x28000) = 0x7fd34da73000 close(4) = 0 open("/usr/lib64/sssd/libplds4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libplds4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\16\0\0\0\0\0\0@\0\0\0\0\0\0\0x6\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0D$\0\0\0\0\0\0D$\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\330-\0\0\0\0\0\0\330- \0\0\0\0\0\330- \0\0\0\0\0 \3\0\0\0\0\0\0(\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\370-\0\0\0\0\0\0\370- \0\0\0\0\0\370- \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\200\35\0\0\0\0\0\0\200\35\0\0\0\0\0\0\200\35\0\0\0\0\0\0\f\1\0\0\0\0\0\0\f\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\330-\0\0\0\0\0\0\330- \0\0\0\0\0\330- \0\0\0\0\0(\2\0\0\0\0\0\0(\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\200\3\245\21a:\261\24\222z,4\235b\274\ 211\2717/-\0\0\0\0\21\0\0\0\r\0\0\0\4\0\0\0\10\0\0\0\0\0\220\0\0\200@\0,\21"\4\30\221\300\22\0c\245\212X\203\10+\300\0H\5\4\6&\0\r\0\0\0\21\0\0\0\23\0\0\0\27\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\36\0\0\0\37\0\0\0"\0\0\0$\0\0\0&\0\0\0'\0\0\0)\0\0\0\0\0\0\0*\0\0\0+\0\0\0\220\370\353\316\326\265\212\350B\325\34\251IwcC\352\323\357\16U61fb9\320\351h/\237d\214\311\244\27\271\215\361\16\306\362\344u\330qX\34Q\0034X\273\343\222|\216Y\36\314\236=\352\202\343\207\265\303CE\325\354\26\257\324\27\226\375\10\256\233\322\277\267\224s\214\267M\232\321?\210\351\21Bm|\357\250md}\357\2509+\272\245\3574\334\247\263`\353\333\351-\2037\24\253\263\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\34\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\336\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=15800, ...}) = 0 mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34d647000 mprotect(0x7fd34d64a000, 2093056, PROT_NONE) = 0 mmap(0x7fd34d849000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7fd34d849000 close(4) = 0 open("/usr/lib64/sssd/libplc4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libplc4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\24\0\0\0\0\0\0@\0\0\0\0\0\0\0@G\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3546\0\0\0\0\0\0\3546\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\330=\0\0\0\0\0\0\330= \0\0\0\0\0\330= \0\0\0\0\0\200\3\0\0\0\0\0\0\230\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\370=\0\0\0\0\0\0\370= \0\0\0\0\0\370= \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(.\0\0\0\0\0\0(.\0\0\0\0\0\0(.\0\0\0\0\0\0d\1\0\0\0\0\0\0d\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\330=\0\0\0\0\0\0\330= \0\0\0\0\0\330= \0\0\0\0\0(\2\0\0\0\0\0\0(\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0b\314\247]\262)\244\331\305\271/|\303l\351\3 5\335\363|\370\0\0\0\0%\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0@ \0010\331\251I\205<@xA >\303\30 3\306\1\10A\10)\201\201\214\t\200\225\226\263\0\0\0\0\34\0\0\0\36\0\0\0\0\0\0\0\0\0\0\0!\0\0\0#\0\0\0$\0\0\0%\0\0\0&\0\0\0(\0\0\0)\0\0\0*\0\0\0+\0\0\0,\0\0\0.\0\0\0/\0\0\0001\0\0\0\0\0\0\0002\0\0\0003\0\0\0005\0\0\0\0\0\0\0008\0\0\0009\0\0\0;\0\0\0<\0\0\0=\0\0\0\0\0\0\0\0\0\0\0?\0\0\0A\0\0\0B\0\0\0C\0\0\0D\0\0\0G\0\0\0\0\0\0\0\262\221-\2719P\34"\256#;\214\322\264\234\32\223\226\304\312\34\260\205\33\353\323\357\16\301\254\247ewS\233\32\211E\16nd+\34"E\336\251e\275\227M\363\377W\241e\371*\34"?f\247e\fo\224\32\351|\250em|\357\2506o\234\32\211\2145\266\367\333Jq\21m\247e$g\247e\363o\34"\370}\7\33X\255:\36;\235\300\32\251\230\251e\6\215\247e\331qX\34\273\343\222|Uw,\276p)\34"\311\17D\271", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=20096, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34d442000 mprotect(0x7fd34d446000, 2093056, PROT_NONE) = 0 mmap(0x7fd34d645000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7fd34d645000 close(4) = 0 open("/usr/lib64/sssd/libnspr4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnspr4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\314\0\0\0\0\0\0@\0\0\0\0\0\0\0\230\320\3\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0004\224\3\0\0\0\0\0004\224\3\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@\227\3\0\0\0\0\0@\227#\0\0\0\0\0@\227#\0\0\0\0\0\250\34\0\0\0\0\0\0\340E\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\235\3\0\0\0\0\0\240\235#\0\0\0\0\0\240\235#\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\230\16\3\0\0\0\0\0\230\16\3\0\0\0\0\0\230\16\3\0\0\0\0\0\24\26\0\0\0\0\0\0\24\26\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@\227\3\0\0\0\0\0@\227#\0\0\0\0\0@\227#\0\0\0\0\0\300\10\0\0\0\0\0\0\300\10\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\3 01V\240\353\211\26\345\230\331\247>_\333\354\350f\346\236\362\214\0\0\0\0\7\1\0\0\257\0\0\0@\0\0\0\f\0\0\0\10\20\360\0 \4\2\0\0\20\202\1\1\22\0 \0\20\4&\0\2\200@@\3\0\202\0\200\200A\10\10\26\200\0000\240\2\205\0\20P@\240\0\301\300\210@@\22\200q\10\244\0\2\305\4\10\22"\0\0\0\1\1\0\240\0022\0\6\21\200\24\0B\0@\2044\1P\20\t@\200\231\240\0\4\0\6\16\10-@ \0\0`\2\10\4\0\231\32@\24\0A\4\2\0P!\210\255\322`\200\210\6@0\200\22\r\t\1T\240\20@\202)\0l\20\20$\20c\0\1\23\t\32(\0\1%\0\0P\n\204\0\10\0\221\21e\20\320\v\300\21 \244\201 \1\200@\24\0@\0\4 \0\0\30\7\10U\0\10D\0$\0\250\0\200\20\t\200!\1\0p\0\0\0\4\4\2\3\0D\340\246\2\10\4\0\10H!A%@U\0\310I\255\30\200a\0\0\0``\0\0\4\0\0\0\4\0\25 d\1\202\4\0\34\2\20\20&\0.\2\20\201D \0\0\0\0\10"\214\0\4\0\3\1 \2a\0\4\0\1\0\0j\0 A\20\36\n\200\3001D\1\224\0\0\0\21\202\0\v\1\4\0\0\30\r\4\0\277\4(\245", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=251864, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f6000 mmap(NULL, 2350368, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34d204000 mprotect(0x7fd34d23e000, 2093056, PROT_NONE) = 0 mmap(0x7fd34d43d000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x39000) = 0x7fd34d43d000 mmap(0x7fd34d440000, 7456, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34d440000 close(4) = 0 open("/usr/lib64/sssd/libpthread.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libpthread.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200m\0\0\0\0\0\0@\0\0\0\0\0\0\0H!\2\0\0\0\0\0\0\0\0\0@\0008\0\t\0@\0(\0'\0\6\0\0\0\5\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\370\1\0\0\0\0\0\0\370\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0\260\22\1\0\0\0\0\0\260\22\1\0\0\0\0\0\260\22\1\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\350e\1\0\0\0\0\0\350e\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`k\1\0\0\0\0\0`k!\0\0\0\0\0`k!\0\0\0\0\0\200\7\0\0\0\0\0\0(I\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0Pm\1\0\0\0\0\0Pm!\0\0\0\0\0Pm!\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\314\22\1\0\0\0\0\0\314\22\1\0\0\0\0\0\314\22\1\0\0\0\0\0t\n\0\0\0\0\0\0t\n\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\ 0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`k\1\0\0\0\0\0`k!\0\0\0\0\0`k!\0\0\0\0\0\240\4\0\0\0\0\0\0\240\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0|\177\374}\242\250\201\20\374\342\236]\274-\243\10N\5\352\10\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\345\1\0\0V\0\0\0 \0\0\0\v\0\0\0\31#\2\261\1\10\20\2@@a\370\3\10\10\25\200 \0\0\0\0\200\300\321Q\0\0\0\22\353\3020D\0\10\20A\0\2\0\2\f\1\200\v\221\1\330\240\r\240@\230 \244\200\21\n\202-l@g\214V\24\0\224 \200$H\200P(\1\22\f\311B\240\220\22\10\f \2ZdA\245c\4@\n\n\2\0\2009\1(\314@\204\201@\22\10(\fD\0\0\0\200Q\10\200\35\4B\320\2608A\0\1\0\0\265\0300\0\200`\2\20"\0\tA\20\1\5\0P(\251\2\7(\0\0\202\4\230@\4\0\20\340T\0\2@\2\2\20\3010D\26\200\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=142152, ...}) = 0 mmap(NULL, 2208904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34cfe8000 mprotect(0x7fd34cfff000, 2093056, PROT_NONE) = 0 mmap(0x7fd34d1fe000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x16000) = 0x7fd34d1fe000 mmap(0x7fd34d200000, 13448, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34d200000 close(4) = 0 open("/usr/lib64/sssd/libdl.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdl.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\16\0\0\0\0\0\0@\0\0\0\0\0\0\0008C\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0 \0\37\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\304\37\0\0\0\0\0\0\304\37\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0X-\0\0\0\0\0\0X- \0\0\0\0\0X- \0\0\0\0\0@\3\0\0\0\0\0\0\330\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\210-\0\0\0\0\0\0\210- \0\0\0\0\0\210- \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\0\32\0\0\0\0\0\0\0\32\0\0\0\0\0\0\0\32\0\0\0\0\0\0\274\0\0\0\0\0\0\0\274\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0X-\0\0\0\0\0\0X- \0\0\0\0\0X- \0\0\0\0\0\250\2\0\0\0\0\0\0\250\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\250\345\361\311\262\225Mb\276m\311\232J\243S \365\260\372P.\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\33\0\0\0\32\0\0\0\2\0\0\0\7\0\0\0\230\2\21\0\200H\0\4\22\0\0@\203(\10\236\32\0\0\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\35\0\0\0\0\0\0\0\36\0\0\0\0\0\0\0\37\0\0\0\0\0\0\0 \0\0\0"\0\0\0#\0\0\0%\0\0\0&\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0'\0\0\0\0\0\0\0\0\0\0\0\353\26\251\30a\257\0\371\301S\200\30\273\25sB\257\304M\17\221!\374\370\6\2\4\371\3733\373\17\371\31sB\372\31sB\225\263_\31\177\236\320\30a\242\222\6\5\350\7\371\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0=\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\375\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\337\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19256, ...}) = 0 mmap(NULL, 2109744, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34cde4000 mprotect(0x7fd34cde6000, 2097152, PROT_NONE) = 0 mmap(0x7fd34cfe6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7fd34cfe6000 close(4) = 0 open("/usr/lib64/sssd/libc.so.6", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P&\2\0\0\0\0\0@\0\0\0\0\0\0\0`\323 \0\0\0\0\0\0\0\0\0@\0008\0\n\0@\0K\0J\0\6\0\0\0\5\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0 \351\30\0\0\0\0\0 \351\30\0\0\0\0\0 \351\30\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260.\34\0\0\0\0\0\260.\34\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\240Q\0\0\0\0\0\0\340\232\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0`k\34\0\0\0\0\0`k<\0\0\0\0\0`k<\0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0p\2\0\0\0\0\0\0p\2\0\0\0\0\0\0p\2\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\20\0\0\0\0\0\0\0\240\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0P\345td\4\0\0\0<\351\30\0\0\0\0\0<\351\30\0\0\0\0\0<\351\30\0\0\0\0\ 0\314j\0\0\0\0\0\0\314j\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\0009\0\0\0\0\0\0\0009\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0)5q\213\177\37\v,\265*\234S\321\265\3377_\270H\327\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\363\3\0\0\7\0\0\0\0\1\0\0\16\0\0\0\0000\20D\240 \2\1\210\3\346\220\305E\214\0\300\0\10\0\5\200\0`\300\200\0\r\212\f\0\4\20\0\210D2\10.@\210T<, \0162H&\204\300\214\4\10\0\2\2\16\241\254\32\4f\300\0\3002\0\300\0P\1 \201\10\204\v ($\0\4 Z\0\20X\200\312DB(\0\6\200\20\30B\0 @\200\0\tP\0Q\212@\20\0\0\0\0\10\0\0\21\20", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=2156064, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f5000 mmap(NULL, 3985888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ca16000 mprotect(0x7fd34cbd9000, 2097152, PROT_NONE) = 0 mmap(0x7fd34cdd9000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1c3000) = 0x7fd34cdd9000 mmap(0x7fd34cddf000, 16864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34cddf000 close(4) = 0 open("/usr/lib64/sssd/libz.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20!\0\0\0\0\0\0@\0\0\0\0\0\0\0HY\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0LD\1\0\0\0\0\0LD\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0(K\1\0\0\0\0\0(K!\0\0\0\0\0(K!\0\0\0\0\0008\5\0\0\0\0\0\0@\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0008L\1\0\0\0\0\0008L!\0\0\0\0\0008L!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\200)\1\0\0\0\0\0\200)\1\0\0\0\0\0\200)\1\0\0\0\0\0\244\3\0\0\0\0\0\0\244\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0(K\1\0\0\0\0\0(K!\0\0\0\0\0(K!\0\0\0\0\0\330\4\0\0\0\0\0\0\330\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\271\325\3674(\275j\326\214\226\230kW\276\243\267\316\333\2 27E\0\0\0\0C\0\0\0\30\0\0\0\10\0\0\0\t\0\0\0\0\3h\24\f\3$\24\221\0\223A;\0\16\30\234\1\4\4\21\4\0\210,\0\303"\224\27\212\203\0c0\262G\212PC ,\20\35\210\341\200\213A\220\23e$g\304\201V\0.\20\2\200\0\20\30\0\0\0\33\0\0\0\34\0\0\0\35\0\0\0!\0\0\0"\0\0\0$\0\0\0%\0\0\0\0\0\0\0&\0\0\0'\0\0\0*\0\0\0-\0\0\0.\0\0\0\0\0\0\0000\0\0\0\0\0\0\0001\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0\0\0\0\0009\0\0\0:\0\0\0;\0\0\0\0\0\0\0<\0\0\0\0\0\0\0>\0\0\0?\0\0\0@\0\0\0A\0\0\0C\0\0\0D\0\0\0F\0\0\0I\0\0\0\0\0\0\0L\0\0\0N\0\0\0\0\0\0\0O\0\0\0S\0\0\0T\0\0\0\0\0\0\0U\0\0\0\0\0\0\0W\0\0\0Y\0\0\0\0\0\0\0Z\0\0\0\\0\0\0\0\0\0\0]\0\0\0`\0\0\0b\0\0\0\0\0\0\0c\0\0\0d\0\0\0e\0\0\0\0\0\0\0\0\0\0\0f\0\0\0g\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=90248, ...}) = 0 mmap(NULL, 2183272, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34c800000 mprotect(0x7fd34c815000, 2093056, PROT_NONE) = 0 mmap(0x7fd34ca14000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7fd34ca14000 close(4) = 0 open("/usr/lib64/sssd/libcrypt.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcrypt.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\16\0\0\0\0\0\0@\0\0\0\0\0\0\0\240\226\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0 \0\37\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Ht\0\0\0\0\0\0Ht\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\200}\0\0\0\0\0\0\200} \0\0\0\0\0\200} \0\0\0\0\0`\3\0\0\0\0\0\0\300\344\2\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240}\0\0\0\0\0\0\240} \0\0\0\0\0\240} \0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0@m\0\0\0\0\0\0@m\0\0\0\0\0\0@m\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\200}\0\0\0\0\0\0\200} \0\0\0\0\0\200} \0\0\0\0\0\200\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\213\10\244\31\321\337\10\301\201T\264"\2 36\2001\203s\177\32\240\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\17\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\4I\300,$\204 \f\0\0\0\0\0\0\0\0\0\0\0\0\36\0\0\0\37\0\0\0 \0\0\0\0\0\0\0!\0\0\0"\0\0\0\0\0\0\0#\0\0\0\0\0\0\0$\0\0\0%\0\0\0\0\0\0\0k\31Qj\233(\375B\233`\205\33\327\16?\17I->\333\235C\r\375\313\373_\22\273\25sB\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0)\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\0\0\0\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\246\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=40608, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f4000 mmap(NULL, 2318912, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34c5c9000 mprotect(0x7fd34c5d1000, 2093056, PROT_NONE) = 0 mmap(0x7fd34c7d0000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7000) = 0x7fd34c7d0000 mmap(0x7fd34c7d2000, 184896, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34c7d2000 close(4) = 0 open("/usr/lib64/sssd/libcap.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcap.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\25\0\0\0\0\0\0@\0\0\0\0\0\0\0@G\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2047\0\0\0\0\0\0\2047\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\320=\0\0\0\0\0\0\320= \0\0\0\0\0\320= \0\0\0\0\0H\4\0\0\0\0\0\0P\4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\360=\0\0\0\0\0\0\360= \0\0\0\0\0\360= \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\3300\0\0\0\0\0\0\3300\0\0\0\0\0\0\3300\0\0\0\0\0\0\24\1\0\0\0\0\0\0\24\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\320=\0\0\0\0\0\0\320= \0\0\0\0\0\320= \0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\25=KEc\301_T\316\300\20\26\5,\23 6;\345i;\210\0\0\0\0\21\0\0\0\36\0\0\0\4\0\0\0\10\0\0\0@\10$\201\30\20@\204\270$\0(\212\0\30$\20\242\220\4\10\10\33\t\2\0H\341\204T\2\220\36\0\0\0\37\0\0\0 \0\0\0!\0\0\0&\0\0\0(\0\0\0)\0\0\0+\0\0\0.\0\0\0002\0\0\0005\0\0\0006\0\0\0\0\0\0\0008\0\0\0009\0\0\0;\0\0\0>\0\0\0E3vg\353\323\357\16\271\215\361\16\216\332\241]\nzqP\330qX\34\210q\356\262[\207i\224\300\277<\316\273\343\222|\37\344l\224\30\277[\27\261D=\BE\325\354t\343\324\225{a,\20\334\347\250\231\360\342kP\226t\207c\25\6\365\262`\n\352\262\226\327kPM\247:\352\337\374~\25,\366-\20#\330\250\231}\335\201c\354\26\v\210#\322\201c\252T\275\331\322^3\20\377\356\311x\261s\16\210\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\265\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0{\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=20096, ...}) = 0 mmap(NULL, 2114080, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34c3c4000 mprotect(0x7fd34c3c8000, 2093056, PROT_NONE) = 0 mmap(0x7fd34c5c7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7fd34c5c7000 close(4) = 0 open("/usr/lib64/sssd/libm.so.6", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libm.so.6", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0PS\0\0\0\0\0\0@\0\0\0\0\0\0\0xP\21\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0#\0"\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\7\20\0\0\0\0\0\374\7\20\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0p\r\20\0\0\0\0\0p\r0\0\0\0\0\0p\r0\0\0\0\0\0t\3\0\0\0\0\0\0\310\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\220\r\20\0\0\0\0\0\220\r0\0\0\0\0\0\220\r0\0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h\206\17\0\0\0\0\0h\206\17\0\0\0\0\0h\206\17\0\0\0\0\0,\22\0\0\0\0\0\0,\22\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0p\r\20\0\0\0\0\0p\r0\0\0\0\0\0p\r0\0\0\0\0\0\220\2\0\0\0\0\0\0\220\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\17\341\360m\25\360D\255Jq\246\324\30'\300 f\6\242CB\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\10\3\0\0\22\0\0\0@\0\0\0\f\0\0\0%\0`\0\0\240."\200\0\26\211\0 E"\2\0\300``i\10\212\0\t\0\0\0\0\0\0\0\0\0\0\0\0\212P\20\1\10\0\0\4\1\302\24\1 \210"\0\304\243X\240\n\6\216\0\212\0\0\4\0@\0\0 \20\0\5\0\5\r\7\7\22A\0\1\0\10\0\0@\0\t\0\20\4D\30\4\200a(\22@\4\1\nE\221 @\200\f\22\1\0\0\0\0\0\0\0\0\4\2\0\0\0@\0\200\2\20\322\0\1\10\4\301 E\1\0\310"\0\4\2\0\202\0\4\0\0\0\4\0Y\4\2\0\n\200\1\0\0\4\0\20 \3\0\0\210 \10\20\0\0 \2\0\0\200\10\2\4\0\0HQ\0\0\f\2\0\0 \10 \0\0\0\0 #\4\0\200\0I\2\fc\2 A\221\242@\4\202EL \0\0\300\2\4\200\10\2\r(\2\0\20"\0!\22\30\30\24 8\0\210\0\0\260 B,\10\302\0 \200\361)\24A\21 @\220 \4\1P\20\202\0\0\214\0\0`\242\10\10A\0\0\0 \202", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=1136952, ...}) = 0 mmap(NULL, 3150136, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34c0c2000 mprotect(0x7fd34c1c3000, 2093056, PROT_NONE) = 0 mmap(0x7fd34c3c2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x100000) = 0x7fd34c3c2000 close(4) = 0 open("/usr/lib64/sssd/librt.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/librt.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000"\0\0\0\0\0\0@\0\0\0\0\0\0\0H\241\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0&\0%\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\24e\0\0\0\0\0\0\24e\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@m\0\0\0\0\0\0@m \0\0\0\0\0@m \0\0\0\0\0\24\5\0\0\0\0\0\0\370\16\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0pm\0\0\0\0\0\0pm \0\0\0\0\0pm \0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24S\0\0\0\0\0\0\24S\0\0\0\0\0\0\24S\0\0\0\0\0\0<\2\0\0\0\0\0\0<\2\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@m\0\0\0\0\0\0@m \0\0\0\0\0@m \0\0\0\0\0\300\2\0\0\0\0\0\0\300\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0.\316\241\235h\2,]\330\301\234/B<\26\242(\25d\304\4\0\0\0\20\0\0\0 \1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0b\0\0\0B\0\0\0\10\0\0\0\t\0\0\0\1\0\204!0\0\10@\0\20P\213\340\6\22 \0\10\202@\0(\200 \t\3\0\4@\1@#\2\20\0\2\240\4 \0\10\0\0\2\0\4\0\200\210\206D\20\0\0\20\4P\20\2\322\4\1\4\206\0\0\0\0\0\0\0\0B\0\0\0C\0\0\0D\0\0\0\0\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0H\0\0\0I\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0K\0\0\0\0\0\0\0L\0\0\0\0\0\0\0M\0\0\0\0\0\0\0O\0\0\0P\0\0\0\0\0\0\0Q\0\0\0R\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0T\0\0\0\0\0\0\0\0\0\0\0U\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0V\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=43720, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f3000 mmap(NULL, 2128952, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34beba000 mprotect(0x7fd34bec1000, 2093056, PROT_NONE) = 0 mmap(0x7fd34c0c0000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x6000) = 0x7fd34c0c0000 close(4) = 0 open("/usr/lib64/sssd/libselinux.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320i\0\0\0\0\0\0@\0\0\0\0\0\0\0\310X\2\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<0\2\0\0\0\0\0<0\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\0\0\230\t\0\0\0\0\0\0\300,\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0H=\2\0\0\0\0\0H="\0\0\0\0\0H="\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\0\0(\0\0\0\0\0\0\0\350\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0P\345td\4\0\0\0\350\344\1\0\0\0\0\0\350\344\1\0\0\0\0\0\350\344\1\0\0\0\0\0\264\n\0\0\0\0\0\0\264\n\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\ 0\0p\3\0\0\0\0\0\0p\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\322\335M\243\375\341G}%\277\377\200\363\242_\333T\32\201y\0\0\0\0\305\0\0\0\206\0\0\0 \0\0\0\v\0\0\0\230 \4\201 L\0\3#\20\300\nT\210\357\322B\6h\10\24\26\0\6\20\4\4\0\0\311@\1P.\21\30\0&\th\30 \200*H\10\22\1\1,!\0\20\0\217\7\250@@Q\0\274\0\0\0R\20\236\4\1\5\24\33\21\33\214 \0\3C\10\1H\21\2\2\0\200j\17\304\1\2\210`\203\200\2*\200\202@\200\4\0\0C\30\4\0\20\200:\0!\266\10\5\0\216\0\4\0@\204\24\0F\n\0\200 \0`0T\1@\304\0\20\0\240\24\20\234\10\200\0D\0\204\10@&\7\202\0\200\200\1\10\10\0\2\2\0\200\232\203\4\304\25\221(\2\200\0\10\0\201@\2\201\200\200@@\201\1\2\21\200@\24\201\4\221\313@ \10D\1\0\0\0\2F@\1\0A\220q\20@Eb\0\t"\0\20@@IL\341\24\200<@!\0\0 \0\0\200\310\206\342@\200\22\0\3 @\2!\200T\2!\206\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=155784, ...}) = 0 mmap(NULL, 2255184, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34bc93000 mprotect(0x7fd34bcb7000, 2093056, PROT_NONE) = 0 mmap(0x7fd34beb6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x23000) = 0x7fd34beb6000 mmap(0x7fd34beb8000, 6480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34beb8000 close(4) = 0 open("/usr/lib64/sssd/liblzma.so.5", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/liblzma.so.5", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\2000\0\0\0\0\0\0@\0\0\0\0\0\0\0\330_\2\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<@\2\0\0\0\0\0<@\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`J\2\0\0\0\0\0`J"\0\0\0\0\0`J"\0\0\0\0\0 \10\0\0\0\0\0\0(\10\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300M\2\0\0\0\0\0\300M"\0\0\0\0\0\300M"\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0 \377\1\0\0\0\0\0 \377\1\0\0\0\0\0 \377\1\0\0\0\0\0004\t\0\0\0\0\0\0004\t\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`J\2\0\0\0\0\0`J"\0\0\0\0\0`J"\0\0\0\0\0\240\5\0\0\0\0\0\0\240\5\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0f\376\346_D\306\304gd\311\334J\332`\274\205\257z\3 43o\0\0\0\0a\0\0\0!\0\0\0\20\0\0\0\n\0\0\0\0\1\242\2 @ \301\230 (\204@\0\1\0(\4\10\200\0\202\5\0\6\0\0\202\1\10 \0\0"\0R@\2\4\201\21Ph\241H\205B \0\10\300\200P\0\210\204\10\200T\n\22\210\0\4A\4\0\0\0@\200\0`8T\0\300\0@\0\202\260\20`\214\20\7\243@\0\31\20E\2P\3 \0 \6\2 \0 l\24P\0\303 \340\0\310\10\0\24\4@\20\4\t\0 \2\300\0C0!\0\0\0#\0\0\0\0\0\0\0\0\0\0\0$\0\0\0\0\0\0\0%\0\0\0\0\0\0\0'\0\0\0*\0\0\0\0\0\0\0+\0\0\0\0\0\0\0-\0\0\0/\0\0\0\0\0\0\0000\0\0\0\0\0\0\0\0\0\0\0001\0\0\0\0\0\0\0003\0\0\0005\0\0\0\0\0\0\0007\0\0\0\0\0\0\0008\0\0\0:\0\0\0<\0\0\0@\0\0\0B\0\0\0C\0\0\0\0\0\0\0\0\0\0\0E\0\0\0\0\0\0\0\0\0\0\0F\0\0\0\0\0\0\0J\0\0\0K\0\0\0L\0\0\0M\0\0\0\0\0\0\0O\0\0\0Q\0\0\0R\0\0\0S\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=157400, ...}) = 0 mmap(NULL, 2249352, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ba6d000 mprotect(0x7fd34ba92000, 2093056, PROT_NONE) = 0 mmap(0x7fd34bc91000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x24000) = 0x7fd34bc91000 close(4) = 0 open("/usr/lib64/sssd/liblz4.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/liblz4.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0%\0\0\0\0\0\0@\0\0\0\0\0\0\0\20I\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\33\0\32\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2044\1\0\0\0\0\0\2044\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0(=\1\0\0\0\0\0(=!\0\0\0\0\0(=!\0\0\0\0\0\30\4\0\0\0\0\0\0 \4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\350=\1\0\0\0\0\0\350=!\0\0\0\0\0\350=!\0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(\31\1\0\0\0\0\0(\31\1\0\0\0\0\0(\31\1\0\0\0\0\0L\4\0\0\0\0\0\0L\4\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0(=\1\0\0\0\0\0(=!\0\0\0\0\0(=!\0\0\0\0\0\330\2\0\0\0\0\0\0\330\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0 \1l:m\206!\226\30\177T\32\327\315\370\220\251\374\322\2 57\0\0\0\0a\0\0\0\r\0\0\0\20\0\0\0\n\0\0\0\2\214!\200\21D\302\5\0\240\1\204\0\0\0\0\0%(F\0\322\350%\0\10\220\1\0\0\10\10\220\0\20\20\20\0\3\fh\5\2\3 &\22\330\20\0\0\1\10\2\0\21@\1\240\21\4 \0\4\0 2q@\2\0b\4\n\0\200\21\310\0\10\0\6\2\f\n\20\216\4\0 \2 \302\0H\20H\204@\0\0$\200\0( 6\200\4\240h\212\0\320\0\0L\10\20-\24\16\3\10\204\7P@\r\0\0\0\0\0\0\0\0\0\0\0\16\0\0\0\20\0\0\0\23\0\0\0\24\0\0\0\0\0\0\0\25\0\0\0\26\0\0\0\0\0\0\0\27\0\0\0\32\0\0\0\33\0\0\0\0\0\0\0\34\0\0\0\36\0\0\0\37\0\0\0 \0\0\0!\0\0\0\0\0\0\0#\0\0\0\0\0\0\0\0\0\0\0$\0\0\0%\0\0\0&\0\0\0'\0\0\0(\0\0\0\0\0\0\0)\0\0\0\0\0\0\0*\0\0\0\0\0\0\0,\0\0\0.\0\0\0\0\0\0\0000\0\0\0001\0\0\0\0\0\0\0002\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0:\0\0\0\0\0\0\0;\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=85968, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f2000 mmap(NULL, 2179400, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34b858000 mprotect(0x7fd34b86c000, 2093056, PROT_NONE) = 0 mmap(0x7fd34ba6b000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x13000) = 0x7fd34ba6b000 close(4) = 0 open("/usr/lib64/sssd/libgcrypt.so.11", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgcrypt.so.11", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0u\0\0\0\0\0\0@\0\0\0\0\0\0\0\310"\10\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\301\7\0\0\0\0\0\374\301\7\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@\310\7\0\0\0\0\0@\310'\0\0\0\0\0@\310'\0\0\0\0\0D3\0\0\0\0\0\0\2208\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\315\7\0\0\0\0\0\240\315'\0\0\0\0\0\240\315'\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h\370\6\0\0\0\0\0h\370\6\0\0\0\0\0h\370\6\0\0\0\0\0\254\35\0\0\0\0\0\0\254\35\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@\310\7\0\0\0\0\0@\310'\0\0\0\0\0@\310'\0\0\0\0\0\300\7\0\0\0\0\0\0\300\7\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\327yrC\0011 v\272\304\213Gdl\215\16\201\202Y\320\361\0\0\0\0\203\0\0\0Y\0\0\0 \0\0\0\v\0\0\0\2\1\0\f\30\1\0`"\200\2\10\0\10\\1\0\4\4\224\221D\1@\340\20\0\22\0\4\0$\21\20\34Bp\6\200\n"\10\204\200\0\24\0\0\0\1\2\24\0@\212\252@\0\4\210\200\0\0\0\204\0@\10P\1\1@\310\10\0$AB\1\200\4\1 @\210`@\1\4\240 \211\320\1\10c`P\242C\1\210\n\0\0\23\10\0\220\22\1@\0E\20\200,\0030\0\200@B,\24\10*\200\0\4\20\4,\4@\340X\0\4\222\0\1$\0\n C\200\3131\1\0\2B\1D\1\f\n\201@P0\1E\222\300(\0\1\0T\0000\nQ\0\0\0\200\10\200\5@\200\310 \30\34\223\300\1P\0\0\0\0\0 \vh@\254\220\0\0\200\2\0-\0\212`\1\200\1\20\300\200\0\0\10\0\4 \0\26\23\2A(\200\210\20@DX\4\0\201@\20\0<\0\0\1\200\0\2\200\0\202\0\3\10Y\0\0\0\0\0\0\0Z\0\0\0^\0\0\0`\0\0\0\0\0\0\0a\0\0\0b\0\0\0d\0\0\0\0\0\0\0f\0\0\0g\0\0\0h\0\0\0i\0\0\0\0\0\0\0j\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=535112, ...}) = 0 mmap(NULL, 2621648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34b5d7000 mprotect(0x7fd34b654000, 2093056, PROT_NONE) = 0 mmap(0x7fd34b853000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7c000) = 0x7fd34b853000 mmap(0x7fd34b857000, 208, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34b857000 close(4) = 0 open("/usr/lib64/sssd/libgpg-error.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgpg-error.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\t\0\0\0\0\0\0@\0\0\0\0\0\0\0\260D\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\33\0\32\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|0\0\0\0\0\0\0|0\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0\210\2\0\0\0\0\0\0\220\2\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\10>\0\0\0\0\0\0\10> \0\0\0\0\0\10> \0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0008.\0\0\0\0\0\0008.\0\0\0\0\0\0008.\0\0\0\0\0\0t\0\0\0\0\0\0\0t\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\367l\226Z\5d\345\365\233\255\203\255g/,M\217 \375L\225\0\0\0\0\3\0\0\0\16\0\0\0\2\0\0\0\7\0\0\0\241 @h#\0\22\t\210\4\0\3\250T\0\0\16\0\0\0\24\0\0\0\32\0\0\0\244X\321QBE\325\354\226"\212\v\272\343\222|\356s\274\5\347\22\211\372\234P\204=\354\fp\254\330qX\34\236\246\321\313\354\3^\n\271\215\361\16\352\323\357\16:\320\f\343\1\232_\263\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\t\0\360\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\254\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\343\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\37\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0&\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\24\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19312, ...}) = 0 mmap(NULL, 2113648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34b3d2000 mprotect(0x7fd34b3d6000, 2093056, PROT_NONE) = 0 mmap(0x7fd34b5d5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7fd34b5d5000 close(4) = 0 open("/usr/lib64/sssd/libresolv.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\00009\0\0\0\0\0\0@\0\0\0\0\0\0\0\320\224\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0!\0 \0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240T\1\0\0\0\0\0\240T\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0HU\1\0\0\0\0\0HU!\0\0\0\0\0HU!\0\0\0\0\0\214\f\0\0\0\0\0\0\2704\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\210]\1\0\0\0\0\0\210]!\0\0\0\0\0\210]!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24/\1\0\0\0\0\0\24/\1\0\0\0\0\0\24/\1\0\0\0\0\0\244\3\0\0\0\0\0\0\244\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0HU\1\0\0\0\0\0HU!\0\0\0\0\0HU!\0\0\0\0\0\270\n\0\0\0\0\0\0\270\n\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0pGd\243*\0\2128\223\26\232\374:\20'<h\n\312y\4\0 \0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\307\0\0\0?\0\0\0\20\0\0\0\n\0\0\0\0\0@\0\0\0\200\0\0F \24\0013\244\232\202\202\20\0\2\5\1\20!\2\30\1`\220T\207\200@\0 \20\0\0\0\200\10\0\26\304\20\0\20"\0\2\20\20\30H\4`\304 @ \4B1\6Z\34\200<\20H4\200\0\20\221\1\1\10\204\200\0\0\4@\t\0\0D\200\0\200D\10\20\1\20H\0@\220\224\32\n\0\20Y\20\201\23\0\10\344\f4\4\0\200\6\20\0!\4\7\1\2431\16?\0\0\0\0\0\0\0A\0\0\0B\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0D\0\0\0E\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0G\0\0\0\0\0\0\0\0\0\0\0I\0\0\0\0\0\0\0J\0\0\0K\0\0\0\0\0\0\0L\0\0\0\0\0\0\0M\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0N\0\0\0\0\0\0\0P\0\0\0\0\0\0\0Q\0\0\0\0\0\0\0\0\0\0\0S\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=105744, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f1000 mmap(NULL, 2198016, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34b1b9000 mprotect(0x7fd34b1cf000, 2093056, PROT_NONE) = 0 mmap(0x7fd34b3ce000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x15000) = 0x7fd34b3ce000 mmap(0x7fd34b3d0000, 6656, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fd34b3d0000 close(4) = 0 open("/usr/lib64/sssd/libdw.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdw.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\236\0\0\0\0\0\0@\0\0\0\0\0\0\0P#\5\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0l\325\4\0\0\0\0\0l\325\4\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\200!\0\0\0\0\0\0\260$\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0@\375\4\0\0\0\0\0@\375$\0\0\0\0\0@\375$\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0000^\4\0\0\0\0\0000^\4\0\0\0\0\0000^\4\0\0\0\0\0\274\20\0\0\0\0\0\0\274\20\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\240\33 \0\0\0\0\0\0\240\33\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0B;\177\227\327\217\324*\273?op\205N\23*\32%\303\335\0\0\0\0\305\0\0\0\226\0\0\0 \0\0\0\v\0\0\0\10\207\204\0223\r\350\211\4\6\222\10$\224F\242PL\260\200\300\0\0\202 \220@@\0$\2B(\20\251H\21T\202$\20\0@ \0 \0\0@\212\0 \1\0\0\0\341\0(\200\0\0\2\0000@\0\0\0\30\2\0\200"\204\220\223\31\0$I@\24\210\0 \222\1\204\220\240&\206\0\2\0\0$\200\0\0\1@\20\5\20\200\1)\0 CD(\t\240\251"\20\200\0\6"\24D\n\200\0`\0\nv \240\0\4\271\205\0002\0 \t\216\24\0\244\2\0\210\0\0010\r\0104\0\f\1\0\0\201\10\312\4\22B\210@!\20D\23\10A\320\30@\202@P\0\1\6\256\1\0 \312\3\5\220\326\241 \4\254\0U\0\10\200\1\25\214\200$d\4\10br\0\10\0\0!\244)H\0!\4\260\240\270\0\20\2\4\4\4\0B\332\242(\34$\206\0\232\240\300\2\20\340\1\1\204\0\0!\5\20\1\226\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=338704, ...}) = 0 mmap(NULL, 2427152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34af68000 mprotect(0x7fd34afb6000, 2097152, PROT_NONE) = 0 mmap(0x7fd34b1b6000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x4e000) = 0x7fd34b1b6000 close(4) = 0 open("/usr/lib64/sssd/libgcc_s.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgcc_s.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320*\0\0\0\0\0\0@\0\0\0\0\0\0\0\20S\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224L\1\0\0\0\0\0\224L\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\260M\1\0\0\0\0\0\260M!\0\0\0\0\0\260M!\0\0\0\0\0\320\3\0\0\0\0\0\0P\6\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\330M\1\0\0\0\0\0\330M!\0\0\0\0\0\330M!\0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\4-\1\0\0\0\0\0\4-\1\0\0\0\0\0\4-\1\0\0\0\0\0D\5\0\0\0\0\0\0D\5\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\260M\1\0\0\0\0\0\260M!\0\0\0\0\0\260M!\0\0\0\0\0P\2\0\0\0\0\0\0P\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0008\32\274;-\23\t\264\351\312\30F\346\326\37 6\273E\274\330*\0\0\0\0\203\0\0\0\26\0\0\0\20\0\0\0\n\0\0\0\23\34\3\30\4$\0\1\1\201\0T\4\6\210\20\200\204\0\10\0\10\5\200\2\0@\20D\20\0\266\2\200\320 \301\0\220\2024\1\0\4\10(@\2H\1\v \320\1\2(\0235\4`l\322\0!\3p`@\322\200\10`\0@\1\0\200\1\0\0\2$\0\10\21\2\10H\300\1$\t\21( \10C\v\246\202H\t\10\10\3D\f\n\34\22O\306\1\207\va\204\226\315\4\302\305\f\242\333\16\314\26\0\0\0\27\0\0\0\32\0\0\0\0\0\0\0\35\0\0\0\0\0\0\0\37\0\0\0 \0\0\0"\0\0\0%\0\0\0'\0\0\0\0\0\0\0(\0\0\0*\0\0\0+\0\0\0.\0\0\0000\0\0\0003\0\0\0004\0\0\0007\0\0\0\0\0\0\0008\0\0\0009\0\0\0<\0\0\0=\0\0\0?\0\0\0@\0\0\0A\0\0\0B\0\0\0C\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0G\0\0\0\0\0\0\0\0\0\0\0H\0\0\0I\0\0\0K\0\0\0L\0\0\0M\0\0\0\0\0\0\0\0\0\0\0O\0\0\0Q\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=88720, ...}) = 0 mmap(NULL, 2184192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ad52000 mprotect(0x7fd34ad67000, 2093056, PROT_NONE) = 0 mmap(0x7fd34af66000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7fd34af66000 close(4) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4f0000 open("/usr/lib64/sssd/libfreebl3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libfreebl3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\v\0\0\0\0\0\0@\0\0\0\0\0\0\0\200%\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\274\24\0\0\0\0\0\0\274\24\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\250\35\0\0\0\0\0\0\250\35 \0\0\0\0\0\250\35 \0\0\0\0\0\360\2\0\0\0\0\0\0\30\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\310\35\0\0\0\0\0\0\310\35 \0\0\0\0\0\310\35 \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(\22\0\0\0\0\0\0(\22\0\0\0\0\0\0(\22\0\0\0\0\0\0t\0\0\0\0\0\0\0t\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\250\35\0\0\0\0\0\0\250\35 \0\0\0\0\0\250\35 \0\0\0\0\0X\2\0\0\0\0\0\0X\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\372\267\335\246\ 3631\211^A\235d\211\211\277\233\346\264\303\271\263\0\0\0\0\3\0\0\0\24\0\0\0\1\0\0\0\6\0\0\0\241\210\31\21@\2\313`\24\0\0\0\31\0\0\0\34\0\0\0\30\274\342\374\320\223@\334\260y\0\362\304\214\267\3467\247\300\312<0?\347J\3178\252?u\4X\322\263\222r\346m\204\214GJ)\252\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\206\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\262\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\231\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\251\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=11392, ...}) = 0 mmap(NULL, 2105536, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34ab4f000 mprotect(0x7fd34ab51000, 2093056, PROT_NONE) = 0 mmap(0x7fd34ad50000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1000) = 0x7fd34ad50000 close(4) = 0 open("/usr/lib64/sssd/libattr.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libattr.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\23\0\0\0\0\0\0@\0\0\0\0\0\0\0\270F\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\344;\0\0\0\0\0\0\344;\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\300=\0\0\0\0\0\0\300= \0\0\0\0\0\300= \0\0\0\0\0\240\3\0\0\0\0\0\0\260\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\3144\0\0\0\0\0\0\3144\0\0\0\0\0\0\3144\0\0\0\0\0\0\374\0\0\0\0\0\0\0\374\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\300=\0\0\0\0\0\0\300= \0\0\0\0\0\300= \0\0\0\0\0@\2\0\0\0\0\0\0@\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\34;-\271\26\356\274\245Z\ 264R\16\7C7\306\307,\252&\0\0\0\0\21\0\0\0\33\0\0\0\4\0\0\0\10\0\0\0*\0\30\0(\340\205\20<\4\1bH X \4\250#\0\v\21\10\311\20\230\10\r\0\5\6\200\33\0\0\0\34\0\0\0!\0\0\0%\0\0\0)\0\0\0\0\0\0\0+\0\0\0-\0\0\0000\0\0\0002\0\0\0\0\0\0\0003\0\0\0\0\0\0\0006\0\0\0007\0\0\0009\0\0\0<\0\0\0\241\213\315\300\4\301X\25\352\323\357\16\276\250\343\370\2-^\203m42\350\352\32\346\300X\235\235\323\276B1\340\271\215\361\16\24\345N\251f\336\10`\330qX\34Q\3431\256\272\343\222|s\302x\356.cx\204\221U_\25J=G\363BE\325\354/cx\2040cx\204\221x\251\335\271\3732\0\362?\355s\240sU\2413S\247\273\313\333\343\370D\366H\0237|h%\332\f\26\211\304\350\33\233\333\217[\25\255\0179N\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\n\0\20\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\242\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\203\0\0\0\22\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19896, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34a94a000 mprotect(0x7fd34a94e000, 2093056, PROT_NONE) = 0 mmap(0x7fd34ab4d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7fd34ab4d000 close(4) = 0 open("/usr/lib64/sssd/libpcre.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libpcre.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\25\0\0\0\0\0\0@\0\0\0\0\0\0\0\320\34\6\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0004\377\5\0\0\0\0\0004\377\5\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\210\f\6\0\0\0\0\0\210\f&\0\0\0\0\0\210\f&\0\0\0\0\0\224\4\0\0\0\0\0\0\200\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\270\r\6\0\0\0\0\0\270\r&\0\0\0\0\0\270\r&\0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\340\321\5\0\0\0\0\0\340\321\5\0\0\0\0\0\340\321\5\0\0\0\0\0\344\4\0\0\0\0\0\0\344\4\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\210\f\6\0\0\0\0\0\210\f&\0\0\0\0\0\210\f&\0\0\0\0\0x\3\0\0\0\0\0\0x\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\3 65\261D\371\365\331\276E\34\200!\0334\333,\343H\3409\266\0\0\0\0\21\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0@\204\t\0\202!\20\240\250@\0\23\304\320\201\30\2"\30@\30"D\v\200\30\10\1">\226\2\34\0\0\0\35\0\0\0\37\0\0\0"\0\0\0$\0\0\0'\0\0\0+\0\0\0000\0\0\0001\0\0\0002\0\0\0005\0\0\0\0\0\0\0006\0\0\0\0\0\0\0009\0\0\0<\0\0\0=\0\0\0\271\201\272\305\352\323\357\16\21\177\27\257\354\7\262\236\370\262E2\271\215\361\16f\267\251\177\331qX\34\312\207\345 bG\32s\273\343\222|\210\236\254\16\362\371\272np\\374\177o\316\312\205f\254\206'\224\273q3n\331\3621DX[\373{\374\266NCE\325\3545\317\205\323\350\341\354\224v\257\326\223'\206t\200\223\351\373\177\350\f.p\244vTi\365\354\2212<\312\356(\3447\234!\353\364\320\30)\241H\16\2542Vs-S>\36\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\t\0\370\23\0\0\0\0\0\0\0\0\0\0\0\0\0\0\23\3\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\306\0\0\0\22\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=402384, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4ef000 mmap(NULL, 2494984, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34a6e8000 mprotect(0x7fd34a748000, 2097152, PROT_NONE) = 0 mmap(0x7fd34a948000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x60000) = 0x7fd34a948000 close(4) = 0 open("/usr/lib64/elfutils/tls/x86_64/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/tls/x86_64", 0x7ffdb254e170) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/tls/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/tls", 0x7ffdb254e170) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/x86_64/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/x86_64", 0x7ffdb254e170) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/lib64/libelf.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0000\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\177\1\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264j\1\0\0\0\0\0\264j\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\314\5\0\0\0\0\0\0\330\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\270m\1\0\0\0\0\0\270m!\0\0\0\0\0\270m!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h@\1\0\0\0\0\0h@\1\0\0\0\0\0h@\1\0\0\0\0\0\244\6\0\0\0\0\0\0\244\6\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\30\4\ 0\0\0\0\0\0\30\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\363\23\224I\342\2027_C~\203w\25}\237zi\324<\366\0\0\0\0a\0\0\0001\0\0\0\20\0\0\0\n\0\0\0C\10\2\0\20\3\10\300\24\0\10\372\207\204\0\10\0\200\201\6\0\0\0\10\200\4\0\0000 \1\240`\20\264S\r\230\30\20\22\0`!\202\210D\n\200\240\300\316\300\201\22\3\10 E\1\310\300\2\2\2\v\21\200A\24\6\n\10\0\0\0\30\202\0 \0\202\200\200\261\1 \0(\1\1T\22H\3642B\20\22\241\10B\210A\0\200\0\200A\200\10\207\4\200\0A\200P\0\1A \0\215UH\0241\0\0\0002\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0003\0\0\0005\0\0\0006\0\0\0009\0\0\0\0\0\0\0<\0\0\0\0\0\0\0=\0\0\0\0\0\0\0\0\0\0\0?\0\0\0B\0\0\0D\0\0\0E\0\0\0\0\0\0\0F\0\0\0H\0\0\0J\0\0\0\0\0\0\0K\0\0\0M\0\0\0\0\0\0\0O\0\0\0P\0\0\0R\0\0\0T\0\0\0U\0\0\0W\0\0\0X\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=100032, ...}) = 0 mmap(NULL, 2191808, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34a4d0000 mprotect(0x7fd34a4e7000, 2093056, PROT_NONE) = 0 mmap(0x7fd34a6e6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x16000) = 0x7fd34a6e6000 close(4) = 0 open("/usr/lib64/elfutils/libbz2.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libbz2.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\27\0\0\0\0\0\0@\0\0\0\0\0\0\0`\3\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|\353\0\0\0\0\0\0|\353\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0 \355\0\0\0\0\0\0 \355 \0\0\0\0\0 \355 \0\0\0\0\0@\20\0\0\0\0\0\0H\20\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\310\355\0\0\0\0\0\0\310\355 \0\0\0\0\0\310\355 \0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\210\340\0\0\0\0\0\0\210\340\0\0\0\0\0\0\210\340\0\0\0\0\0\0d\1\0\0\0\0\0\0d\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0 \355\0\0\0\0\0\0 \355 \0\0\0\0\0 \355 \0\0\0\0\0\340\2\0\0\0\0\0\0\340\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\342\317WR=\30=\3 0n\276`\371\21\3\240\221^G\226\344\0\0\0\0%\0\0\0\32\0\0\0\4\0\0\0\10\0\0\0\1@\200\0@\0\2\22(\206\213\5x\6\200\4\211\276\0102\230\244\200\v\325\0\r\1T\34"`\0\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\35\0\0\0\37\0\0\0\0\0\0\0\0\0\0\0 \0\0\0!\0\0\0\0\0\0\0\0\0\0\0$\0\0\0&\0\0\0(\0\0\0)\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0*\0\0\0+\0\0\0\0\0\0\0.\0\0\0\0\0\0\0001\0\0\0002\0\0\0004\0\0\0005\0\0\0006\0\0\0007\0\0\0008\0\0\0:\0\0\0\0\0\0\0\0\0\0\0<\0\0\0>\0\0\0A\0\0\0\377&\310\200J\2676}\271\355\315\302z\344\306]\17\200%\327\353\323\357\16\3215\227\301B\323\rid\246\2517\201\215\375\251\212\tpYYZ\210\301\2027#\31\215G\215\323\301&W\3279\346\354\262\217\223\26a\300lm\312\246$\f\370=q\372KP\343F\16zi\317\222\213\234X\327\331qX\34\230\335\212\300\273\343\222|\345\222t\301\307\342\351\224\307\202\245r\305\322`\301BE\325\354\2537\337\302N\317\273\224I\3463\262\26f\346\344", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=68192, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4ee000 mmap(NULL, 2162024, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7fd34a2c0000 mprotect(0x7fd34a2cf000, 2093056, PROT_NONE) = 0 mmap(0x7fd34a4ce000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xe000) = 0x7fd34a4ce000 close(4) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4ed000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4ec000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4eb000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4ea000 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f4e8000 arch_prctl(ARCH_SET_FS, 0x7fd34f4e8880) = 0 mprotect(0x7fd34cdd9000, 16384, PROT_READ) = 0 mprotect(0x7fd34a4ce000, 4096, PROT_READ) = 0 mprotect(0x7fd34ca14000, 4096, PROT_READ) = 0 mprotect(0x7fd34a6e6000, 4096, PROT_READ) = 0 mprotect(0x7fd34d1fe000, 4096, PROT_READ) = 0 mprotect(0x7fd34a948000, 4096, PROT_READ) = 0 mprotect(0x7fd34ab4d000, 4096, PROT_READ) = 0 mprotect(0x7fd34cfe6000, 4096, PROT_READ) = 0 mprotect(0x7fd34ad50000, 4096, PROT_READ) = 0 mprotect(0x7fd34af66000, 4096, PROT_READ) = 0 mprotect(0x7fd34bc91000, 4096, PROT_READ) = 0 mprotect(0x7fd34b1b6000, 8192, PROT_READ) = 0 mprotect(0x7fd34b3ce000, 4096, PROT_READ) = 0 mprotect(0x7fd34b5d5000, 4096, PROT_READ) = 0 mprotect(0x7fd34b853000, 4096, PROT_READ) = 0 mprotect(0x7fd34ba6b000, 4096, PROT_READ) = 0 mprotect(0x7fd34beb6000, 4096, PROT_READ) = 0 mprotect(0x7fd34c0c0000, 4096, PROT_READ) = 0 mprotect(0x7fd34c3c2000, 4096, PROT_READ) = 0 mprotect(0x7fd34c5c7000, 4096, PROT_READ) = 0 mprotect(0x7fd34c7d0000, 4096, PROT_READ) = 0 mprotect(0x7fd34d43d000, 4096, PROT_READ) = 0 mprotect(0x7fd34d645000, 4096, PROT_READ) = 0 mprotect(0x7fd34d849000, 4096, PROT_READ) = 0 mprotect(0x7fd34da73000, 28672, PROT_READ) = 0 mprotect(0x7fd34dda1000, 20480, PROT_READ) = 0 mprotect(0x7fd34dfce000, 12288, PROT_READ) = 0 mprotect(0x7fd34e225000, 16384, PROT_READ) = 0 mprotect(0x7fd34e45a000, 4096, PROT_READ) = 0 mprotect(0x7fd34e669000, 4096, PROT_READ) = 0 mprotect(0x7fd34e86d000, 4096, PROT_READ) = 0 mprotect(0x7fd34eca5000, 114688, PROT_READ) = 0 mprotect(0x7fd34f2e6000, 4096, PROT_READ) = 0 mprotect(0x7fd34eed7000, 4096, PROT_READ) = 0 mprotect(0x7fd34f0e1000, 4096, PROT_READ) = 0 mprotect(0x5647a6624000, 4096, PROT_READ) = 0 mprotect(0x7fd34f509000, 4096, PROT_READ) = 0 munmap(0x7fd34f4fb000, 49694) = 0 set_tid_address(0x7fd34f4e8b50) = 5539 set_robust_list(0x7fd34f4e8b60, 24) = 0 rt_sigaction(SIGRTMIN, {0x7fd34cfee860, [], SA_RESTORER|SA_SIGINFO, 0x7fd34cff7630}, NULL, 8) = 0 rt_sigaction(SIGRT_1, {0x7fd34cfee8f0, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x7fd34cff7630}, NULL, 8) = 0 rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0 getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0 brk(NULL) = 0x5647a7f10000 brk(0x5647a7f31000) = 0x5647a7f31000 access("/etc/system-fips", F_OK) = -1 ENOENT (No such file or directory) statfs("/sys/fs/selinux", 0x7ffdb25503d0) = -1 ENOENT (No such file or directory) statfs("/selinux", 0x7ffdb25503d0) = -1 ENOENT (No such file or directory) open("/proc/filesystems", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f507000 read(4, "nodev\tsysfs\nnodev\trootfs\nnodev\tramfs\nnodev\tbdev\nnodev\tproc\nnodev\tcpuset\nnodev\tcgroup\nnodev\tcgroup2\nnodev\ttmpfs\nnodev\tdevtmpfs\nnodev\tconfigfs\nnodev\tdebugfs\nnodev\ttracefs\nnodev\tsecurityfs\nnodev\tsockfs\nnodev\tdax\nnodev\tbpf\nnodev\tpipefs\nnodev\thugetlbfs\nnodev\tdevpts\nnodev\tautofs\nnodev\tpstore\nnodev\tmqueue\n\txfs\nnodev\tbinfmt_misc\nnodev\trpc_pipefs\nnodev\tocfs2_dlmfs\nnodev\tnfs\nnodev\tnfs4\n\tocfs2\n", 1024) = 386 stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 read(4, "", 1024) = 0 close(4) = 0 munmap(0x7fd34f507000, 4096) = 0 access("/etc/selinux/config", F_OK) = 0 open("/etc/pki/tls/legacy-settings", O_RDONLY) = -1 ENOENT (No such file or directory) access("/etc/system-fips", F_OK) = -1 ENOENT (No such file or directory) umask(0177) = 0177 fcntl(2, F_GETFL) = 0x402 (flags O_RDWR|O_APPEND) open("/etc/localtime", O_RDONLY|O_CLOEXEC) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 fstat(4, {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f507000 read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0\6\0\0\0\0\0\0\0x\0\0\0\6\0\0\0\t\312\0025\340\314\347K\20\315\251\27\220\316\242C\20\317\2224\20\320\202%\20\320\372\1p\321\241\214\20\322N@\220\30E_p\30\343\257\220\31\323\240\220\32\303\221\220\33\274\275\20\34\254\256\20\35\234\237\20\36\214\220\20\37|\201\20 lr\20!\c\20"LT\20#<E\20$,6\20%\34'\20&\f\30\20'\5C\220'\3654\220(\345%\220)\325\26\220*\305\7\220+\264\370\220,\244\351\220-\224\332\220.\204\313\220/t\274\2200d\255\2201]\331\0202r\264\0203=\273\0204R\226\0205\35\235\02062x\0206\375\177\0208\33\224\2208\335a\0209\373v\220:\275C\20;\333X\220<\246_\220=\273:\220>\206A\220?\233\34\220@f#\220A\2049\20BF\5\220Cd\33\20D%\347\220EC\375\20F\5\311\220G#\337\20G\356\346\20I\3\301\20I\316\310\20J\343\243\20K\256\252\20L\314\277\220M\216\214\20N\254\241\220Onn\20P\214\203\220QW\212\220Rle\220S7l\220TLG\220U\27N\220V,)\220V\3670\220X\25F\20X\327\22\220Y\365(\20Z\266\364\220[\325\n\20\\240\21\20]\264\354\20^\177\363\20_\224\316 \20`_\325\20a}\352\220b?\267\20c]\314\220d\37\231\20e=\256\220f\10\265\220g\35\220\220g\350\227\220h\375r\220i\310y\220j\335T\220k\250[\220l\306q\20m\210=\220n\246S\20oh\37\220p\2065\20qQ<\20rf\27\20s1\36\20tE\371\20u\21\0\20v/\25\220v\360\342\20x\16\367\220x\320\304\20y\356\331\220z\260\246\20{\316\273\220|\231\302\220}\256\235\220~y\244\220\177\216\177\220\3\1\2\1\2\1\0\2\1\0\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\0\0\16\20\0\0\0\0\16\20\0\0\0\0\34 \1\4\0\0\34 \1\4\0\0\34 \1\4\0\0\16\20\0\0CET\0CEST\0\0\1\1\0\1\1\0\0\0\0\1\1TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0\0\0\0y\0\0\0\7\0\0\0\r\377\377\377\377^<\360H\377\377\377\377\312\0025\340\377\377\377\377\314\347K\20\377\377\377\377\315\251\27\220\377\377\377\377\316\242C\20\377\377\377\377\317\2224\20\377\377\377\377\320\202%\20\377\37 7\377\377\320\372\1p\377\377\377\377\321\241\214\20\377\377\377\377\322N@\220\0\0\0\0\30E_p\0\0\0\0\30\343\257\220\0\0\0\0\31\323\240\220\0\0\0\0\32\303\221\220\0\0\0\0\33\274\275\20\0\0\0\0\34\254\256\20\0\0\0\0\35\234\237\20\0\0\0\0\36\214\220\20\0\0\0\0\37|\201\20\0\0\0\0 lr\20\0\0\0\0!\c\20\0\0\0\0"LT\20\0\0\0\0#<E\20\0\0\0\0$,6\20\0\0\0\0%\34'\20\0\0\0\0&\f\30\20\0\0\0\0'\5C\220\0\0\0\0'\3654\220\0\0\0\0(\345%\220\0\0\0\0)\325\26\220\0\0\0\0*\305\7\220\0\0\0\0+\264\370\220\0\0\0\0,\244\351\220\0\0\0\0-\224\332\220\0\0\0\0.\204\313"..., 4096) = 1931 lseek(4, -1230, SEEK_CUR) = 701 read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0\0\0\0y\0\0\0\7\0\0\0\r\377\377\377\377^<\360H\377\377\377\377\312\0025\340\377\377\377\377\314\347K\20\377\377\377\377\315\251\27\220\377\377\377\377\316\242C\20\377\377\377\377\317\2224\20\377\377\377\377\320\202%\20\377\377\377\377\320\372\1p\377\377\377\377\321\241\214\20\377\377\377\377\322N@\220\0\0\0\0\30E_p\0\0\0\0\30\343\257\220\0\0\0\0\31\323\240\220\0\0\0\0\32\303\221\220\0\0\0\0\33\274\275\20\0\0\0\0\34\254\256\20\0\0\0\0\35\234\237\20\0\0\0\0\36\214\220\20\0\0\0\0\37|\201\20\0\0\0\0 lr\20\0\0\0\0!\c\20\0\0\0\0"LT\20\0\0\0\0#<E\20\0\0\0\0$,6\20\0\0\0\0%\34'\20\0\0\0\0&\f\30\20\0\0\0\0'\5C\220\0\0\0\0'\3654\220\0\0\0\0(\345%\220\0\0\0\0)\325\26\220\0\0\0\0*\305\7\220\0\0\0\0+\264\370\220\0\0\0\0,\244\351\220\0\0\0\0-\224\332\220\0\0\0\0.\204\313\220\0\0\0\0/t\274\220\0\0\0\0000d\255\220\0\0\0\0001]\331\20\0\0\0\0002r\264\20\0\0\0\0003=\273\20\0\0\0\0004R\226\20\0\0\0\0005\35\235\20\0\0\0\00062x\20\0\0\0\ 0006\375\177\20\0\0\0\0008\33\224\220\0\0\0\0008\335a\20\0\0\0\0009\373v\220\0\0\0\0:\275C\20\0\0\0\0;\333X\220\0\0\0\0<\246_\220\0\0\0\0=\273:\220\0\0\0\0>\206A\220\0\0\0\0?\233\34\220\0\0\0\0@f#\220\0\0\0\0A\2049\20\0\0\0\0BF\5\220\0\0\0\0Cd\33\20\0\0\0\0D%\347\220\0\0\0\0EC\375\20\0\0\0\0F\5\311\220\0\0\0\0G#\337\20\0\0\0\0G\356\346\20\0\0\0\0I\3\301\20\0\0\0\0I\316\310\20\0\0\0\0J\343\243\20\0\0\0\0K\256\252\20\0\0\0\0L\314\277\220\0\0\0\0M\216\214\20\0\0\0\0N\254\241\220\0\0\0\0Onn\20\0\0\0\0P\214\203\220\0\0\0\0QW\212\220\0\0\0\0Rle\220\0\0\0\0S7l\220\0\0\0\0TLG\220\0\0\0\0U\27N\220\0\0\0\0V,)\220\0\0\0\0V\3670\220\0\0\0\0X\25F\20\0\0\0\0X\327\22\220\0\0\0\0Y\365(\20\0\0\0\0Z\266\364\220\0\0\0\0[\325\n\20\0\0\0\0\\240\21\20\0\0\0\0]\264\354\20\0\0\0\0^\177\363\20\0\0\0\0_\224\316\20\0\0\0\0`_\325\20\0\0\0\0a}\352\220\0\0\0\0b?\267\20\0\0\0\0c]\314\220\0\0\0\0d\37\231\20\0\0\0\0e=\256\220\0\0\0\0f\10\265\220\0\0\0\0g\35\220\220\0\0\0\0g\350\227\220\0\0\0\0h\375r\220\0\0\0\0i\3 10y\220\0\0\0\0j\335T\220\0\0\0\0k\250[\220\0\0\0\0l\306q\20\0\0\0\0m\210=\220\0\0\0\0n\246S\20\0\0\0\0oh\37\220\0\0\0\0p\2065\20\0\0\0\0qQ<\20\0\0\0\0rf\27\20\0\0\0\0s1\36\20\0\0\0\0tE\371\20\0\0\0\0u\21\0\20\0\0\0\0v/\25\220\0\0\0\0v\360\342\20\0\0\0\0x\16\367\220\0\0\0\0x\320\304\20\0\0\0\0y\356\331\220\0\0\0\0z\260\246\20\0\0\0\0{\316\273\220\0\0\0\0|\231\302\220\0\0\0\0}\256\235\220\0\0\0\0~y\244\220\0\0\0\0\177\216\177\220\1\4\2\3\2\3\2\1\3\2\1\5"..., 4096) = 1230 close(4) = 0 munmap(0x7fd34f507000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 fstat(2, {st_mode=S_IFSOCK|0777, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fd34f507000 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x0400): p11_child started.\n", 89) = 89 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x2000): Running in [verifiy] mode.\n", 97) = 97 getegid() = 0 geteuid() = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x2000): Running with effective IDs: [0][0].\n", 106) = 106 getgid() = 0 getuid() = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x2000): Running with real IDs [0][0].\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [parse_cert_verify_opts] (0x4000): Found 'no_ocsp' option, disabling OCSP.\n", 128) = 128 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [parse_cert_verify_opts] (0x0020): Found 'no_verification' option, disabling verification completely. This should not be used in production.\n", 194) = 194 write(2, "Cannot run verification with option 'no_verification'.\n", 55) = 55 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
On Tue, Mar 17, 2020 at 11:17:34AM -0000, Hristina Marosevic wrote:
On Tue, Mar 17, 2020 at 09:41:16AM -0000, Hristina Marosevic wrote: ....
Hi,
so p11_child is really called but as you said earlier there are no logs.
This might e.g. be a permission issue, please check the permissions on /var/log/sssd if you see anything odd. For me it looks like:
drwxr-x---. 2 root root system_u:object_r:sssd_var_log_t:s0 4096 Mar 17 09:09 . drwxr-xr-x. 12 root root system_u:object_r:var_log_t:s0 4096 Mar 15 03:27 .. -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 221452 Mar 17 09:19 krb5_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 1069023 Mar 17 11:16 ldap_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 p11_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 14816 Mar 17 09:19 selinux_child.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 623 Mar 16 10:31 sssd.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_nss.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_pac.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 490679 Mar 17 11:18 sssd_pam.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 6723166 Mar 17 11:18 sssd_ipa.devel.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_ssh.log -rw-------. 1 root root system_u:object_r:sssd_var_log_t:s0 0 Mar 16 10:31 sssd_sudo.log
The next step would be to check what failed with strace. For this call
mkdir /tmp/strace_data strace -ff -s 1024 -o /tmp/strace_data/strace_ -p $(pidof /usr/libexec/sssd/sssd_ssh)
in one terminal can call 'sss_ssh_authorizedkeys IIN32000000001' in a different terminal. After calling sss_ssh_authorizedkeys you can stop the strace command with CTRL-C. In /tmp/strace_data there should be at least 2 files, one of the main sssd_ssh process and the other for p11_child, please send both (if there are more than 2 please send all).
bye, Sumit
There are two files:
after executing strace -ff -s 1024 -o /tmp/strace_data/strace_ -p $(pidof /usr/libexec/sssd/sssd_ssh) strace_.24180 was generated.
....
write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [parse_cert_verify_opts] (0x4000): Found 'no_ocsp' option, disabling OCSP.\n", 128) = 128 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [parse_cert_verify_opts] (0x0020): Found 'no_verification' option, disabling verification completely. This should not be used in production.\n", 194) = 194 write(2, "Cannot run verification with option 'no_verification'.\n", 55) = 55
Hi,
I'm sorry, I haven't read one of your earlier emails carefully enough, please do not use "certificate_verification = no_ocsp, no_verification" but only
certificate_verification = no_verification
'no_ocsp' implies verification but without OCSP so using both options is an inconsistency.
bye, Sumit
stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 12:09:26 2020) [[sssd[p11_child[5539]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++ _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Tue, Mar 17, 2020 at 11:17:34AM -0000, Hristina Marosevic wrote: ....
Hi,
I'm sorry, I haven't read one of your earlier emails carefully enough, please do not use "certificate_verification = no_ocsp, no_verification" but only
certificate_verification = no_verification
'no_ocsp' implies verification but without OCSP so using both options is an inconsistency.
bye, Sumit
Hello,
I changed the sssd configuration such that now there is only "certificate_verification = no_verification" in [sssd] field. I got the same error in the sssd_ssh.log i.e. certificate is not valid, and the content of the files in /tmp/strace_data is: #cat /tmp/strace_data/strace_.3070 epoll_wait(0, [], 1, 8457) = 0 epoll_wait(0, 0x7ffe40874780, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=-1216446368, ptr=0x7fc5b77e8060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, [], 1, 9222) = 0 epoll_wait(0, 0x7ffe40874780, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=-1216446368, ptr=0x7fc5b77e8060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, [{EPOLLIN, {u32=3728739296, u64=94518779055072}}], 1, 9230) = 1 accept(17, {sa_family=AF_LOCAL, NULL}, [2]) = 18 getsockopt(18, SOL_SOCKET, SO_PEERCRED, {pid=6094, uid=0, gid=0}, [12]) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [get_client_cred] (0x4000): Client creds: euid[0] egid[0] pid[6094].\n", 108) = 108 getsockopt(18, SOL_SOCKET, SO_PEERSEC, 0x55f6de3feec0, 0x7ffe408745b4) = -1 ENOPROTOOPT (Protocol not available) stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [get_client_cred] (0x0080): The following failure is expected to happen in case SELinux is disabled:\nSELINUX_getpeercon failed [92][Protocol not available].\nPlease, consider enabling SELinux in your system.\n", 246) = 246 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=3728721952, u64=94518779037728}}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [setup_client_idle_timer] (0x4000): Idle timer re-set for client [0x55f6de400390][18]\n", 125) = 125 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [accept_fd_handler] (0x0400): Client connected!\n", 87) = 87 epoll_wait(0, [{EPOLLIN, {u32=3728721952, u64=94518779037728}}], 1, 5049) = 1 recvfrom(18, "\24\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0", 1536, 0, NULL, NULL) = 16 epoll_wait(0, [{EPOLLIN, {u32=3728721952, u64=94518779037728}}], 1, 5049) = 1 recvfrom(18, "\0\0\0\0", 4, 0, NULL, NULL) = 4 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe408746a0) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Received client version [0].\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [sss_cmd_get_version] (0x0200): Offered version [0].\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=3728721952, u64=94518779037728}}) = 0 epoll_wait(0, [{EPOLLOUT, {u32=3728721952, u64=94518779037728}}], 1, 5049) = 1 sendto(18, "\24\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 20, 0, NULL, 0) = 20 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe408746a0) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=3728721952, u64=94518779037728}}) = 0 epoll_wait(0, [{EPOLLIN, {u32=3728721952, u64=94518779037728}}], 1, 5048) = 1 recvfrom(18, "+\0\0\0\341\0\0\0\0\0\0\0\0\0\0\0", 1536, 0, NULL, NULL) = 16 epoll_wait(0, [{EPOLLIN, {u32=3728721952, u64=94518779037728}}], 1, 5048) = 1 recvfrom(18, "\2\0\0\0\17\0\0\0IIN32000000001\0\0\0\0\0", 27, 0, NULL, NULL) = 27 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe408746a0) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ssh_protocol_parse_request] (0x0400): Requested domain [<ALL>]\n", 103) = 103 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ssh_cmd_get_user_pubkeys] (0x0400): Requesting SSH user public keys for [IIN32000000001] from [<ALL>]\n", 142) = 142 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_set_plugin] (0x2000): CR #1: Setting "User by name" plugin\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_send] (0x0400): CR #1: New request 'User by name'\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_process_input] (0x0400): CR #1: Parsing input name [IIN32000000001]\n", 118) = 118 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [sss_parse_name_for_domains] (0x0200): name 'IIN32000000001' matched without domain, user is IIN32000000001\n", 147) = 147 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_set_name] (0x0400): CR #1: Setting name [IIN32000000001]\n", 107) = 107 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_select_domains] (0x0400): CR #1: Performing a multi-domain search\n", 116) = 116 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_domains] (0x0400): CR #1: Search will check the cache and check the data provider\n", 139) = 139 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_validate_domain_type] (0x2000): Request type POSIX-only for domain LDAP type POSIX is valid\n", 142) = 142 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_set_domain] (0x0400): CR #1: Using domain [LDAP]\n", 99) = 99 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_prepare_domain_data] (0x0400): CR #1: Preparing input data for domain [LDAP] rules\n", 133) = 133 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #1: Looking up IIN32000000001@ldap\n", 111) = 111 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #1: Checking negative cache for [IIN32000000001@ldap]\n", 132) = 132 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [sss_ncache_check_str] (0x2000): Checking negative cache for [NCE/USER/LDAP/IIN32000000001@ldap]\n", 136) = 136 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_ncache] (0x0400): CR #1: [IIN32000000001@ldap] is not present in negative cache\n", 137) = 137 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_cache] (0x0400): CR #1: Looking up [IIN32000000001@ldap] in cache\n", 123) = 123 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(14, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(14, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55f6de41fe00\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55f6de41fed0\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55f6de41fe00 "ltdb_callback"\n\n", 107) = 107 fcntl(14, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de41fed0 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de41fe00 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(16, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(16, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55f6de41fe90\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55f6de40b2f0\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55f6de41fe90 "ltdb_callback"\n\n", 107) = 107 fcntl(16, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de40b2f0 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de41fe90 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_send] (0x0400): CR #1: Returning [IIN32000000001@ldap] from cache\n", 123) = 123 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_search_ncache_filter] (0x0400): CR #1: This request type does not support filtering result by negative cache\n", 159) = 159 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_create_and_add_result] (0x0400): CR #1: Found 1 entries in domain LDAP\n", 121) = 121 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cache_req_done] (0x0400): CR #1: Finished: Success\n", 91) = 91 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55f6de4233c0\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55f6de423490\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de423490 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55f6de4233c0\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55f6de423490\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de423490 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 epoll_create(64) = 19 fcntl(19, F_GETFD) = 0 fcntl(19, F_SETFD, FD_CLOEXEC) = 0 fcntl(5, F_SETLK, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=168, l_len=40000}) = 0 fcntl(5, F_SETLKW, {l_type=F_RDLCK, l_whence=SEEK_SET, l_start=40168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x55f6de4233c0\n\n", 106) = 106 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Added timed event "ltdb_timeout": 0x55f6de423490\n\n", 105) = 105 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Running timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 107) = 107 fcntl(5, F_SETLKW, {l_type=F_UNLCK, l_whence=SEEK_SET, l_start=168, l_len=0}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de423490 "ltdb_timeout"\n\n", 109) = 109 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ldb] (0x4000): Destroying timer event 0x55f6de4233c0 "ltdb_callback"\n\n", 110) = 110 close(19) = 0 pipe([19, 20]) = 0 pipe([21, 22]) = 0 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7fc5b79e2b50) = 6095 close(20) = 0 fcntl(19, F_GETFL) = 0 (flags O_RDONLY) fcntl(19, F_SETFL, O_RDONLY|O_NONBLOCK) = 0 close(21) = 0 fcntl(22, F_GETFL) = 0x1 (flags O_WRONLY) fcntl(22, F_SETFL, O_WRONLY|O_NONBLOCK) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Setting up signal handler up for pid [6095]\n", 115) = 115 rt_sigaction(SIGCHLD, {0x7fc5b4c60dd0, [], SA_RESTORER|SA_SIGINFO, 0x7fc5b31d0630}, {SIG_DFL, [], SA_RESTORER, 0x7fc5b31d0630}, 8) = 0 rt_sigprocmask(SIG_BLOCK, [CHLD], [INT FPE USR1 USR2 PIPE], 8) = 0 rt_sigprocmask(SIG_SETMASK, [INT FPE USR1 USR2 PIPE], NULL, 8) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [child_handler_setup] (0x2000): Signal handler set up for pid [6095]\n", 108) = 108 epoll_wait(0, 0x7ffe40874780, 1, 5033) = -1 EINTR (Interrupted system call) --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=6095, si_uid=0, si_status=1, si_utime=0, si_stime=0} --- write(3, "\1\0\0\0\0\0\0\0", 8) = 8 rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [6095].\n", 95) = 95 wait4(6095, [{WIFEXITED(s) && WEXITSTATUS(s) == 1}], WNOHANG, NULL) = 6095 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [child_sig_handler] (0x0020): child [6095] failed with status [1].\n", 106) = 106 close(19) = 0 close(22) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0040): /usr/libexec/sssd/p11_child failed with status [256]\n", 125) = 125 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x0080): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DV nBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735"..., 2221) = 2221 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=3728721952, u64=94518779037728}}) = 0 rt_sigaction(SIGCHLD, {SIG_DFL, [], SA_RESTORER, 0x7fc5b31d0630}, NULL, 8) = 0 epoll_wait(0, [{EPOLLIN, {u32=3728653488, u64=94518778969264}}], 1, 4994) = 1 read(3, "\1\0\0\0\0\0\0\0", 8) = 8 epoll_wait(0, [{EPOLLOUT, {u32=3728721952, u64=94518779037728}}], 1, 4994) = 1 sendto(18, "\30\0\0\0\341\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 24, 0, NULL, 0) = 24 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe408746a0) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=3728721952, u64=94518779037728}}) = 0 epoll_wait(0, [{EPOLLIN|EPOLLHUP, {u32=3728721952, u64=94518779037728}}], 1, 4992) = 1 recvfrom(18, "", 1536, 0, NULL, NULL) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected!\n", 84) = 84 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe40874640) = 0 close(18) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Tue Mar 17 14:17:03 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x55f6de400390][18]\n", 106) = 106 epoll_wait(0, [], 1, 4992) = 0 epoll_wait(0, 0x7ffe40874780, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=-1216446368, ptr=0x7fc5b77e8060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, <detached ...>
# cat /tmp/strace_data/strace_.6095 set_robust_list(0x7fc5b79e2b60, 24) = 0 close(22) = 0 dup2(21, 0) = 0 close(19) = 0 dup2(20, 1) = 1 execve("/usr/libexec/sssd/p11_child", ["/usr/libexec/sssd/p11_child", "--debug-microseconds=0", "--debug-timestamps=1", "--debug-fd=2", "--debug-level=0xf7f0", "--verification", "--verify", "no_verification", "--nssdb", "/home/oracle", "--certificate", "MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg22 9G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtp"...], [/* 6 vars */]) = 0 brk(NULL) = 0x55b0e4726000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41d4000 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/tls/x86_64/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/tls/x86_64", 0x7ffc176c4d20) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/tls/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/tls", 0x7ffc176c4d20) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/x86_64/libsss_debug.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/sssd/x86_64", 0x7ffc176c4d20) = -1 ENOENT (No such file or directory) open("/usr/lib64/sssd/libsss_debug.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\23\0\0\0\0\0\0@\0\0\0\0\0\0\0hF\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<6\0\0\0\0\0\0<6\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0x=\0\0\0\0\0\0x= \0\0\0\0\0x= \0\0\0\0\0\330\3\0\0\0\0\0\0\370\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\230=\0\0\0\0\0\0\230= \0\0\0\0\0\230= \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0L2\0\0\0\0\0\0L2\0\0\0\0\0\0L2\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0x=\0\0\0\0\0\0x= \0\0\0\0\0x= \0\0\0\0\0\210\2\0\0\0\0\0\0\210\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0w\221\0%\247\326~\210\326\26\341\277\252\275\350\222\217 \360yy\0\0\0\0\21\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0\10\1\220\20H\10\234\21(\2\0\31@p \200\n\240\0\3\f\0\20)\n"\270\3\2026\6\25\34\0\0\0\35\0\0\0\36\0\0\0 \0\0\0%\0\0\0)\0\0\0+\0\0\0-\0\0\0\0\0\0\0.\0\0\0/\0\0\0000\0\0\0002\0\0\0005\0\0\0007\0\0\0\0\0\0\0:\0\0\0Yu\32\\353\323\357\16\216\31\37)\271\215\361\16\200\342\256\2118s\203:f\356?\241\330qX\34\363\315\307\276\324\252\36\376\3101\330\332\354xl\20\273\343\222|2\367T\271\375\351Yol\t1\32+\224\254UCE\325\354\3\246\251\v\177\34\301\254\34\327\255G\327A\22\337\10#45\340Y\2078\275\3\303\20\264\230M\3305<\333|\354\347v\301l\33\337\352\325\303f\250\351:\\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0=\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\251\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19816, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad3daf000 mprotect(0x7f8ad3db3000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad3fb2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7f8ad3fb2000 close(4) = 0 open("/usr/lib64/sssd/libpopt.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=49694, ...}) = 0 mmap(NULL, 49694, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7f8ad41c7000 close(4) = 0 open("/lib64/libpopt.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\34\0\0\0\0\0\0@\0\0\0\0\0\0\0\310\231\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\354\203\0\0\0\0\0\0\354\203\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\240\215\0\0\0\0\0\0\240\215 \0\0\0\0\0\240\215 \0\0\0\0\0@\6\0\0\0\0\0\0\220\6\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300\215\0\0\0\0\0\0\300\215 \0\0\0\0\0\300\215 \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0008u\0\0\0\0\0\0008u\0\0\0\0\0\0008u\0\0\0\0\0\0\264\1\0\0\0\0\0\0\264\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\240\215\0\0\0\0\0\0\240\215 \0\0\0\0\0\240\215 \0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0G NU\0\310hy\351\335\317X\236M\ri\1\221TC,\205N\371\233\0\0\0\0\21\0\0\0:\0\0\0\4\0\0\0\10\0\0\0\200@\4A\214@\341,\0! H%\4\221\4 \2A\2\225\4\r\200!(\0\311\314\0\f:\0\0\0;\0\0\0=\0\0\0?\0\0\0@\0\0\0D\0\0\0E\0\0\0H\0\0\0\0\0\0\0L\0\0\0\0\0\0\0O\0\0\0Q\0\0\0R\0\0\0T\0\0\0W\0\0\0\0\0\0\0y\225{\313\352\323\357\16\273\315\340\37\346f\377\t\271\215\361\16\307\353\t\2\356\323\252@~\343A\370\240\354G\224;\230\236\305g\315\206\364\202\362\311\350\324z,V]\210\36\316h<\250\354\252\250Fm\16\7\267~\315\373|\2154\347\300\263\342\373\230\345#w\356\241"\266ug\341\310\334\204\271\257\233\10\352\256\\257]rB\203j\255\375<<\322\214\v\273Q\0005\236\3308\3050;\324\23\37n\r1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\n\0\350\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0001\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\33\3\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=41224, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c6000 mmap(NULL, 2135088, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad3ba5000 mprotect(0x7f8ad3bae000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad3dad000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x8000) = 0x7f8ad3dad000 close(4) = 0 open("/usr/lib64/sssd/libsss_crypt.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240!\0\0\0\0\0\0@\0\0\0\0\0\0\0\0h\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\364Z\0\0\0\0\0\0\364Z\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\320\\0\0\0\0\0\0\320\ \0\0\0\0\0\320\ \0\0\0\0\0\360\5\0\0\0\0\0\0\370\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\360\\0\0\0\0\0\0\360\ \0\0\0\0\0\360\ \0\0\0\0\0\300\2\0\0\0\0\0\0\300\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0hU\0\0\0\0\0\0hU\0\0\0\0\0\0hU\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\320\\0\0\0\0\0\0\320\ \0\0\0\0\0\320\ \0\0\0\0\0000\3\0\0\0\0\0\0000\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\f\2232\251\372\17\244\31\ 354\214vv)\246\351S\366gV?\0\0\0\0\21\0\0\0I\0\0\0\4\0\0\0\10\0\0\0\4\0 \4,2\20\0=\4!\0@\250(\7 \0\0\34\0\0\v\0\4\210\1\24D\2\0I\0\0\0K\0\0\0L\0\0\0O\0\0\0S\0\0\0\0\0\0\0\0\0\0\0U\0\0\0V\0\0\0W\0\0\0X\0\0\0Y\0\0\0\\0\0\0\0\0\0\0^\0\0\0_\0\0\0`\0\0\0x\0\225\254Q\355\206]\353\323\357\16\356\312|\20\312W\326M\271\215\361\16@\263\352\212\342\244\264\v,"!\350\331qX\34(\355b\2\273\343\222|CE\325\354E\246k\301U\204\354\17uzG\364\204\271\223|4\2\317\257#\225\201Yx\372\273\251\243dj\253\33\345}\262C\n\336}o\253c\304\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\235\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\267\4\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0P\4\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0I\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=28416, ...}) = 0 mmap(NULL, 2122440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad399e000 mprotect(0x7f8ad39a4000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad3ba3000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x5000) = 0x7f8ad3ba3000 close(4) = 0 open("/usr/lib64/sssd/libcrypto.so.10", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcrypto.so.10", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\321\6\0\0\0\0\0@\0\0\0\0\0\0\0\370p&\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224_#\0\0\0\0\0\224_#\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\0l#\0\0\0\0\0\0lC\0\0\0\0\0\0lC\0\0\0\0\0\240v\2\0\0\0\0\0H\267\2\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0p\35%\0\0\0\0\0p\35E\0\0\0\0\0p\35E\0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0`r\37\0\0\0\0\0`r\37\0\0\0\0\0`r\37\0\0\0\0\0\274\235\0\0\0\0\0\0\274\235\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\0l#\0\0\0\0\0\0lC\0\0\0\0\0\0lC\0\0\0\0\0\0\264\1\0\0\0\0\0\0\264\1\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0L\361\223\237f\0\10\317\250i\3306FQ\363\32\254\322\3 01\304\0\0\0\0\3\20\0\0}\0\0\0\0\2\0\0\17\0\0\0\1\0\30\205D\4\201\200a\200\2\0%L\4\200\201\0\0\10\30\206\4\200\10\2!\300\220\0@\0\201\204\3\21\204\244`\0F\10\fH\0\3\200\24\201\0\212\4\t\3\311\204\10\2l\30\200B\5\261\10H\1\204\10\0 \0\254\24t\201\22\10T\4\0\22BE\t@\340\20\f\224\34\0\0Q\0\300 A\0H(\f\300C\10D\231\2\0\35\0\0\301\2 \212\21Ql\264\205\200\0D\10\350"\16\0\0\0\0\4@\0\0\0\6\220\16\0\0(\5\7\0f\0b\244\0\2\4\200\200@\0P2\10\0\0\0\0\340\0\0\1\1\t\34\202T#\10\n\10\0A\200\2 \4\202;\4@\27\25\2\37@\242`\33\24\24\201\2E\306\2\0\210\21\0\0'\200\2\302!\f\304\0\2\1 \340\10\10\0\240 \262\0\2240\201\204\21\0a\f\302\f\34\10\260\21\r\0@\4 "\4\4\0@\204\263\201\f\200\320\31\25p4\200\2\200\6Ta\0\224D!\3\244\200@A\20@i@\n\240\240\223\0\23$\354\2D&\270\10\20\0C\1 H$\0\0C\204\2B\254\21@\4 "@\22\16 \200A\5\221Q", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=2521144, ...}) = 0 mmap(NULL, 4596552, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad353b000 mprotect(0x7f8ad3771000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad3971000, 167936, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x236000) = 0x7f8ad3971000 mmap(0x7f8ad399a000, 13128, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad399a000 close(4) = 0 open("/usr/lib64/sssd/libdhash.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdhash.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\n\0\0\0\0\0\0@\0\0\0\0\0\0\0\3205\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L$\0\0\0\0\0\0L$\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310-\0\0\0\0\0\0\310- \0\0\0\0\0\310- \0\0\0\0\0\260\2\0\0\0\0\0\0\270\2\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\350-\0\0\0\0\0\0\350- \0\0\0\0\0\350- \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\314\36\0\0\0\0\0\0\314\36\0\0\0\0\0\0\314\36\0\0\0\0\0\0\324\0\0\0\0\0\0\0\324\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310-\0\0\0\0\0\0\310- \0\0\0\0\0\310- \0\0\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\202+\273\247\313u\263* \350"\356\333\251\373::\6\363s\331\0\0\0\0\21\0\0\0\r\0\0\0\2\0\0\0\7\0\0\0\31\22"\200\200\3\10\20B\220%\205\34\0@\r\r\0\0\0\16\0\0\0\17\0\0\0\0\0\0\0\20\0\0\0\22\0\0\0\0\0\0\0\25\0\0\0\0\0\0\0\27\0\0\0\30\0\0\0\31\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\34\0\0\0\0\0\0\0w\251\371;\307\0WI\343\252\232\204<\340\314o\373\261:qbR!\373XhCg\323's\227\236Sm/\251\371,|\221a3Iym\357\232\205j\221WM}\240\303\2114\354\353\322\317\27\231\215\371GR\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0>\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\t\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\276\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0u\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=15632, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c5000 mmap(NULL, 2109568, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad3337000 mprotect(0x7f8ad333a000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad3539000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7f8ad3539000 close(4) = 0 open("/usr/lib64/sssd/libtalloc.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libtalloc.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@'\0\0\0\0\0\0@\0\0\0\0\0\0\0\210\351\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\34\322\0\0\0\0\0\0\34\322\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\230\335\0\0\0\0\0\0\230\335 \0\0\0\0\0\230\335 \0\0\0\0\0T\4\0\0\0\0\0\0\230\4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300\335\0\0\0\0\0\0\300\335 \0\0\0\0\0\300\335 \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\310\272\0\0\0\0\0\0\310\272\0\0\0\0\0\0\310\272\0\0\0\0\0\0\34\3\0\0\0\0\0\0\34\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\230\335\0\0\0\0\0\0\230\335 \0\0\0\0\0\230\335 \0\0\0\0\0h\2\0\0\0\0\0\0h\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0 GNU\0\374\200E\361~\373\364\334\360\313\331Dv\361q\311iq\253e\0\0\0\0C\0\0\0&\0\0\0\10\0\0\0\t\0\0\0 \20\0\1\0101\203\0\0\240\0\220\0\4p\10v\301\370\3\224\20\4\2A\5\374\17\2<\221\4\f\20\22\250\0\4\10\0\1\0\201"\370\20\0\20\10` \30\250C\212p\36\255&\6\v\361T\7&\0\0\0'\0\0\0\0\0\0\0(\0\0\0\0\0\0\0)\0\0\0\0\0\0\0*\0\0\0,\0\0\0000\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0<\0\0\0?\0\0\0B\0\0\0D\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0\0\0\0\0G\0\0\0H\0\0\0J\0\0\0K\0\0\0\0\0\0\0L\0\0\0M\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0N\0\0\0O\0\0\0Q\0\0\0R\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0\0\0T\0\0\0V\0\0\0W\0\0\0X\0\0\0\0\0\0\0Z\0\0\0\\0\0\0]\0\0\0^\0\0\0\0\0\0\0`\0\0\0a\0\0\0e\0\0\0g\0\0\0\0\0\0\0h\0\0\0i\0\0\0\0\0\0\0k\0\0\0m\0\0\0p\0\0\0s\0\0\0u\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=61704, ...}) = 0 mmap(NULL, 2155056, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad3128000 mprotect(0x7f8ad3136000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad3335000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xd000) = 0x7f8ad3335000 close(4) = 0 open("/usr/lib64/sssd/libsystemd.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libsystemd.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@O\0\0\0\0\0\0@\0\0\0\0\0\0\0(\24\3\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\361\351\2\0\0\0\0\0\361\351\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\250\366\2\0\0\0\0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0\320\t\0\0\0\0\0\0008\24\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0 \370\2\0\0\0\0\0 \370"\0\0\0\0\0 \370"\0\0\0\0\0\360\2\0\0\0\0\0\0\360\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\250\366\2\0\0\0\0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0\0\0\0\0\0\0\0\0008\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0P\345td\4\0\0\0$\212\2\0\0\0\0\0$\212\2\0\0\0\0\0$\212\2\0\0\0\0\0\204\f\0\0\0\0\0\0\204\f\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\250\366\2\0\0\0\ 0\0\250\366"\0\0\0\0\0\250\366"\0\0\0\0\0X\t\0\0\0\0\0\0X\t\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0001\264'\262\214\20\306\01612\340"\305\225l\364\36\233\343\217\0\0\0\0a\0\0\0\205\0\0\0\20\0\0\0\n\0\0\0\24\31@\5\0\210\0\246\202\204\230\2@\20@V\0A\5\0\26J\f\34@\200\1\0\0\0\10\2\4\0202\304@\210\24@\t\0\20\340 \10\0\0\200h\2\20"\4\221\20$\300\212\304"aPo1\25H@\22\23l\10J\20\0\200\0\0 \1C@\324\10@\0\0044\r\244\20\200\304N\22P\250\24\10\210\2D",\300\0`\204i\2j\20\4\0\4E\4\4 \20\300\4\201\224\0\200\30\10\0\0\0\0\0\0\0\0\205\0\0\0\207\0\0\0\211\0\0\0\212\0\0\0\0\0\0\0\213\0\0\0\215\0\0\0\216\0\0\0\0\0\0\0\0\0\0\0\217\0\0\0\0\0\0\0\220\0\0\0\221\0\0\0\223\0\0\0\225\0\0\0\227\0\0\0\231\0\0\0\232\0\0\0\234\0\0\0\236\0\0\0\237\0\0\0\241\0\0\0\242\0\0\0\243\0\0\0\0\0\0\0\245\0\0\0\0\0\0\0\0\0\0\0\247\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=203688, ...}) = 0 mmap(NULL, 2296544, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2ef7000 mprotect(0x7f8ad2f26000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad3126000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2f000) = 0x7f8ad3126000 close(4) = 0 open("/usr/lib64/sssd/libssl3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libssl3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\311\0\0\0\0\0\0@\0\0\0\0\0\0\0\270\240\5\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\324*\5\0\0\0\0\0\324*\5\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310:\5\0\0\0\0\0\310:%\0\0\0\0\0\310:%\0\0\0\0\0\240@\0\0\0\0\0\0@L\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0@m\5\0\0\0\0\0@m%\0\0\0\0\0@m%\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0004\200\4\0\0\0\0\0004\200\4\0\0\0\0\0004\200\4\0\0\0\0\0T\27\0\0\0\0\0\0T\27\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310:\5\0\0\0\0\0\310:%\0\0\0\0\0\310:%\0\0\0\0\00085\0\0\0\0\0\00085\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\332Z\330,\315\25q\256\22<L\347\273\251\2 15\363\310&\213;\0\0\0\0a\0\0\0\3\1\0\0\20\0\0\0\n\0\0\0'\1H\220\2R\25C\24\2\0@\10\1\0\261\224\22\2" \4J\6\0\5\262AD\0@\4A\4\0\0\211\4@A\211\20\6\0\1\200\200\1"0\0\0@1!\30\0\24\0\0!`\0\0\21)\202\204\2&$@\201\0\0\16\225\310 \10T\f\200\0\0\21\4\2\3\240\2\310\f\0\202\204\10\4-L\16A&L\205\216\240\4\0@\234\10\20\0@\241\2\0\1\0\nQ\340D\220\0\214I\3\1\0\0\0\0\0\0\0\0\0\0\5\1\0\0\6\1\0\0\t\1\0\0\n\1\0\0\16\1\0\0\20\1\0\0\21\1\0\0\23\1\0\0\25\1\0\0\32\1\0\0\34\1\0\0\35\1\0\0\37\1\0\0 \1\0\0!\1\0\0"\1\0\0#\1\0\0$\1\0\0\0\0\0\0%\1\0\0&\1\0\0\0\0\0\0(\1\0\0*\1\0\0+\1\0\0,\1\0\0\0\0\0\0-\1\0\0.\1\0\0000\1\0\0002\1\0\0003\1\0\0005\1\0\0007\1\0\0\0\0\0\0:\1\0\0<\1\0\0>\1\0\0?\1\0\0B\1\0\0C\1\0\0\0\0\0\0E\1\0\0F\1\0\0H\1\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=370680, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c4000 mmap(NULL, 2459400, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2c9e000 mprotect(0x7f8ad2cf1000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad2ef1000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x53000) = 0x7f8ad2ef1000 mmap(0x7f8ad2ef6000, 1800, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad2ef6000 close(4) = 0 open("/usr/lib64/sssd/libsmime3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libsmime3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\223\0\0\0\0\0\0@\0\0\0\0\0\0\0P\212\2\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0dA\2\0\0\0\0\0dA\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0hO\2\0\0\0\0\0hO"\0\0\0\0\0hO"\0\0\0\0\0`+\0\0\0\0\0\0\20,\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\340l\2\0\0\0\0\0\340l"\0\0\0\0\0\340l"\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24\346\1\0\0\0\0\0\24\346\1\0\0\0\0\0\24\346\1\0\0\0\0\0\314\v\0\0\0\0\0\0\314\v\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0hO\2\0\0\0\0\0hO"\0\0\0\0\0hO"\0\0\0\0\0\230 \0\0\0\0\0\0\230 \0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\226\270\313g\3045D\230\23s\366\300 \373\375\333 &\314\206\311\0\0\0\0\203\0\0\0\344\0\0\0\20\0\0\0\n\0\0\0\0\22(b\22\211\t\0 0\244\4\34\200@FD\210q !\6Fx\26\24\211I!\34\213`P\200BT`\0\214\201D\7'\6`\227\20!\0\20\240\tU\5\22\0$B\10\0B@\0\223\225\1\270\3\205\0-\00000\22\5\24\256\250(\260\220\264\261\234\0211\24\3B\0\5\200R\203r\230\v\240\200\2100\200B\314L \0i\23mf\6\20 \2\3@(\20\t\304\264\20%\6\330\3\344\0\0\0\345\0\0\0\347\0\0\0\350\0\0\0\351\0\0\0\0\0\0\0\352\0\0\0\0\0\0\0\354\0\0\0\355\0\0\0\361\0\0\0\0\0\0\0\365\0\0\0\366\0\0\0\370\0\0\0\0\0\0\0\371\0\0\0\372\0\0\0\373\0\0\0\0\0\0\0\374\0\0\0\376\0\0\0\0\1\0\0\1\1\0\0\2\1\0\0\4\1\0\0\7\1\0\0\10\1\0\0\0\0\0\0\t\1\0\0\n\1\0\0\v\1\0\0\0\0\0\0\f\1\0\0\0\0\0\0\r\1\0\0\16\1\0\0\0\0\0\0\21\1\0\0\24\1\0\0\25\1\0\0\26\1\0\0\0\0\0\0\30\1\0\0\31\1\0\0\0\0\0\0\34\1\0\0\36\1\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=168336, ...}) = 0 mmap(NULL, 2259832, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2a76000 mprotect(0x7f8ad2a9b000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad2c9a000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x24000) = 0x7f8ad2c9a000 close(4) = 0 open("/usr/lib64/sssd/libnss3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnss3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\242\1\0\0\0\0\0@\0\0\0\0\0\0\0 *\23\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224S\22\0\0\0\0\0\224S\22\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\310a\22\0\0\0\0\0\310a2\0\0\0\0\0\310a2\0\0\0\0\0\324l\0\0\0\0\0\0\240\204\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\253\22\0\0\0\0\0\240\2532\0\0\0\0\0\240\2532\0\0\0\0\0P\2\0\0\0\0\0\0P\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\354-\20\0\0\0\0\0\354-\20\0\0\0\0\0\354-\20\0\0\0\0\0$K\0\0\0\0\0\0$K\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\310a\22\0\0\0\0\0\310a2\0\0\0\0\0\310a2\0\0\0\0\0008N\0\0\0\0\0\0008N\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\313L\213"&t\310'\334\2 02y\371j\326N`\300\2627L\0\0\0\0\t\2\0\0000\1\0\0\200\0\0\0\r\0\0\0008\240\n\2`!\20\1\20\0\0\0\200\0\0!\7\0\22\214$\220K\4\5\2\20\0\20\t\4Y8\4\302\210\0"\0\2\0(\20\0\2 2\0\200H\0\f\4\10\270@\5\30\3\300\0!\2\2\200 K&\0B \0\0\1\5\17\0\2\1\10\220\216N\30\36\200R\30\22\0\6\2\0\30\240!\0\1\4\10\20\2\0@\306\3$\205\310\0\22\2000\240\21\20\r\10$9J\210\2\374kqP\240@\0\0HP\201\200\0\343\0\232\244\16\270m \352$P\f\2\0204\n\240\3\4\0\204\24\0\2\20\0\201\202\20\0\5\4\6\206\0@\214\2\0\20\300\0\1\0\10\n`D@\20\0\0\1\0 \240\215\5X\0001\2\0\4\300H"\4 \2\0\6F\20"\f\0\t\222D\10\261\22\0e\203\1\230 \10\210\0\202\10\0@\5\3\204\1\4\4\300\3000\0@\304\220 E\220\244\0\0\0\244\0\0\0\20\200\221!x\v\0244\204\v5$+!\201\0\0 \0&``\0 \302 a\0\0\200Q\2\200\0\0\10\0\1\0\2\0\4 \0\0\0\200@\0@\0\1\200\20P\n \0@\0\3\5\4\4", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=1257824, ...}) = 0 mmap(NULL, 3335784, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2747000 mprotect(0x7f8ad286d000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad2a6d000, 28672, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x126000) = 0x7f8ad2a6d000 mmap(0x7f8ad2a74000, 5736, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad2a74000 close(4) = 0 open("/usr/lib64/sssd/libnssutil3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnssutil3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\314\0\0\0\0\0\0@\0\0\0\0\0\0\0\360\1\3\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\214\204\2\0\0\0\0\0\214\204\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\10\216\2\0\0\0\0\0\10\216"\0\0\0\0\0\10\216"\0\0\0\0\0\300g\0\0\0\0\0\0\20n\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\354\2\0\0\0\0\0\240\354"\0\0\0\0\0\240\354"\0\0\0\0\0@\2\0\0\0\0\0\0@\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0|E\2\0\0\0\0\0|E\2\0\0\0\0\0|E\2\0\0\0\0\0\34\t\0\0\0\0\0\0\34\t\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\10\216\2\0\0\0\0\0\10\216"\0\0\0\0\0\10\216"\0\0\0\0\0\370a\0\0\0\0\0\0\370a\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\213\272 y1X\343\361\330d\nI\220J\216Rs\331\311\10\307\0\0\0\0\305\0\0\0Z\0\0\0 \0\0\0\v\0\0\0\0h\0\20\0D\2\0\230\4\310\f\0\0\n\342\1@\300\320\10F\4\200\t\300H\2\17\0062!`(\4H\0A\4\0\f\0\0\vC\24\3\1\0!l\2!\201\4"\200\210\0\250P\1\4p\1\200\10\10\0A\2\0*)(% \t\10\f\230\0\0\2+\10\20Q\200\10\203\20\0\0(\0\275\2@@p\200\300\200\26AH\v \0\16\0\230\2030\17\n\26l\22\204\0C\0@\16\1\22\0\0!\310\2!\200@\0\4\10\222\0@\0\0\200\0\0\4\200\223 x\10\22\202\10\n \0@\4\200\20\0\1\33?b\240\0\356\0\30T\250\f\240\4\226\21A\30\2\0\2000\20\2\f\206\20\32\6\5dB@\0\0\0\0\202\4\200&\0\234\26\4$h\310\0\240\220!\4\20\31\221p\242\10\1A\f@\4\21\0@E\0Z\200\31`\2!\22\20\1\1\2\22\0 \0\5B(\0\0\224\342Z\0\0\0\0\0\0\0]\0\0\0^\0\0\0`\0\0\0b\0\0\0c\0\0\0\0\0\0\0e\0\0\0f\0\0\0\0\0\0\0\0\0\0\0i\0\0\0k\0\0\0\0\0\0\0m\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=198960, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c3000 mmap(NULL, 2292760, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2517000 mprotect(0x7f8ad2540000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad273f000, 32768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x28000) = 0x7f8ad273f000 close(4) = 0 open("/usr/lib64/sssd/libplds4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libplds4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\16\0\0\0\0\0\0@\0\0\0\0\0\0\0x6\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0D$\0\0\0\0\0\0D$\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\330-\0\0\0\0\0\0\330- \0\0\0\0\0\330- \0\0\0\0\0 \3\0\0\0\0\0\0(\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\370-\0\0\0\0\0\0\370- \0\0\0\0\0\370- \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\200\35\0\0\0\0\0\0\200\35\0\0\0\0\0\0\200\35\0\0\0\0\0\0\f\1\0\0\0\0\0\0\f\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\330-\0\0\0\0\0\0\330- \0\0\0\0\0\330- \0\0\0\0\0(\2\0\0\0\0\0\0(\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\200\3\245\21a:\261\24\222z,4\235b\274\ 211\2717/-\0\0\0\0\21\0\0\0\r\0\0\0\4\0\0\0\10\0\0\0\0\0\220\0\0\200@\0,\21"\4\30\221\300\22\0c\245\212X\203\10+\300\0H\5\4\6&\0\r\0\0\0\21\0\0\0\23\0\0\0\27\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\36\0\0\0\37\0\0\0"\0\0\0$\0\0\0&\0\0\0'\0\0\0)\0\0\0\0\0\0\0*\0\0\0+\0\0\0\220\370\353\316\326\265\212\350B\325\34\251IwcC\352\323\357\16U61fb9\320\351h/\237d\214\311\244\27\271\215\361\16\306\362\344u\330qX\34Q\0034X\273\343\222|\216Y\36\314\236=\352\202\343\207\265\303CE\325\354\26\257\324\27\226\375\10\256\233\322\277\267\224s\214\267M\232\321?\210\351\21Bm|\357\250md}\357\2509+\272\245\3574\334\247\263`\353\333\351-\2037\24\253\263\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\34\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\336\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=15800, ...}) = 0 mmap(NULL, 2109696, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad2313000 mprotect(0x7f8ad2316000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad2515000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7f8ad2515000 close(4) = 0 open("/usr/lib64/sssd/libplc4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libplc4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\24\0\0\0\0\0\0@\0\0\0\0\0\0\0@G\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3546\0\0\0\0\0\0\3546\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\330=\0\0\0\0\0\0\330= \0\0\0\0\0\330= \0\0\0\0\0\200\3\0\0\0\0\0\0\230\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\370=\0\0\0\0\0\0\370= \0\0\0\0\0\370= \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(.\0\0\0\0\0\0(.\0\0\0\0\0\0(.\0\0\0\0\0\0d\1\0\0\0\0\0\0d\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\330=\0\0\0\0\0\0\330= \0\0\0\0\0\330= \0\0\0\0\0(\2\0\0\0\0\0\0(\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0b\314\247]\262)\244\331\305\271/|\303l\351\3 5\335\363|\370\0\0\0\0%\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0@ \0010\331\251I\205<@xA >\303\30 3\306\1\10A\10)\201\201\214\t\200\225\226\263\0\0\0\0\34\0\0\0\36\0\0\0\0\0\0\0\0\0\0\0!\0\0\0#\0\0\0$\0\0\0%\0\0\0&\0\0\0(\0\0\0)\0\0\0*\0\0\0+\0\0\0,\0\0\0.\0\0\0/\0\0\0001\0\0\0\0\0\0\0002\0\0\0003\0\0\0005\0\0\0\0\0\0\0008\0\0\0009\0\0\0;\0\0\0<\0\0\0=\0\0\0\0\0\0\0\0\0\0\0?\0\0\0A\0\0\0B\0\0\0C\0\0\0D\0\0\0G\0\0\0\0\0\0\0\262\221-\2719P\34"\256#;\214\322\264\234\32\223\226\304\312\34\260\205\33\353\323\357\16\301\254\247ewS\233\32\211E\16nd+\34"E\336\251e\275\227M\363\377W\241e\371*\34"?f\247e\fo\224\32\351|\250em|\357\2506o\234\32\211\2145\266\367\333Jq\21m\247e$g\247e\363o\34"\370}\7\33X\255:\36;\235\300\32\251\230\251e\6\215\247e\331qX\34\273\343\222|Uw,\276p)\34"\311\17D\271", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=20096, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad210e000 mprotect(0x7f8ad2112000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad2311000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7f8ad2311000 close(4) = 0 open("/usr/lib64/sssd/libnspr4.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libnspr4.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\314\0\0\0\0\0\0@\0\0\0\0\0\0\0\230\320\3\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0004\224\3\0\0\0\0\0004\224\3\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@\227\3\0\0\0\0\0@\227#\0\0\0\0\0@\227#\0\0\0\0\0\250\34\0\0\0\0\0\0\340E\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\235\3\0\0\0\0\0\240\235#\0\0\0\0\0\240\235#\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\230\16\3\0\0\0\0\0\230\16\3\0\0\0\0\0\230\16\3\0\0\0\0\0\24\26\0\0\0\0\0\0\24\26\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@\227\3\0\0\0\0\0@\227#\0\0\0\0\0@\227#\0\0\0\0\0\300\10\0\0\0\0\0\0\300\10\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\3 01V\240\353\211\26\345\230\331\247>_\333\354\350f\346\236\362\214\0\0\0\0\7\1\0\0\257\0\0\0@\0\0\0\f\0\0\0\10\20\360\0 \4\2\0\0\20\202\1\1\22\0 \0\20\4&\0\2\200@@\3\0\202\0\200\200A\10\10\26\200\0000\240\2\205\0\20P@\240\0\301\300\210@@\22\200q\10\244\0\2\305\4\10\22"\0\0\0\1\1\0\240\0022\0\6\21\200\24\0B\0@\2044\1P\20\t@\200\231\240\0\4\0\6\16\10-@ \0\0`\2\10\4\0\231\32@\24\0A\4\2\0P!\210\255\322`\200\210\6@0\200\22\r\t\1T\240\20@\202)\0l\20\20$\20c\0\1\23\t\32(\0\1%\0\0P\n\204\0\10\0\221\21e\20\320\v\300\21 \244\201 \1\200@\24\0@\0\4 \0\0\30\7\10U\0\10D\0$\0\250\0\200\20\t\200!\1\0p\0\0\0\4\4\2\3\0D\340\246\2\10\4\0\10H!A%@U\0\310I\255\30\200a\0\0\0``\0\0\4\0\0\0\4\0\25 d\1\202\4\0\34\2\20\20&\0.\2\20\201D \0\0\0\0\10"\214\0\4\0\3\1 \2a\0\4\0\1\0\0j\0 A\20\36\n\200\3001D\1\224\0\0\0\21\202\0\v\1\4\0\0\30\r\4\0\277\4(\245", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=251864, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c2000 mmap(NULL, 2350368, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad1ed0000 mprotect(0x7f8ad1f0a000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad2109000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x39000) = 0x7f8ad2109000 mmap(0x7f8ad210c000, 7456, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad210c000 close(4) = 0 open("/usr/lib64/sssd/libpthread.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libpthread.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200m\0\0\0\0\0\0@\0\0\0\0\0\0\0H!\2\0\0\0\0\0\0\0\0\0@\0008\0\t\0@\0(\0'\0\6\0\0\0\5\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\370\1\0\0\0\0\0\0\370\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0\260\22\1\0\0\0\0\0\260\22\1\0\0\0\0\0\260\22\1\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\350e\1\0\0\0\0\0\350e\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`k\1\0\0\0\0\0`k!\0\0\0\0\0`k!\0\0\0\0\0\200\7\0\0\0\0\0\0(I\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0Pm\1\0\0\0\0\0Pm!\0\0\0\0\0Pm!\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0008\2\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\314\22\1\0\0\0\0\0\314\22\1\0\0\0\0\0\314\22\1\0\0\0\0\0t\n\0\0\0\0\0\0t\n\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\ 0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`k\1\0\0\0\0\0`k!\0\0\0\0\0`k!\0\0\0\0\0\240\4\0\0\0\0\0\0\240\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0|\177\374}\242\250\201\20\374\342\236]\274-\243\10N\5\352\10\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\345\1\0\0V\0\0\0 \0\0\0\v\0\0\0\31#\2\261\1\10\20\2@@a\370\3\10\10\25\200 \0\0\0\0\200\300\321Q\0\0\0\22\353\3020D\0\10\20A\0\2\0\2\f\1\200\v\221\1\330\240\r\240@\230 \244\200\21\n\202-l@g\214V\24\0\224 \200$H\200P(\1\22\f\311B\240\220\22\10\f \2ZdA\245c\4@\n\n\2\0\2009\1(\314@\204\201@\22\10(\fD\0\0\0\200Q\10\200\35\4B\320\2608A\0\1\0\0\265\0300\0\200`\2\20"\0\tA\20\1\5\0P(\251\2\7(\0\0\202\4\230@\4\0\20\340T\0\2@\2\2\20\3010D\26\200\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=142152, ...}) = 0 mmap(NULL, 2208904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad1cb4000 mprotect(0x7f8ad1ccb000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad1eca000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x16000) = 0x7f8ad1eca000 mmap(0x7f8ad1ecc000, 13448, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad1ecc000 close(4) = 0 open("/usr/lib64/sssd/libdl.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdl.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\16\0\0\0\0\0\0@\0\0\0\0\0\0\0008C\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0 \0\37\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\304\37\0\0\0\0\0\0\304\37\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0X-\0\0\0\0\0\0X- \0\0\0\0\0X- \0\0\0\0\0@\3\0\0\0\0\0\0\330\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\210-\0\0\0\0\0\0\210- \0\0\0\0\0\210- \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\0\32\0\0\0\0\0\0\0\32\0\0\0\0\0\0\0\32\0\0\0\0\0\0\274\0\0\0\0\0\0\0\274\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0X-\0\0\0\0\0\0X- \0\0\0\0\0X- \0\0\0\0\0\250\2\0\0\0\0\0\0\250\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\250\345\361\311\262\225Mb\276m\311\232J\243S \365\260\372P.\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\33\0\0\0\32\0\0\0\2\0\0\0\7\0\0\0\230\2\21\0\200H\0\4\22\0\0@\203(\10\236\32\0\0\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\35\0\0\0\0\0\0\0\36\0\0\0\0\0\0\0\37\0\0\0\0\0\0\0 \0\0\0"\0\0\0#\0\0\0%\0\0\0&\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0'\0\0\0\0\0\0\0\0\0\0\0\353\26\251\30a\257\0\371\301S\200\30\273\25sB\257\304M\17\221!\374\370\6\2\4\371\3733\373\17\371\31sB\372\31sB\225\263_\31\177\236\320\30a\242\222\6\5\350\7\371\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0=\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\375\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\337\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19256, ...}) = 0 mmap(NULL, 2109744, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad1ab0000 mprotect(0x7f8ad1ab2000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad1cb2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0x7f8ad1cb2000 close(4) = 0 open("/usr/lib64/sssd/libc.so.6", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P&\2\0\0\0\0\0@\0\0\0\0\0\0\0`\323 \0\0\0\0\0\0\0\0\0@\0008\0\n\0@\0K\0J\0\6\0\0\0\5\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0 \351\30\0\0\0\0\0 \351\30\0\0\0\0\0 \351\30\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260.\34\0\0\0\0\0\260.\34\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\240Q\0\0\0\0\0\0\340\232\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0`k\34\0\0\0\0\0`k<\0\0\0\0\0`k<\0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0p\2\0\0\0\0\0\0p\2\0\0\0\0\0\0p\2\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\20\0\0\0\0\0\0\0\240\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0P\345td\4\0\0\0<\351\30\0\0\0\0\0<\351\30\0\0\0\0\0<\351\30\0\0\0\0\ 0\314j\0\0\0\0\0\0\314j\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\0007\34\0\0\0\0\0\0007<\0\0\0\0\0\0007<\0\0\0\0\0\0009\0\0\0\0\0\0\0009\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0)5q\213\177\37\v,\265*\234S\321\265\3377_\270H\327\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\363\3\0\0\7\0\0\0\0\1\0\0\16\0\0\0\0000\20D\240 \2\1\210\3\346\220\305E\214\0\300\0\10\0\5\200\0`\300\200\0\r\212\f\0\4\20\0\210D2\10.@\210T<, \0162H&\204\300\214\4\10\0\2\2\16\241\254\32\4f\300\0\3002\0\300\0P\1 \201\10\204\v ($\0\4 Z\0\20X\200\312DB(\0\6\200\20\30B\0 @\200\0\tP\0Q\212@\20\0\0\0\0\10\0\0\21\20", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=2156064, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c1000 mmap(NULL, 3985888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad16e2000 mprotect(0x7f8ad18a5000, 2097152, PROT_NONE) = 0 mmap(0x7f8ad1aa5000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1c3000) = 0x7f8ad1aa5000 mmap(0x7f8ad1aab000, 16864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad1aab000 close(4) = 0 open("/usr/lib64/sssd/libz.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20!\0\0\0\0\0\0@\0\0\0\0\0\0\0HY\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0LD\1\0\0\0\0\0LD\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0(K\1\0\0\0\0\0(K!\0\0\0\0\0(K!\0\0\0\0\0008\5\0\0\0\0\0\0@\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0008L\1\0\0\0\0\0008L!\0\0\0\0\0008L!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\200)\1\0\0\0\0\0\200)\1\0\0\0\0\0\200)\1\0\0\0\0\0\244\3\0\0\0\0\0\0\244\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0(K\1\0\0\0\0\0(K!\0\0\0\0\0(K!\0\0\0\0\0\330\4\0\0\0\0\0\0\330\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\271\325\3674(\275j\326\214\226\230kW\276\243\267\316\333\2 27E\0\0\0\0C\0\0\0\30\0\0\0\10\0\0\0\t\0\0\0\0\3h\24\f\3$\24\221\0\223A;\0\16\30\234\1\4\4\21\4\0\210,\0\303"\224\27\212\203\0c0\262G\212PC ,\20\35\210\341\200\213A\220\23e$g\304\201V\0.\20\2\200\0\20\30\0\0\0\33\0\0\0\34\0\0\0\35\0\0\0!\0\0\0"\0\0\0$\0\0\0%\0\0\0\0\0\0\0&\0\0\0'\0\0\0*\0\0\0-\0\0\0.\0\0\0\0\0\0\0000\0\0\0\0\0\0\0001\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0\0\0\0\0009\0\0\0:\0\0\0;\0\0\0\0\0\0\0<\0\0\0\0\0\0\0>\0\0\0?\0\0\0@\0\0\0A\0\0\0C\0\0\0D\0\0\0F\0\0\0I\0\0\0\0\0\0\0L\0\0\0N\0\0\0\0\0\0\0O\0\0\0S\0\0\0T\0\0\0\0\0\0\0U\0\0\0\0\0\0\0W\0\0\0Y\0\0\0\0\0\0\0Z\0\0\0\\0\0\0\0\0\0\0]\0\0\0`\0\0\0b\0\0\0\0\0\0\0c\0\0\0d\0\0\0e\0\0\0\0\0\0\0\0\0\0\0f\0\0\0g\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=90248, ...}) = 0 mmap(NULL, 2183272, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad14cc000 mprotect(0x7f8ad14e1000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad16e0000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7f8ad16e0000 close(4) = 0 open("/usr/lib64/sssd/libcrypt.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcrypt.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\16\0\0\0\0\0\0@\0\0\0\0\0\0\0\240\226\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0 \0\37\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Ht\0\0\0\0\0\0Ht\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\200}\0\0\0\0\0\0\200} \0\0\0\0\0\200} \0\0\0\0\0`\3\0\0\0\0\0\0\300\344\2\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240}\0\0\0\0\0\0\240} \0\0\0\0\0\240} \0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0@m\0\0\0\0\0\0@m\0\0\0\0\0\0@m\0\0\0\0\0\0\254\0\0\0\0\0\0\0\254\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\200}\0\0\0\0\0\0\200} \0\0\0\0\0\200} \0\0\0\0\0\200\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\213\10\244\31\321\337\10\301\201T\264"\2 36\2001\203s\177\32\240\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\17\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\4I\300,$\204 \f\0\0\0\0\0\0\0\0\0\0\0\0\36\0\0\0\37\0\0\0 \0\0\0\0\0\0\0!\0\0\0"\0\0\0\0\0\0\0#\0\0\0\0\0\0\0$\0\0\0%\0\0\0\0\0\0\0k\31Qj\233(\375B\233`\205\33\327\16?\17I->\333\235C\r\375\313\373_\22\273\25sB\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0)\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\0\0\0\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\246\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=40608, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41c0000 mmap(NULL, 2318912, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad1295000 mprotect(0x7f8ad129d000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad149c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7000) = 0x7f8ad149c000 mmap(0x7f8ad149e000, 184896, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad149e000 close(4) = 0 open("/usr/lib64/sssd/libcap.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libcap.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\25\0\0\0\0\0\0@\0\0\0\0\0\0\0@G\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\35\0\34\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2047\0\0\0\0\0\0\2047\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\320=\0\0\0\0\0\0\320= \0\0\0\0\0\320= \0\0\0\0\0H\4\0\0\0\0\0\0P\4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\360=\0\0\0\0\0\0\360= \0\0\0\0\0\360= \0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\3300\0\0\0\0\0\0\3300\0\0\0\0\0\0\3300\0\0\0\0\0\0\24\1\0\0\0\0\0\0\24\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\320=\0\0\0\0\0\0\320= \0\0\0\0\0\320= \0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\25=KEc\301_T\316\300\20\26\5,\23 6;\345i;\210\0\0\0\0\21\0\0\0\36\0\0\0\4\0\0\0\10\0\0\0@\10$\201\30\20@\204\270$\0(\212\0\30$\20\242\220\4\10\10\33\t\2\0H\341\204T\2\220\36\0\0\0\37\0\0\0 \0\0\0!\0\0\0&\0\0\0(\0\0\0)\0\0\0+\0\0\0.\0\0\0002\0\0\0005\0\0\0006\0\0\0\0\0\0\0008\0\0\0009\0\0\0;\0\0\0>\0\0\0E3vg\353\323\357\16\271\215\361\16\216\332\241]\nzqP\330qX\34\210q\356\262[\207i\224\300\277<\316\273\343\222|\37\344l\224\30\277[\27\261D=\BE\325\354t\343\324\225{a,\20\334\347\250\231\360\342kP\226t\207c\25\6\365\262`\n\352\262\226\327kPM\247:\352\337\374~\25,\366-\20#\330\250\231}\335\201c\354\26\v\210#\322\201c\252T\275\331\322^3\20\377\356\311x\261s\16\210\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\265\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0{\2\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=20096, ...}) = 0 mmap(NULL, 2114080, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad1090000 mprotect(0x7f8ad1094000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad1293000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7f8ad1293000 close(4) = 0 open("/usr/lib64/sssd/libm.so.6", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libm.so.6", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0PS\0\0\0\0\0\0@\0\0\0\0\0\0\0xP\21\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0#\0"\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\7\20\0\0\0\0\0\374\7\20\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0p\r\20\0\0\0\0\0p\r0\0\0\0\0\0p\r0\0\0\0\0\0t\3\0\0\0\0\0\0\310\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\220\r\20\0\0\0\0\0\220\r0\0\0\0\0\0\220\r0\0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h\206\17\0\0\0\0\0h\206\17\0\0\0\0\0h\206\17\0\0\0\0\0,\22\0\0\0\0\0\0,\22\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0p\r\20\0\0\0\0\0p\r0\0\0\0\0\0p\r0\0\0\0\0\0\220\2\0\0\0\0\0\0\220\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\17\341\360m\25\360D\255Jq\246\324\30'\300 f\6\242CB\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\10\3\0\0\22\0\0\0@\0\0\0\f\0\0\0%\0`\0\0\240."\200\0\26\211\0 E"\2\0\300``i\10\212\0\t\0\0\0\0\0\0\0\0\0\0\0\0\212P\20\1\10\0\0\4\1\302\24\1 \210"\0\304\243X\240\n\6\216\0\212\0\0\4\0@\0\0 \20\0\5\0\5\r\7\7\22A\0\1\0\10\0\0@\0\t\0\20\4D\30\4\200a(\22@\4\1\nE\221 @\200\f\22\1\0\0\0\0\0\0\0\0\4\2\0\0\0@\0\200\2\20\322\0\1\10\4\301 E\1\0\310"\0\4\2\0\202\0\4\0\0\0\4\0Y\4\2\0\n\200\1\0\0\4\0\20 \3\0\0\210 \10\20\0\0 \2\0\0\200\10\2\4\0\0HQ\0\0\f\2\0\0 \10 \0\0\0\0 #\4\0\200\0I\2\fc\2 A\221\242@\4\202EL \0\0\300\2\4\200\10\2\r(\2\0\20"\0!\22\30\30\24 8\0\210\0\0\260 B,\10\302\0 \200\361)\24A\21 @\220 \4\1P\20\202\0\0\214\0\0`\242\10\10A\0\0\0 \202", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=1136952, ...}) = 0 mmap(NULL, 3150136, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad0d8e000 mprotect(0x7f8ad0e8f000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad108e000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x100000) = 0x7f8ad108e000 close(4) = 0 open("/usr/lib64/sssd/librt.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/librt.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000"\0\0\0\0\0\0@\0\0\0\0\0\0\0H\241\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0&\0%\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\24e\0\0\0\0\0\0\24e\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@m\0\0\0\0\0\0@m \0\0\0\0\0@m \0\0\0\0\0\24\5\0\0\0\0\0\0\370\16\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0pm\0\0\0\0\0\0pm \0\0\0\0\0pm \0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24S\0\0\0\0\0\0\24S\0\0\0\0\0\0\24S\0\0\0\0\0\0<\2\0\0\0\0\0\0<\2\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@m\0\0\0\0\0\0@m \0\0\0\0\0@m \0\0\0\0\0\300\2\0\0\0\0\0\0\300\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0.\316\241\235h\2,]\330\301\234/B<\26\242(\25d\304\4\0\0\0\20\0\0\0 \1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0b\0\0\0B\0\0\0\10\0\0\0\t\0\0\0\1\0\204!0\0\10@\0\20P\213\340\6\22 \0\10\202@\0(\200 \t\3\0\4@\1@#\2\20\0\2\240\4 \0\10\0\0\2\0\4\0\200\210\206D\20\0\0\20\4P\20\2\322\4\1\4\206\0\0\0\0\0\0\0\0B\0\0\0C\0\0\0D\0\0\0\0\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0H\0\0\0I\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0K\0\0\0\0\0\0\0L\0\0\0\0\0\0\0M\0\0\0\0\0\0\0O\0\0\0P\0\0\0\0\0\0\0Q\0\0\0R\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0T\0\0\0\0\0\0\0\0\0\0\0U\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0V\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=43720, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41bf000 mmap(NULL, 2128952, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad0b86000 mprotect(0x7f8ad0b8d000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad0d8c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x6000) = 0x7f8ad0d8c000 close(4) = 0 open("/usr/lib64/sssd/libselinux.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320i\0\0\0\0\0\0@\0\0\0\0\0\0\0\310X\2\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<0\2\0\0\0\0\0<0\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\0\0\230\t\0\0\0\0\0\0\300,\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0H=\2\0\0\0\0\0H="\0\0\0\0\0H="\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\0\0(\0\0\0\0\0\0\0\350\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0P\345td\4\0\0\0\350\344\1\0\0\0\0\0\350\344\1\0\0\0\0\0\350\344\1\0\0\0\0\0\264\n\0\0\0\0\0\0\264\n\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\220<\2\0\0\0\0\0\220<"\0\0\0\0\0\220<"\0\0\0\ 0\0p\3\0\0\0\0\0\0p\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\322\335M\243\375\341G}%\277\377\200\363\242_\333T\32\201y\0\0\0\0\305\0\0\0\206\0\0\0 \0\0\0\v\0\0\0\230 \4\201 L\0\3#\20\300\nT\210\357\322B\6h\10\24\26\0\6\20\4\4\0\0\311@\1P.\21\30\0&\th\30 \200*H\10\22\1\1,!\0\20\0\217\7\250@@Q\0\274\0\0\0R\20\236\4\1\5\24\33\21\33\214 \0\3C\10\1H\21\2\2\0\200j\17\304\1\2\210`\203\200\2*\200\202@\200\4\0\0C\30\4\0\20\200:\0!\266\10\5\0\216\0\4\0@\204\24\0F\n\0\200 \0`0T\1@\304\0\20\0\240\24\20\234\10\200\0D\0\204\10@&\7\202\0\200\200\1\10\10\0\2\2\0\200\232\203\4\304\25\221(\2\200\0\10\0\201@\2\201\200\200@@\201\1\2\21\200@\24\201\4\221\313@ \10D\1\0\0\0\2F@\1\0A\220q\20@Eb\0\t"\0\20@@IL\341\24\200<@!\0\0 \0\0\200\310\206\342@\200\22\0\3 @\2!\200T\2!\206\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=155784, ...}) = 0 mmap(NULL, 2255184, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad095f000 mprotect(0x7f8ad0983000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad0b82000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x23000) = 0x7f8ad0b82000 mmap(0x7f8ad0b84000, 6480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad0b84000 close(4) = 0 open("/usr/lib64/sssd/liblzma.so.5", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/liblzma.so.5", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\2000\0\0\0\0\0\0@\0\0\0\0\0\0\0\330_\2\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<@\2\0\0\0\0\0<@\2\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`J\2\0\0\0\0\0`J"\0\0\0\0\0`J"\0\0\0\0\0 \10\0\0\0\0\0\0(\10\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\300M\2\0\0\0\0\0\300M"\0\0\0\0\0\300M"\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0 \377\1\0\0\0\0\0 \377\1\0\0\0\0\0 \377\1\0\0\0\0\0004\t\0\0\0\0\0\0004\t\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`J\2\0\0\0\0\0`J"\0\0\0\0\0`J"\0\0\0\0\0\240\5\0\0\0\0\0\0\240\5\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0f\376\346_D\306\304gd\311\334J\332`\274\205\257z\3 43o\0\0\0\0a\0\0\0!\0\0\0\20\0\0\0\n\0\0\0\0\1\242\2 @ \301\230 (\204@\0\1\0(\4\10\200\0\202\5\0\6\0\0\202\1\10 \0\0"\0R@\2\4\201\21Ph\241H\205B \0\10\300\200P\0\210\204\10\200T\n\22\210\0\4A\4\0\0\0@\200\0`8T\0\300\0@\0\202\260\20`\214\20\7\243@\0\31\20E\2P\3 \0 \6\2 \0 l\24P\0\303 \340\0\310\10\0\24\4@\20\4\t\0 \2\300\0C0!\0\0\0#\0\0\0\0\0\0\0\0\0\0\0$\0\0\0\0\0\0\0%\0\0\0\0\0\0\0'\0\0\0*\0\0\0\0\0\0\0+\0\0\0\0\0\0\0-\0\0\0/\0\0\0\0\0\0\0000\0\0\0\0\0\0\0\0\0\0\0001\0\0\0\0\0\0\0003\0\0\0005\0\0\0\0\0\0\0007\0\0\0\0\0\0\0008\0\0\0:\0\0\0<\0\0\0@\0\0\0B\0\0\0C\0\0\0\0\0\0\0\0\0\0\0E\0\0\0\0\0\0\0\0\0\0\0F\0\0\0\0\0\0\0J\0\0\0K\0\0\0L\0\0\0M\0\0\0\0\0\0\0O\0\0\0Q\0\0\0R\0\0\0S\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=157400, ...}) = 0 mmap(NULL, 2249352, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad0739000 mprotect(0x7f8ad075e000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad095d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x24000) = 0x7f8ad095d000 close(4) = 0 open("/usr/lib64/sssd/liblz4.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/liblz4.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0%\0\0\0\0\0\0@\0\0\0\0\0\0\0\20I\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\33\0\32\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2044\1\0\0\0\0\0\2044\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0(=\1\0\0\0\0\0(=!\0\0\0\0\0(=!\0\0\0\0\0\30\4\0\0\0\0\0\0 \4\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\350=\1\0\0\0\0\0\350=!\0\0\0\0\0\350=!\0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(\31\1\0\0\0\0\0(\31\1\0\0\0\0\0(\31\1\0\0\0\0\0L\4\0\0\0\0\0\0L\4\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0(=\1\0\0\0\0\0(=!\0\0\0\0\0(=!\0\0\0\0\0\330\2\0\0\0\0\0\0\330\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0 \1l:m\206!\226\30\177T\32\327\315\370\220\251\374\322\2 57\0\0\0\0a\0\0\0\r\0\0\0\20\0\0\0\n\0\0\0\2\214!\200\21D\302\5\0\240\1\204\0\0\0\0\0%(F\0\322\350%\0\10\220\1\0\0\10\10\220\0\20\20\20\0\3\fh\5\2\3 &\22\330\20\0\0\1\10\2\0\21@\1\240\21\4 \0\4\0 2q@\2\0b\4\n\0\200\21\310\0\10\0\6\2\f\n\20\216\4\0 \2 \302\0H\20H\204@\0\0$\200\0( 6\200\4\240h\212\0\320\0\0L\10\20-\24\16\3\10\204\7P@\r\0\0\0\0\0\0\0\0\0\0\0\16\0\0\0\20\0\0\0\23\0\0\0\24\0\0\0\0\0\0\0\25\0\0\0\26\0\0\0\0\0\0\0\27\0\0\0\32\0\0\0\33\0\0\0\0\0\0\0\34\0\0\0\36\0\0\0\37\0\0\0 \0\0\0!\0\0\0\0\0\0\0#\0\0\0\0\0\0\0\0\0\0\0$\0\0\0%\0\0\0&\0\0\0'\0\0\0(\0\0\0\0\0\0\0)\0\0\0\0\0\0\0*\0\0\0\0\0\0\0,\0\0\0.\0\0\0\0\0\0\0000\0\0\0001\0\0\0\0\0\0\0002\0\0\0003\0\0\0004\0\0\0006\0\0\0008\0\0\0:\0\0\0\0\0\0\0;\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=85968, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41be000 mmap(NULL, 2179400, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad0524000 mprotect(0x7f8ad0538000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad0737000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x13000) = 0x7f8ad0737000 close(4) = 0 open("/usr/lib64/sssd/libgcrypt.so.11", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgcrypt.so.11", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0u\0\0\0\0\0\0@\0\0\0\0\0\0\0\310"\10\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\301\7\0\0\0\0\0\374\301\7\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0@\310\7\0\0\0\0\0@\310'\0\0\0\0\0@\310'\0\0\0\0\0D3\0\0\0\0\0\0\2208\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\240\315\7\0\0\0\0\0\240\315'\0\0\0\0\0\240\315'\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h\370\6\0\0\0\0\0h\370\6\0\0\0\0\0h\370\6\0\0\0\0\0\254\35\0\0\0\0\0\0\254\35\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0@\310\7\0\0\0\0\0@\310'\0\0\0\0\0@\310'\0\0\0\0\0\300\7\0\0\0\0\0\0\300\7\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\327yrC\0011 v\272\304\213Gdl\215\16\201\202Y\320\361\0\0\0\0\203\0\0\0Y\0\0\0 \0\0\0\v\0\0\0\2\1\0\f\30\1\0`"\200\2\10\0\10\\1\0\4\4\224\221D\1@\340\20\0\22\0\4\0$\21\20\34Bp\6\200\n"\10\204\200\0\24\0\0\0\1\2\24\0@\212\252@\0\4\210\200\0\0\0\204\0@\10P\1\1@\310\10\0$AB\1\200\4\1 @\210`@\1\4\240 \211\320\1\10c`P\242C\1\210\n\0\0\23\10\0\220\22\1@\0E\20\200,\0030\0\200@B,\24\10*\200\0\4\20\4,\4@\340X\0\4\222\0\1$\0\n C\200\3131\1\0\2B\1D\1\f\n\201@P0\1E\222\300(\0\1\0T\0000\nQ\0\0\0\200\10\200\5@\200\310 \30\34\223\300\1P\0\0\0\0\0 \vh@\254\220\0\0\200\2\0-\0\212`\1\200\1\20\300\200\0\0\10\0\4 \0\26\23\2A(\200\210\20@DX\4\0\201@\20\0<\0\0\1\200\0\2\200\0\202\0\3\10Y\0\0\0\0\0\0\0Z\0\0\0^\0\0\0`\0\0\0\0\0\0\0a\0\0\0b\0\0\0d\0\0\0\0\0\0\0f\0\0\0g\0\0\0h\0\0\0i\0\0\0\0\0\0\0j\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=535112, ...}) = 0 mmap(NULL, 2621648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad02a3000 mprotect(0x7f8ad0320000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad051f000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x7c000) = 0x7f8ad051f000 mmap(0x7f8ad0523000, 208, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad0523000 close(4) = 0 open("/usr/lib64/sssd/libgpg-error.so.0", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgpg-error.so.0", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\300\t\0\0\0\0\0\0@\0\0\0\0\0\0\0\260D\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\33\0\32\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|0\0\0\0\0\0\0|0\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0\210\2\0\0\0\0\0\0\220\2\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\10>\0\0\0\0\0\0\10> \0\0\0\0\0\10> \0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0008.\0\0\0\0\0\0008.\0\0\0\0\0\0008.\0\0\0\0\0\0t\0\0\0\0\0\0\0t\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0 \2\0\0\0\0\0\0 \2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\367l\226Z\5d\345\365\233\255\203\255g/,M\217 \375L\225\0\0\0\0\3\0\0\0\16\0\0\0\2\0\0\0\7\0\0\0\241 @h#\0\22\t\210\4\0\3\250T\0\0\16\0\0\0\24\0\0\0\32\0\0\0\244X\321QBE\325\354\226"\212\v\272\343\222|\356s\274\5\347\22\211\372\234P\204=\354\fp\254\330qX\34\236\246\321\313\354\3^\n\271\215\361\16\352\323\357\16:\320\f\343\1\232_\263\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\t\0\360\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\254\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\343\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\37\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0&\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\24\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19312, ...}) = 0 mmap(NULL, 2113648, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8ad009e000 mprotect(0x7f8ad00a2000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad02a1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7f8ad02a1000 close(4) = 0 open("/usr/lib64/sssd/libresolv.so.2", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\00009\0\0\0\0\0\0@\0\0\0\0\0\0\0\320\224\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0!\0 \0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240T\1\0\0\0\0\0\240T\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0HU\1\0\0\0\0\0HU!\0\0\0\0\0HU!\0\0\0\0\0\214\f\0\0\0\0\0\0\2704\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\210]\1\0\0\0\0\0\210]!\0\0\0\0\0\210]!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0D\0\0\0\0\0\0\0D\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\24/\1\0\0\0\0\0\24/\1\0\0\0\0\0\24/\1\0\0\0\0\0\244\3\0\0\0\0\0\0\244\3\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0HU\1\0\0\0\0\0HU!\0\0\0\0\0HU!\0\0\0\0\0\270\n\0\0\0\0\0\0\270\n\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0pGd\243*\0\2128\223\26\232\374:\20'<h\n\312y\4\0 \0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\6\0\0\0 \0\0\0\0\0\0\0\307\0\0\0?\0\0\0\20\0\0\0\n\0\0\0\0\0@\0\0\0\200\0\0F \24\0013\244\232\202\202\20\0\2\5\1\20!\2\30\1`\220T\207\200@\0 \20\0\0\0\200\10\0\26\304\20\0\20"\0\2\20\20\30H\4`\304 @ \4B1\6Z\34\200<\20H4\200\0\20\221\1\1\10\204\200\0\0\4@\t\0\0D\200\0\200D\10\20\1\20H\0@\220\224\32\n\0\20Y\20\201\23\0\10\344\f4\4\0\200\6\20\0!\4\7\1\2431\16?\0\0\0\0\0\0\0A\0\0\0B\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0D\0\0\0E\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0G\0\0\0\0\0\0\0\0\0\0\0I\0\0\0\0\0\0\0J\0\0\0K\0\0\0\0\0\0\0L\0\0\0\0\0\0\0M\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0N\0\0\0\0\0\0\0P\0\0\0\0\0\0\0Q\0\0\0\0\0\0\0\0\0\0\0S\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=105744, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41bd000 mmap(NULL, 2198016, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acfe85000 mprotect(0x7f8acfe9b000, 2093056, PROT_NONE) = 0 mmap(0x7f8ad009a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x15000) = 0x7f8ad009a000 mmap(0x7f8ad009c000, 6656, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f8ad009c000 close(4) = 0 open("/usr/lib64/sssd/libdw.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libdw.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\236\0\0\0\0\0\0@\0\0\0\0\0\0\0P#\5\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0l\325\4\0\0\0\0\0l\325\4\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\200!\0\0\0\0\0\0\260$\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0@\375\4\0\0\0\0\0@\375$\0\0\0\0\0@\375$\0\0\0\0\0`\2\0\0\0\0\0\0`\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0000^\4\0\0\0\0\0000^\4\0\0\0\0\0000^\4\0\0\0\0\0\274\20\0\0\0\0\0\0\274\20\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0`\344\4\0\0\0\0\0`\344$\0\0\0\0\0`\344$\0\0\0\0\0\240\33 \0\0\0\0\0\0\240\33\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0B;\177\227\327\217\324*\273?op\205N\23*\32%\303\335\0\0\0\0\305\0\0\0\226\0\0\0 \0\0\0\v\0\0\0\10\207\204\0223\r\350\211\4\6\222\10$\224F\242PL\260\200\300\0\0\202 \220@@\0$\2B(\20\251H\21T\202$\20\0@ \0 \0\0@\212\0 \1\0\0\0\341\0(\200\0\0\2\0000@\0\0\0\30\2\0\200"\204\220\223\31\0$I@\24\210\0 \222\1\204\220\240&\206\0\2\0\0$\200\0\0\1@\20\5\20\200\1)\0 CD(\t\240\251"\20\200\0\6"\24D\n\200\0`\0\nv \240\0\4\271\205\0002\0 \t\216\24\0\244\2\0\210\0\0010\r\0104\0\f\1\0\0\201\10\312\4\22B\210@!\20D\23\10A\320\30@\202@P\0\1\6\256\1\0 \312\3\5\220\326\241 \4\254\0U\0\10\200\1\25\214\200$d\4\10br\0\10\0\0!\244)H\0!\4\260\240\270\0\20\2\4\4\4\0B\332\242(\34$\206\0\232\240\300\2\20\340\1\1\204\0\0!\5\20\1\226\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=338704, ...}) = 0 mmap(NULL, 2427152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acfc34000 mprotect(0x7f8acfc82000, 2097152, PROT_NONE) = 0 mmap(0x7f8acfe82000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x4e000) = 0x7f8acfe82000 close(4) = 0 open("/usr/lib64/sssd/libgcc_s.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libgcc_s.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320*\0\0\0\0\0\0@\0\0\0\0\0\0\0\20S\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\36\0\35\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224L\1\0\0\0\0\0\224L\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\260M\1\0\0\0\0\0\260M!\0\0\0\0\0\260M!\0\0\0\0\0\320\3\0\0\0\0\0\0P\6\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\330M\1\0\0\0\0\0\330M!\0\0\0\0\0\330M!\0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\4-\1\0\0\0\0\0\4-\1\0\0\0\0\0\4-\1\0\0\0\0\0D\5\0\0\0\0\0\0D\5\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\260M\1\0\0\0\0\0\260M!\0\0\0\0\0\260M!\0\0\0\0\0P\2\0\0\0\0\0\0P\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0008\32\274;-\23\t\264\351\312\30F\346\326\37 6\273E\274\330*\0\0\0\0\203\0\0\0\26\0\0\0\20\0\0\0\n\0\0\0\23\34\3\30\4$\0\1\1\201\0T\4\6\210\20\200\204\0\10\0\10\5\200\2\0@\20D\20\0\266\2\200\320 \301\0\220\2024\1\0\4\10(@\2H\1\v \320\1\2(\0235\4`l\322\0!\3p`@\322\200\10`\0@\1\0\200\1\0\0\2$\0\10\21\2\10H\300\1$\t\21( \10C\v\246\202H\t\10\10\3D\f\n\34\22O\306\1\207\va\204\226\315\4\302\305\f\242\333\16\314\26\0\0\0\27\0\0\0\32\0\0\0\0\0\0\0\35\0\0\0\0\0\0\0\37\0\0\0 \0\0\0"\0\0\0%\0\0\0'\0\0\0\0\0\0\0(\0\0\0*\0\0\0+\0\0\0.\0\0\0000\0\0\0003\0\0\0004\0\0\0007\0\0\0\0\0\0\0008\0\0\0009\0\0\0<\0\0\0=\0\0\0?\0\0\0@\0\0\0A\0\0\0B\0\0\0C\0\0\0E\0\0\0\0\0\0\0F\0\0\0\0\0\0\0G\0\0\0\0\0\0\0\0\0\0\0H\0\0\0I\0\0\0K\0\0\0L\0\0\0M\0\0\0\0\0\0\0\0\0\0\0O\0\0\0Q\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=88720, ...}) = 0 mmap(NULL, 2184192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acfa1e000 mprotect(0x7f8acfa33000, 2093056, PROT_NONE) = 0 mmap(0x7f8acfc32000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x14000) = 0x7f8acfc32000 close(4) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41bc000 open("/usr/lib64/sssd/libfreebl3.so", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libfreebl3.so", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\v\0\0\0\0\0\0@\0\0\0\0\0\0\0\200%\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\274\24\0\0\0\0\0\0\274\24\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\250\35\0\0\0\0\0\0\250\35 \0\0\0\0\0\250\35 \0\0\0\0\0\360\2\0\0\0\0\0\0\30\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\310\35\0\0\0\0\0\0\310\35 \0\0\0\0\0\310\35 \0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0(\22\0\0\0\0\0\0(\22\0\0\0\0\0\0(\22\0\0\0\0\0\0t\0\0\0\0\0\0\0t\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\250\35\0\0\0\0\0\0\250\35 \0\0\0\0\0\250\35 \0\0\0\0\0X\2\0\0\0\0\0\0X\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\372\267\335\246\ 3631\211^A\235d\211\211\277\233\346\264\303\271\263\0\0\0\0\3\0\0\0\24\0\0\0\1\0\0\0\6\0\0\0\241\210\31\21@\2\313`\24\0\0\0\31\0\0\0\34\0\0\0\30\274\342\374\320\223@\334\260y\0\362\304\214\267\3467\247\300\312<0?\347J\3178\252?u\4X\322\263\222r\346m\204\214GJ)\252\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\206\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0q\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\262\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0i\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\231\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\251\0\0\0\22\0\0\0\0\0\0\0\0\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=11392, ...}) = 0 mmap(NULL, 2105536, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acf81b000 mprotect(0x7f8acf81d000, 2093056, PROT_NONE) = 0 mmap(0x7f8acfa1c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x1000) = 0x7f8acfa1c000 close(4) = 0 open("/usr/lib64/sssd/libattr.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libattr.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\320\23\0\0\0\0\0\0@\0\0\0\0\0\0\0\270F\0\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\344;\0\0\0\0\0\0\344;\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\300=\0\0\0\0\0\0\300= \0\0\0\0\0\300= \0\0\0\0\0\240\3\0\0\0\0\0\0\260\3\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\340=\0\0\0\0\0\0\340= \0\0\0\0\0\340= \0\0\0\0\0\360\1\0\0\0\0\0\0\360\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\3144\0\0\0\0\0\0\3144\0\0\0\0\0\0\3144\0\0\0\0\0\0\374\0\0\0\0\0\0\0\374\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\300=\0\0\0\0\0\0\300= \0\0\0\0\0\300= \0\0\0\0\0@\2\0\0\0\0\0\0@\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\34;-\271\26\356\274\245Z\ 264R\16\7C7\306\307,\252&\0\0\0\0\21\0\0\0\33\0\0\0\4\0\0\0\10\0\0\0*\0\30\0(\340\205\20<\4\1bH X \4\250#\0\v\21\10\311\20\230\10\r\0\5\6\200\33\0\0\0\34\0\0\0!\0\0\0%\0\0\0)\0\0\0\0\0\0\0+\0\0\0-\0\0\0000\0\0\0002\0\0\0\0\0\0\0003\0\0\0\0\0\0\0006\0\0\0007\0\0\0009\0\0\0<\0\0\0\241\213\315\300\4\301X\25\352\323\357\16\276\250\343\370\2-^\203m42\350\352\32\346\300X\235\235\323\276B1\340\271\215\361\16\24\345N\251f\336\10`\330qX\34Q\3431\256\272\343\222|s\302x\356.cx\204\221U_\25J=G\363BE\325\354/cx\2040cx\204\221x\251\335\271\3732\0\362?\355s\240sU\2413S\247\273\313\333\343\370D\366H\0237|h%\332\f\26\211\304\350\33\233\333\217[\25\255\0179N\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\n\0\20\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\242\1\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\203\0\0\0\22\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=19896, ...}) = 0 mmap(NULL, 2113904, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acf616000 mprotect(0x7f8acf61a000, 2093056, PROT_NONE) = 0 mmap(0x7f8acf819000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0x7f8acf819000 close(4) = 0 open("/usr/lib64/sssd/libpcre.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libpcre.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\25\0\0\0\0\0\0@\0\0\0\0\0\0\0\320\34\6\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0004\377\5\0\0\0\0\0004\377\5\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\210\f\6\0\0\0\0\0\210\f&\0\0\0\0\0\210\f&\0\0\0\0\0\224\4\0\0\0\0\0\0\200\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\270\r\6\0\0\0\0\0\270\r&\0\0\0\0\0\270\r&\0\0\0\0\0\340\1\0\0\0\0\0\0\340\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\340\321\5\0\0\0\0\0\340\321\5\0\0\0\0\0\340\321\5\0\0\0\0\0\344\4\0\0\0\0\0\0\344\4\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\210\f\6\0\0\0\0\0\210\f&\0\0\0\0\0\210\f&\0\0\0\0\0x\3\0\0\0\0\0\0x\3\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\3 65\261D\371\365\331\276E\34\200!\0334\333,\343H\3409\266\0\0\0\0\21\0\0\0\34\0\0\0\4\0\0\0\10\0\0\0@\204\t\0\202!\20\240\250@\0\23\304\320\201\30\2"\30@\30"D\v\200\30\10\1">\226\2\34\0\0\0\35\0\0\0\37\0\0\0"\0\0\0$\0\0\0'\0\0\0+\0\0\0000\0\0\0001\0\0\0002\0\0\0005\0\0\0\0\0\0\0006\0\0\0\0\0\0\0009\0\0\0<\0\0\0=\0\0\0\271\201\272\305\352\323\357\16\21\177\27\257\354\7\262\236\370\262E2\271\215\361\16f\267\251\177\331qX\34\312\207\345 bG\32s\273\343\222|\210\236\254\16\362\371\272np\\374\177o\316\312\205f\254\206'\224\273q3n\331\3621DX[\373{\374\266NCE\325\3545\317\205\323\350\341\354\224v\257\326\223'\206t\200\223\351\373\177\350\f.p\244vTi\365\354\2212<\312\356(\3447\234!\353\364\320\30)\241H\16\2542Vs-S>\36\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\t\0\370\23\0\0\0\0\0\0\0\0\0\0\0\0\0\0\23\3\0\0\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\306\0\0\0\22\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=402384, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41bb000 mmap(NULL, 2494984, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acf3b4000 mprotect(0x7f8acf414000, 2097152, PROT_NONE) = 0 mmap(0x7f8acf614000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x60000) = 0x7f8acf614000 close(4) = 0 open("/usr/lib64/elfutils/tls/x86_64/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/tls/x86_64", 0x7ffc176c42b0) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/tls/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/tls", 0x7ffc176c42b0) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/x86_64/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils/x86_64", 0x7ffc176c42b0) = -1 ENOENT (No such file or directory) open("/usr/lib64/elfutils/libelf.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) stat("/usr/lib64/elfutils", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/lib64/libelf.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0000\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\177\1\0\0\0\0\0\0\0\0\0@\0008\0\10\0@\0\37\0\36\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264j\1\0\0\0\0\0\264j\1\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\314\5\0\0\0\0\0\0\330\5\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\270m\1\0\0\0\0\0\270m!\0\0\0\0\0\270m!\0\0\0\0\0\20\2\0\0\0\0\0\0\20\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0\0\2\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\7\0\0\0\4\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0h@\1\0\0\0\0\0h@\1\0\0\0\0\0h@\1\0\0\0\0\0\244\6\0\0\0\0\0\0\244\6\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0\350k\1\0\0\0\0\0\350k!\0\0\0\0\0\350k!\0\0\0\0\0\30\4\ 0\0\0\0\0\0\30\4\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\363\23\224I\342\2027_C~\203w\25}\237zi\324<\366\0\0\0\0a\0\0\0001\0\0\0\20\0\0\0\n\0\0\0C\10\2\0\20\3\10\300\24\0\10\372\207\204\0\10\0\200\201\6\0\0\0\10\200\4\0\0000 \1\240`\20\264S\r\230\30\20\22\0`!\202\210D\n\200\240\300\316\300\201\22\3\10 E\1\310\300\2\2\2\v\21\200A\24\6\n\10\0\0\0\30\202\0 \0\202\200\200\261\1 \0(\1\1T\22H\3642B\20\22\241\10B\210A\0\200\0\200A\200\10\207\4\200\0A\200P\0\1A \0\215UH\0241\0\0\0002\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0003\0\0\0005\0\0\0006\0\0\0009\0\0\0\0\0\0\0<\0\0\0\0\0\0\0=\0\0\0\0\0\0\0\0\0\0\0?\0\0\0B\0\0\0D\0\0\0E\0\0\0\0\0\0\0F\0\0\0H\0\0\0J\0\0\0\0\0\0\0K\0\0\0M\0\0\0\0\0\0\0O\0\0\0P\0\0\0R\0\0\0T\0\0\0U\0\0\0W\0\0\0X\0\0\0", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=100032, ...}) = 0 mmap(NULL, 2191808, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acf19c000 mprotect(0x7f8acf1b3000, 2093056, PROT_NONE) = 0 mmap(0x7f8acf3b2000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x16000) = 0x7f8acf3b2000 close(4) = 0 open("/usr/lib64/elfutils/libbz2.so.1", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) open("/lib64/libbz2.so.1", O_RDONLY|O_CLOEXEC) = 4 read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`\27\0\0\0\0\0\0@\0\0\0\0\0\0\0`\3\1\0\0\0\0\0\0\0\0\0@\0008\0\7\0@\0\34\0\33\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0|\353\0\0\0\0\0\0|\353\0\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0 \355\0\0\0\0\0\0 \355 \0\0\0\0\0 \355 \0\0\0\0\0@\20\0\0\0\0\0\0H\20\0\0\0\0\0\0\0\0 \0\0\0\0\0\2\0\0\0\6\0\0\0\310\355\0\0\0\0\0\0\310\355 \0\0\0\0\0\310\355 \0\0\0\0\0\320\1\0\0\0\0\0\0\320\1\0\0\0\0\0\0\10\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0\310\1\0\0\0\0\0\0$\0\0\0\0\0\0\0$\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0P\345td\4\0\0\0\210\340\0\0\0\0\0\0\210\340\0\0\0\0\0\0\210\340\0\0\0\0\0\0d\1\0\0\0\0\0\0d\1\0\0\0\0\0\0\4\0\0\0\0\0\0\0Q\345td\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0R\345td\4\0\0\0 \355\0\0\0\0\0\0 \355 \0\0\0\0\0 \355 \0\0\0\0\0\340\2\0\0\0\0\0\0\340\2\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\342\317WR=\30=\3 0n\276`\371\21\3\240\221^G\226\344\0\0\0\0%\0\0\0\32\0\0\0\4\0\0\0\10\0\0\0\1@\200\0@\0\2\22(\206\213\5x\6\200\4\211\276\0102\230\244\200\v\325\0\r\1T\34"`\0\0\0\0\32\0\0\0\0\0\0\0\33\0\0\0\35\0\0\0\37\0\0\0\0\0\0\0\0\0\0\0 \0\0\0!\0\0\0\0\0\0\0\0\0\0\0$\0\0\0&\0\0\0(\0\0\0)\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0*\0\0\0+\0\0\0\0\0\0\0.\0\0\0\0\0\0\0001\0\0\0002\0\0\0004\0\0\0005\0\0\0006\0\0\0007\0\0\0008\0\0\0:\0\0\0\0\0\0\0\0\0\0\0<\0\0\0>\0\0\0A\0\0\0\377&\310\200J\2676}\271\355\315\302z\344\306]\17\200%\327\353\323\357\16\3215\227\301B\323\rid\246\2517\201\215\375\251\212\tpYYZ\210\301\2027#\31\215G\215\323\301&W\3279\346\354\262\217\223\26a\300lm\312\246$\f\370=q\372KP\343F\16zi\317\222\213\234X\327\331qX\34\230\335\212\300\273\343\222|\345\222t\301\307\342\351\224\307\202\245r\305\322`\301BE\325\354\2537\337\302N\317\273\224I\3463\262\26f\346\344", 832) = 832 fstat(4, {st_mode=S_IFREG|0755, st_size=68192, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41ba000 mmap(NULL, 2162024, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f8acef8c000 mprotect(0x7f8acef9b000, 2093056, PROT_NONE) = 0 mmap(0x7f8acf19a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xe000) = 0x7f8acf19a000 close(4) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41b9000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41b8000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41b7000 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41b6000 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41b4000 arch_prctl(ARCH_SET_FS, 0x7f8ad41b4880) = 0 mprotect(0x7f8ad1aa5000, 16384, PROT_READ) = 0 mprotect(0x7f8acf19a000, 4096, PROT_READ) = 0 mprotect(0x7f8ad16e0000, 4096, PROT_READ) = 0 mprotect(0x7f8acf3b2000, 4096, PROT_READ) = 0 mprotect(0x7f8ad1eca000, 4096, PROT_READ) = 0 mprotect(0x7f8acf614000, 4096, PROT_READ) = 0 mprotect(0x7f8acf819000, 4096, PROT_READ) = 0 mprotect(0x7f8ad1cb2000, 4096, PROT_READ) = 0 mprotect(0x7f8acfa1c000, 4096, PROT_READ) = 0 mprotect(0x7f8acfc32000, 4096, PROT_READ) = 0 mprotect(0x7f8ad095d000, 4096, PROT_READ) = 0 mprotect(0x7f8acfe82000, 8192, PROT_READ) = 0 mprotect(0x7f8ad009a000, 4096, PROT_READ) = 0 mprotect(0x7f8ad02a1000, 4096, PROT_READ) = 0 mprotect(0x7f8ad051f000, 4096, PROT_READ) = 0 mprotect(0x7f8ad0737000, 4096, PROT_READ) = 0 mprotect(0x7f8ad0b82000, 4096, PROT_READ) = 0 mprotect(0x7f8ad0d8c000, 4096, PROT_READ) = 0 mprotect(0x7f8ad108e000, 4096, PROT_READ) = 0 mprotect(0x7f8ad1293000, 4096, PROT_READ) = 0 mprotect(0x7f8ad149c000, 4096, PROT_READ) = 0 mprotect(0x7f8ad2109000, 4096, PROT_READ) = 0 mprotect(0x7f8ad2311000, 4096, PROT_READ) = 0 mprotect(0x7f8ad2515000, 4096, PROT_READ) = 0 mprotect(0x7f8ad273f000, 28672, PROT_READ) = 0 mprotect(0x7f8ad2a6d000, 20480, PROT_READ) = 0 mprotect(0x7f8ad2c9a000, 12288, PROT_READ) = 0 mprotect(0x7f8ad2ef1000, 16384, PROT_READ) = 0 mprotect(0x7f8ad3126000, 4096, PROT_READ) = 0 mprotect(0x7f8ad3335000, 4096, PROT_READ) = 0 mprotect(0x7f8ad3539000, 4096, PROT_READ) = 0 mprotect(0x7f8ad3971000, 114688, PROT_READ) = 0 mprotect(0x7f8ad3fb2000, 4096, PROT_READ) = 0 mprotect(0x7f8ad3ba3000, 4096, PROT_READ) = 0 mprotect(0x7f8ad3dad000, 4096, PROT_READ) = 0 mprotect(0x55b0e3631000, 4096, PROT_READ) = 0 mprotect(0x7f8ad41d5000, 4096, PROT_READ) = 0 munmap(0x7f8ad41c7000, 49694) = 0 set_tid_address(0x7f8ad41b4b50) = 6095 set_robust_list(0x7f8ad41b4b60, 24) = 0 rt_sigaction(SIGRTMIN, {0x7f8ad1cba860, [], SA_RESTORER|SA_SIGINFO, 0x7f8ad1cc3630}, NULL, 8) = 0 rt_sigaction(SIGRT_1, {0x7f8ad1cba8f0, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x7f8ad1cc3630}, NULL, 8) = 0 rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0 getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0 brk(NULL) = 0x55b0e4726000 brk(0x55b0e4747000) = 0x55b0e4747000 access("/etc/system-fips", F_OK) = -1 ENOENT (No such file or directory) statfs("/sys/fs/selinux", 0x7ffc176c6510) = -1 ENOENT (No such file or directory) statfs("/selinux", 0x7ffc176c6510) = -1 ENOENT (No such file or directory) open("/proc/filesystems", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41d3000 read(4, "nodev\tsysfs\nnodev\trootfs\nnodev\tramfs\nnodev\tbdev\nnodev\tproc\nnodev\tcpuset\nnodev\tcgroup\nnodev\tcgroup2\nnodev\ttmpfs\nnodev\tdevtmpfs\nnodev\tconfigfs\nnodev\tdebugfs\nnodev\ttracefs\nnodev\tsecurityfs\nnodev\tsockfs\nnodev\tdax\nnodev\tbpf\nnodev\tpipefs\nnodev\thugetlbfs\nnodev\tdevpts\nnodev\tautofs\nnodev\tpstore\nnodev\tmqueue\n\txfs\nnodev\tbinfmt_misc\nnodev\trpc_pipefs\nnodev\tocfs2_dlmfs\nnodev\tnfs\nnodev\tnfs4\n\tocfs2\n", 1024) = 386 stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 read(4, "", 1024) = 0 close(4) = 0 munmap(0x7f8ad41d3000, 4096) = 0 access("/etc/selinux/config", F_OK) = 0 open("/etc/pki/tls/legacy-settings", O_RDONLY) = -1 ENOENT (No such file or directory) access("/etc/system-fips", F_OK) = -1 ENOENT (No such file or directory) umask(0177) = 0177 fcntl(2, F_GETFL) = 0x402 (flags O_RDWR|O_APPEND) open("/etc/localtime", O_RDONLY|O_CLOEXEC) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 fstat(4, {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41d3000 read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0\6\0\0\0\0\0\0\0x\0\0\0\6\0\0\0\t\312\0025\340\314\347K\20\315\251\27\220\316\242C\20\317\2224\20\320\202%\20\320\372\1p\321\241\214\20\322N@\220\30E_p\30\343\257\220\31\323\240\220\32\303\221\220\33\274\275\20\34\254\256\20\35\234\237\20\36\214\220\20\37|\201\20 lr\20!\c\20"LT\20#<E\20$,6\20%\34'\20&\f\30\20'\5C\220'\3654\220(\345%\220)\325\26\220*\305\7\220+\264\370\220,\244\351\220-\224\332\220.\204\313\220/t\274\2200d\255\2201]\331\0202r\264\0203=\273\0204R\226\0205\35\235\02062x\0206\375\177\0208\33\224\2208\335a\0209\373v\220:\275C\20;\333X\220<\246_\220=\273:\220>\206A\220?\233\34\220@f#\220A\2049\20BF\5\220Cd\33\20D%\347\220EC\375\20F\5\311\220G#\337\20G\356\346\20I\3\301\20I\316\310\20J\343\243\20K\256\252\20L\314\277\220M\216\214\20N\254\241\220Onn\20P\214\203\220QW\212\220Rle\220S7l\220TLG\220U\27N\220V,)\220V\3670\220X\25F\20X\327\22\220Y\365(\20Z\266\364\220[\325\n\20\\240\21\20]\264\354\20^\177\363\20_\224\316 \20`_\325\20a}\352\220b?\267\20c]\314\220d\37\231\20e=\256\220f\10\265\220g\35\220\220g\350\227\220h\375r\220i\310y\220j\335T\220k\250[\220l\306q\20m\210=\220n\246S\20oh\37\220p\2065\20qQ<\20rf\27\20s1\36\20tE\371\20u\21\0\20v/\25\220v\360\342\20x\16\367\220x\320\304\20y\356\331\220z\260\246\20{\316\273\220|\231\302\220}\256\235\220~y\244\220\177\216\177\220\3\1\2\1\2\1\0\2\1\0\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\4\5\0\0\16\20\0\0\0\0\16\20\0\0\0\0\34 \1\4\0\0\34 \1\4\0\0\34 \1\4\0\0\16\20\0\0CET\0CEST\0\0\1\1\0\1\1\0\0\0\0\1\1TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0\0\0\0y\0\0\0\7\0\0\0\r\377\377\377\377^<\360H\377\377\377\377\312\0025\340\377\377\377\377\314\347K\20\377\377\377\377\315\251\27\220\377\377\377\377\316\242C\20\377\377\377\377\317\2224\20\377\377\377\377\320\202%\20\377\37 7\377\377\320\372\1p\377\377\377\377\321\241\214\20\377\377\377\377\322N@\220\0\0\0\0\30E_p\0\0\0\0\30\343\257\220\0\0\0\0\31\323\240\220\0\0\0\0\32\303\221\220\0\0\0\0\33\274\275\20\0\0\0\0\34\254\256\20\0\0\0\0\35\234\237\20\0\0\0\0\36\214\220\20\0\0\0\0\37|\201\20\0\0\0\0 lr\20\0\0\0\0!\c\20\0\0\0\0"LT\20\0\0\0\0#<E\20\0\0\0\0$,6\20\0\0\0\0%\34'\20\0\0\0\0&\f\30\20\0\0\0\0'\5C\220\0\0\0\0'\3654\220\0\0\0\0(\345%\220\0\0\0\0)\325\26\220\0\0\0\0*\305\7\220\0\0\0\0+\264\370\220\0\0\0\0,\244\351\220\0\0\0\0-\224\332\220\0\0\0\0.\204\313"..., 4096) = 1931 lseek(4, -1230, SEEK_CUR) = 701 read(4, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0\0\0\0y\0\0\0\7\0\0\0\r\377\377\377\377^<\360H\377\377\377\377\312\0025\340\377\377\377\377\314\347K\20\377\377\377\377\315\251\27\220\377\377\377\377\316\242C\20\377\377\377\377\317\2224\20\377\377\377\377\320\202%\20\377\377\377\377\320\372\1p\377\377\377\377\321\241\214\20\377\377\377\377\322N@\220\0\0\0\0\30E_p\0\0\0\0\30\343\257\220\0\0\0\0\31\323\240\220\0\0\0\0\32\303\221\220\0\0\0\0\33\274\275\20\0\0\0\0\34\254\256\20\0\0\0\0\35\234\237\20\0\0\0\0\36\214\220\20\0\0\0\0\37|\201\20\0\0\0\0 lr\20\0\0\0\0!\c\20\0\0\0\0"LT\20\0\0\0\0#<E\20\0\0\0\0$,6\20\0\0\0\0%\34'\20\0\0\0\0&\f\30\20\0\0\0\0'\5C\220\0\0\0\0'\3654\220\0\0\0\0(\345%\220\0\0\0\0)\325\26\220\0\0\0\0*\305\7\220\0\0\0\0+\264\370\220\0\0\0\0,\244\351\220\0\0\0\0-\224\332\220\0\0\0\0.\204\313\220\0\0\0\0/t\274\220\0\0\0\0000d\255\220\0\0\0\0001]\331\20\0\0\0\0002r\264\20\0\0\0\0003=\273\20\0\0\0\0004R\226\20\0\0\0\0005\35\235\20\0\0\0\00062x\20\0\0\0\ 0006\375\177\20\0\0\0\0008\33\224\220\0\0\0\0008\335a\20\0\0\0\0009\373v\220\0\0\0\0:\275C\20\0\0\0\0;\333X\220\0\0\0\0<\246_\220\0\0\0\0=\273:\220\0\0\0\0>\206A\220\0\0\0\0?\233\34\220\0\0\0\0@f#\220\0\0\0\0A\2049\20\0\0\0\0BF\5\220\0\0\0\0Cd\33\20\0\0\0\0D%\347\220\0\0\0\0EC\375\20\0\0\0\0F\5\311\220\0\0\0\0G#\337\20\0\0\0\0G\356\346\20\0\0\0\0I\3\301\20\0\0\0\0I\316\310\20\0\0\0\0J\343\243\20\0\0\0\0K\256\252\20\0\0\0\0L\314\277\220\0\0\0\0M\216\214\20\0\0\0\0N\254\241\220\0\0\0\0Onn\20\0\0\0\0P\214\203\220\0\0\0\0QW\212\220\0\0\0\0Rle\220\0\0\0\0S7l\220\0\0\0\0TLG\220\0\0\0\0U\27N\220\0\0\0\0V,)\220\0\0\0\0V\3670\220\0\0\0\0X\25F\20\0\0\0\0X\327\22\220\0\0\0\0Y\365(\20\0\0\0\0Z\266\364\220\0\0\0\0[\325\n\20\0\0\0\0\\240\21\20\0\0\0\0]\264\354\20\0\0\0\0^\177\363\20\0\0\0\0_\224\316\20\0\0\0\0`_\325\20\0\0\0\0a}\352\220\0\0\0\0b?\267\20\0\0\0\0c]\314\220\0\0\0\0d\37\231\20\0\0\0\0e=\256\220\0\0\0\0f\10\265\220\0\0\0\0g\35\220\220\0\0\0\0g\350\227\220\0\0\0\0h\375r\220\0\0\0\0i\3 10y\220\0\0\0\0j\335T\220\0\0\0\0k\250[\220\0\0\0\0l\306q\20\0\0\0\0m\210=\220\0\0\0\0n\246S\20\0\0\0\0oh\37\220\0\0\0\0p\2065\20\0\0\0\0qQ<\20\0\0\0\0rf\27\20\0\0\0\0s1\36\20\0\0\0\0tE\371\20\0\0\0\0u\21\0\20\0\0\0\0v/\25\220\0\0\0\0v\360\342\20\0\0\0\0x\16\367\220\0\0\0\0x\320\304\20\0\0\0\0y\356\331\220\0\0\0\0z\260\246\20\0\0\0\0{\316\273\220\0\0\0\0|\231\302\220\0\0\0\0}\256\235\220\0\0\0\0~y\244\220\0\0\0\0\177\216\177\220\1\4\2\3\2\3\2\1\3\2\1\5"..., 4096) = 1230 close(4) = 0 munmap(0x7f8ad41d3000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 fstat(2, {st_mode=S_IFSOCK|0777, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f8ad41d3000 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [main] (0x0400): p11_child started.\n", 89) = 89 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [main] (0x2000): Running in [verifiy] mode.\n", 97) = 97 getegid() = 0 geteuid() = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [main] (0x2000): Running with effective IDs: [0][0].\n", 106) = 106 getgid() = 0 getuid() = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [main] (0x2000): Running with real IDs [0][0].\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [parse_cert_verify_opts] (0x0020): Found 'no_verification' option, disabling verification completely. This should not be used in production.\n", 194) = 194 write(2, "Cannot run verification with option 'no_verification'.\n", 55) = 55 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 17 14:17:03 2020) [[sssd[p11_child[6095]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
As I can see, errors are the same as before: SELinux missing, p11_child failed with status 1, and p11_child failed with status 256
On Tue, Mar 17, 2020 at 11:17:34AM -0000, Hristina Marosevic wrote: ....
Hi,
I'm sorry, I haven't read one of your earlier emails carefully enough, please do not use "certificate_verification = no_ocsp, no_verification" but only
certificate_verification = no_verification
'no_ocsp' implies verification but without OCSP so using both options is an inconsistency.
bye, Sumit
Besides this, I thought of another scenario which may help me validate the certificate. I can add certificate_verification=no_ocsp instead of certificate_verification=no_verification in [sssd] section of sssd.conf file, and store the trust on the server - in that case, where should I store the trust and is it enought just to provide the root CA certificate, or it is needed to store the intermediate CAs certificates? Also, in which format?
If this won't work, I really have no idea of any other options for testing the PKI based authentication, so if you have any other ideas, I will appreciate if you share it.
Thank you for your help!
On Tue, Mar 17, 2020 at 02:17:06PM -0000, Hristina Marosevic wrote:
On Tue, Mar 17, 2020 at 11:17:34AM -0000, Hristina Marosevic wrote: ....
Hi,
I'm sorry, I haven't read one of your earlier emails carefully enough, please do not use "certificate_verification = no_ocsp, no_verification" but only
certificate_verification = no_verification
'no_ocsp' implies verification but without OCSP so using both options is an inconsistency.
bye, Sumit
Hi,
about 'certificate_verification = no_verification', there is an issue which was fixed by https://pagure.io/SSSD/sssd/c/31ebf912d6426aea446b2bdae919d4e33b0c95be but the fix is not in the build you are using. So better continue with 'certificate_verification = no_ocsp'.
Besides this, I thought of another scenario which may help me validate the certificate. I can add certificate_verification=no_ocsp instead of certificate_verification=no_verification in [sssd] section of sssd.conf file, and store the trust on the server - in that case, where should I store the trust and is it enought just to provide the root CA certificate, or it is needed to store the intermediate CAs certificates? Also, in which format?
Please add all CA certificates to the NSS database /etc/pki/nssdb with the help of the certutil command:
certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d /etc/pki/nssdb
each CA certificate should get an individual nickname. If your CA_cert_file is in PEM format (with BEGIN CERTIFICATE and END CERTIFICATE lines) you might need to add a '-a' option as well.
If there are still issues please send the strace output.
HTH
bye, Sumit
If this won't work, I really have no idea of any other options for testing the PKI based authentication, so if you have any other ideas, I will appreciate if you share it.
Thank you for your help! _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Tue, Mar 17, 2020 at 02:17:06PM -0000, Hristina Marosevic wrote:
Hi,
about 'certificate_verification = no_verification', there is an issue which was fixed by https://pagure.io/SSSD/sssd/c/31ebf912d6426aea446b2bdae919d4e33b0c95be but the fix is not in the build you are using. So better continue with 'certificate_verification = no_ocsp'.
Please add all CA certificates to the NSS database /etc/pki/nssdb with the help of the certutil command:
certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d
/etc/pki/nssdb
each CA certificate should get an individual nickname. If your CA_cert_file is in PEM format (with BEGIN CERTIFICATE and END CERTIFICATE lines) you might need to add a '-a' option as well.
If there are still issues please send the strace output.
HTH
bye, Sumit
Hello,
I just tried to add the certificates (intermediate and root CA) to the database and I got the error: "certutil: function failed: SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in an old, unsupported format." for each one.
The confirugation in sssd is still not changed and no other step is executed due to this error. I think it is important to solve this problem first, and that this one is not related to the sssd configuration and option certificate_verification in the config file. Can you propose me a solution for this?
BR, Hristina
On Wed, Mar 18, 2020 at 10:42:52AM -0000, Hristina Marosevic wrote:
On Tue, Mar 17, 2020 at 02:17:06PM -0000, Hristina Marosevic wrote:
Hi,
about 'certificate_verification = no_verification', there is an issue which was fixed by https://pagure.io/SSSD/sssd/c/31ebf912d6426aea446b2bdae919d4e33b0c95be but the fix is not in the build you are using. So better continue with 'certificate_verification = no_ocsp'.
Please add all CA certificates to the NSS database /etc/pki/nssdb with the help of the certutil command:
certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d
/etc/pki/nssdb
each CA certificate should get an individual nickname. If your CA_cert_file is in PEM format (with BEGIN CERTIFICATE and END CERTIFICATE lines) you might need to add a '-a' option as well.
If there are still issues please send the strace output.
HTH
bye, Sumit
Hello,
I just tried to add the certificates (intermediate and root CA) to the database and I got the error: "certutil: function failed: SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in an old, unsupported format." for each one.
Hi,
can you send the output of
ls -al /etc/pki/nssdb
and
certutil -L -d /etc/pki/nssdb -h all
bye, Sumit
The confirugation in sssd is still not changed and no other step is executed due to this error. I think it is important to solve this problem first, and that this one is not related to the sssd configuration and option certificate_verification in the config file. Can you propose me a solution for this?
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Wed, Mar 18, 2020 at 10:42:52AM -0000, Hristina Marosevic wrote:
Hi,
can you send the output of
ls -al /etc/pki/nssdb
and
certutil -L -d /etc/pki/nssdb -h all
bye, Sumit
Hello Sumit,
Somehow, today I didn't get any error when executing certutil command. In meanwhile I didn't do anything different, except for the sssd and sshd restart. Few days ago, I couldn't add nor list the existing certificates in the nssdb using certutil. Now, when this is working, I added the two CA certs in the chain of the user's public certificate. One is intermediate, and one is root CA. Too add the intermediate and root CA certs in the nssdb, I used der fomrats of the certificates and the following command for each one of them: certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d /etc/pki/nssdb
You asked me to list the nssdb directory. Here is the result: $ ls -al /etc/pki/nssdb total 132 drwxr-xr-x. 2 root root 4096 Mar 6 10:34 . drwxr-xr-x. 10 root root 4096 Jan 24 2019 .. -rw-r--r-- 1 root root 65536 Aug 7 2019 cert8.db -rw-r--r--. 1 root root 9216 Jan 24 2019 cert9.db -rw-r--r-- 1 root root 0 Mar 6 10:34 i#uiap -rw-r--r-- 1 root root 16384 Aug 7 2019 key3.db -rw-r--r--. 1 root root 11264 Jan 24 2019 key4.db -rw-r--r-- 1 root root 451 Aug 7 2019 pkcs11.txt -rw-r--r-- 1 root root 16384 Aug 7 2019 secmod.db
After adding the certificates from the chain of the user's public certificate, following command: certutil -L -d /etc/pki/nssdb -h all resulted with:
Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI
root_KZ C,C,C intermediate_KZ C,C,C
In the sssd section of the sssd.conf file the value for certificate_verification is no_ocsp. Using strace, recorded log of the p11_child about the pki authentication attempt is:
..... stat("/home/oracle/secmod.db", 0x7ffcf6ee2350) = -1 ENOENT (No such file or directory) open("/home/oracle/secmod.db", O_RDONLY) = -1 ENOENT (No such file or directory) open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/home/oracle/cert8.db", 0x7ffcf6ee1f30) = -1 ENOENT (No such file or directory) open("/home/oracle/cert8.db", O_RDONLY) = -1 ENOENT (No such file or directory) stat("/home/oracle/cert7.db", 0x7ffcf6ee1f50) = -1 ENOENT (No such file or directory) open("/home/oracle/cert7.db", O_RDONLY) = -1 ENOENT (No such file or directory) access("/etc/pki/nss-legacy/nss-rhel7.config", R_OK) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/etc/pki/nss-legacy/nss-rhel7.config", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=257, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257 stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 read(4, "", 4096) = 0 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_verification] (0x0040): Certificate [(null)][givenName=\320\242\320\225\320\241\320\242\320\242\320\236\320\222\320\230\320\247,ST=\320\220\320\241\320\242\320\220\320\235\320\220,L=\320\220\320\241\320\242\320\220\320\235\320\220,C=KZ,serialNumber=IIN123456789012,SN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222,CN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222 \320\242\320\225\320\241\320\242\320\242] not valid [-8179][Peer's Certificate issuer is not recognized.].\n", 309) = 309 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 99) = 99 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0040): do_work failed.\n", 86) = 86 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
"Peer's Certificate issuer is not recognized" - why is this appearing in the logs if the CA certs are already imported in the nssdb?
This line is also not clear to me: "mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257" What is it about?
Thank you for your help! Hristina M.
On Tue, Mar 24, 2020 at 02:20:17PM -0000, Hristina Marosevic wrote:
On Wed, Mar 18, 2020 at 10:42:52AM -0000, Hristina Marosevic wrote:
Hi,
can you send the output of
ls -al /etc/pki/nssdb
and
certutil -L -d /etc/pki/nssdb -h all
bye, Sumit
Hello Sumit,
Somehow, today I didn't get any error when executing certutil command. In meanwhile I didn't do anything different, except for the sssd and sshd restart. Few days ago, I couldn't add nor list the existing certificates in the nssdb using certutil. Now, when this is working, I added the two CA certs in the chain of the user's public certificate. One is intermediate, and one is root CA. Too add the intermediate and root CA certs in the nssdb, I used der fomrats of the certificates and the following command for each one of them: certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d /etc/pki/nssdb
Hi,
please try to add them with
certutil -A -n "CA cert nickname" -t CT,C,C -i /path/to/CA_cert_file -d /etc/pki/nssdb
(please note the additional 'T' for 'trusted CA for client authentication') and check if this makes a difference.
bye, Sumit
You asked me to list the nssdb directory. Here is the result: $ ls -al /etc/pki/nssdb total 132 drwxr-xr-x. 2 root root 4096 Mar 6 10:34 . drwxr-xr-x. 10 root root 4096 Jan 24 2019 .. -rw-r--r-- 1 root root 65536 Aug 7 2019 cert8.db -rw-r--r--. 1 root root 9216 Jan 24 2019 cert9.db -rw-r--r-- 1 root root 0 Mar 6 10:34 i#uiap -rw-r--r-- 1 root root 16384 Aug 7 2019 key3.db -rw-r--r--. 1 root root 11264 Jan 24 2019 key4.db -rw-r--r-- 1 root root 451 Aug 7 2019 pkcs11.txt -rw-r--r-- 1 root root 16384 Aug 7 2019 secmod.db
After adding the certificates from the chain of the user's public certificate, following command: certutil -L -d /etc/pki/nssdb -h all resulted with:
Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI
root_KZ C,C,C intermediate_KZ C,C,C
In the sssd section of the sssd.conf file the value for certificate_verification is no_ocsp. Using strace, recorded log of the p11_child about the pki authentication attempt is:
..... stat("/home/oracle/secmod.db", 0x7ffcf6ee2350) = -1 ENOENT (No such file or directory) open("/home/oracle/secmod.db", O_RDONLY) = -1 ENOENT (No such file or directory) open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/home/oracle/cert8.db", 0x7ffcf6ee1f30) = -1 ENOENT (No such file or directory) open("/home/oracle/cert8.db", O_RDONLY) = -1 ENOENT (No such file or directory) stat("/home/oracle/cert7.db", 0x7ffcf6ee1f50) = -1 ENOENT (No such file or directory) open("/home/oracle/cert7.db", O_RDONLY) = -1 ENOENT (No such file or directory) access("/etc/pki/nss-legacy/nss-rhel7.config", R_OK) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/etc/pki/nss-legacy/nss-rhel7.config", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=257, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257 stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 read(4, "", 4096) = 0 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_verification] (0x0040): Certificate [(null)][givenName=\320\242\320\225\320\241\320\242\320\242\320\236\320\222\320\230\320\247,ST=\320\220\320\241\320\242\320\220\320\235\320\220,L=\320\220\320\241\320\242\320\220\320\235\320\220,C=KZ,serialNumber=IIN123456789012,SN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222,CN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222 \320\242\320\225\320\241\320\242\320\242] not valid [-8179][Peer's Certificate issuer is not recognized.].\n", 309) = 309 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 99) = 99 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0040): do_work failed.\n", 86) = 86 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
"Peer's Certificate issuer is not recognized" - why is this appearing in the logs if the CA certs are already imported in the nssdb?
This line is also not clear to me: "mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257" What is it about?
Thank you for your help! Hristina M. _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Tue, Mar 24, 2020 at 02:20:17PM -0000, Hristina Marosevic wrote:
Hi,
please try to add them with
certutil -A -n "CA cert nickname" -t CT,C,C -i /path/to/CA_cert_file -d
/etc/pki/nssdb
(please note the additional 'T' for 'trusted CA for client authentication') and check if this makes a difference.
bye, Sumit
Hello,
I got the same error: write(2, "(Tue Mar 24 15:56:24 2020) [[sssd[p11_child[28171]]]] [do_verification] (0x0040): Certificate [(null)][givenName=\320\242\320\225\320\241\320\242\320\242\320\236\320\222\320\230\320\247,ST=\320\220\320\241\320\242\320\220\320\235\320\220,L=\320\220\320\241\320\242\320\220\320\235\320\220,C=KZ,serialNumber=IIN123456789012,SN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222,CN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222 \320\242\320\225\320\241\320\242\320\242] not valid [-8179][Peer's Certificate issuer is not recognized.].\n", 310) = 310 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 15:56:24 2020) [[sssd[p11_child[28171]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 15:56:24 2020) [[sssd[p11_child[28171]]]] [main] (0x0040): do_work failed.\n", 87) = 87 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 15:56:24 2020) [[sssd[p11_child[28171]]]] [main] (0x0020): p11_child failed!\n", 89) = 89 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
What I did is: added the CA certs once again, as trusted:
certutil -L -d /etc/pki/nssdb -h all Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI
root_KZ CT,C,C intermediate_KZ CT,C,C
and stoppped sssd, emptyed its cache, started sssd, restarted sshd, afterwards.
BR, Hristina M.
On Tue, Mar 24, 2020 at 02:20:17PM -0000, Hristina Marosevic wrote:
On Wed, Mar 18, 2020 at 10:42:52AM -0000, Hristina Marosevic wrote:
Hi,
can you send the output of
ls -al /etc/pki/nssdb
and
certutil -L -d /etc/pki/nssdb -h all
bye, Sumit
Hello Sumit,
Somehow, today I didn't get any error when executing certutil command. In meanwhile I didn't do anything different, except for the sssd and sshd restart. Few days ago, I couldn't add nor list the existing certificates in the nssdb using certutil. Now, when this is working, I added the two CA certs in the chain of the user's public certificate. One is intermediate, and one is root CA. Too add the intermediate and root CA certs in the nssdb, I used der fomrats of the certificates and the following command for each one of them: certutil -A -n "CA cert nickname" -t C,C,C -i /path/to/CA_cert_file -d /etc/pki/nssdb
You asked me to list the nssdb directory. Here is the result: $ ls -al /etc/pki/nssdb total 132 drwxr-xr-x. 2 root root 4096 Mar 6 10:34 . drwxr-xr-x. 10 root root 4096 Jan 24 2019 .. -rw-r--r-- 1 root root 65536 Aug 7 2019 cert8.db -rw-r--r--. 1 root root 9216 Jan 24 2019 cert9.db -rw-r--r-- 1 root root 0 Mar 6 10:34 i#uiap -rw-r--r-- 1 root root 16384 Aug 7 2019 key3.db -rw-r--r--. 1 root root 11264 Jan 24 2019 key4.db -rw-r--r-- 1 root root 451 Aug 7 2019 pkcs11.txt -rw-r--r-- 1 root root 16384 Aug 7 2019 secmod.db
After adding the certificates from the chain of the user's public certificate, following command: certutil -L -d /etc/pki/nssdb -h all resulted with:
Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI
root_KZ C,C,C intermediate_KZ C,C,C
In the sssd section of the sssd.conf file the value for certificate_verification is no_ocsp. Using strace, recorded log of the p11_child about the pki authentication attempt is:
..... stat("/home/oracle/secmod.db", 0x7ffcf6ee2350) = -1 ENOENT (No such file or directory) open("/home/oracle/secmod.db", O_RDONLY) = -1 ENOENT (No such file or directory) open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/home/oracle/cert8.db", 0x7ffcf6ee1f30) = -1 ENOENT (No such file or directory) open("/home/oracle/cert8.db", O_RDONLY) = -1 ENOENT (No such file or directory) stat("/home/oracle/cert7.db", 0x7ffcf6ee1f50) = -1 ENOENT (No such file or directory) open("/home/oracle/cert7.db", O_RDONLY) = -1 ENOENT (No such file or directory)
Hi,
did you change the 'ca_db' option in sssd.conf? If looks like a wrong path '/home/oracle' is used for the NSS database.
bye, Sumit
access("/etc/pki/nss-legacy/nss-rhel7.config", R_OK) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/etc/pki/nss-legacy/nss-rhel7.config", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0644, st_size=257, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257 stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0 read(4, "", 4096) = 0 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 open("/proc/sys/crypto/fips_enabled", O_RDONLY) = 4 fstat(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "0\n", 1024) = 2 close(4) = 0 munmap(0x7f2379ad3000, 4096) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_verification] (0x0040): Certificate [(null)][givenName=\320\242\320\225\320\241\320\242\320\242\320\236\320\222\320\230\320\247,ST=\320\220\320\241\320\242\320\220\320\235\320\220,L=\320\220\320\241\320\242\320\220\320\235\320\220,C=KZ,serialNumber=IIN123456789012,SN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222,CN=\320\242\320\225\320\241\320\242\320\242\320\236\320\222 \320\242\320\225\320\241\320\242\320\242] not valid [-8179][Peer's Certificate issuer is not recognized.].\n", 309) = 309 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 99) = 99 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0040): do_work failed.\n", 86) = 86 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Tue Mar 24 13:36:19 2020) [[sssd[p11_child[5538]]]] [main] (0x0020): p11_child failed!\n", 88) = 88 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
"Peer's Certificate issuer is not recognized" - why is this appearing in the logs if the CA certs are already imported in the nssdb?
This line is also not clear to me: "mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2379ad3000 read(4, "# To re-enable legacy algorithms, edit this file\n# Note that the last empty line in this file must be preserved\nlibrary=\nname=Policy\nNSS=flags=policyOnly,moduleDB\nconfig="disallow=MD5:RC4 allow=DH-MIN=1023:DSA-MIN=1023:RSA-MIN=1023:TLS-VERSION-MIN=tls1.0"\n\n", 4096) = 257" What is it about?
Thank you for your help! Hristina M. _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Tue, Mar 24, 2020 at 02:20:17PM -0000, Hristina Marosevic wrote:
Hi,
did you change the 'ca_db' option in sssd.conf? If looks like a wrong path '/home/oracle' is used for the NSS database.
bye, Sumit
Hello,
It was anold configuration - thank you for noticing! After deleting the ca_db option value from the sssd configuration i.e. now, when it has the default value - /etc/pki/nssdb user authentication passed successfully.
/var/log/sssd/sssd_ssh.log ... (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [20372]. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x0100): child [20372] finished successfully. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x1000): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is valid. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected! (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x561dbac3a190][18]
p11_child-log # log file 2... write(2, "(Wed Mar 25 11:34:44 2020) [[sssd[p11_child[20372]]]] [do_work] (0x0400): Certificate is valid.\n", 96) = 96 # log file 1... write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [20372].\n", 96) = 96 wait4(20372, [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], WNOHANG, NULL) = 20372 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x0100): child [20372] finished successfully.\n", 106) = 106 close(19) = 0 close(22) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x1000): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DV nBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735"..., 2217) = 2217 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=3133374048, u64=94685687414368}}) = 0 rt_sigaction(SIGCHLD, {SIG_DFL, [], SA_RESTORER, 0x7f78689db630}, NULL, 8) = 0 epoll_wait(0, [{EPOLLIN, {u32=3133299888, u64=94685687340208}}], 1, 2897) = 1 read(3, "\1\0\0\0\0\0\0\0", 8) = 8 epoll_wait(0, [{EPOLLOUT, {u32=3133374048, u64=94685687414368}}], 1, 2897) = 1 sendto(18, "O\1\0\0\341\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\24\0\0\0IIN32000000001@ldap\0\27\1\0\0\0\0\0\7ssh-rsa\0\0\0\3\1\0\1\0\0\1\1\0\217d^\332\27127N?\356\256zW\355\206\306\3368P\253\214\364\35\312\226\360\2208\10\241\2534\347\201I\274\241\340}\177Z\245Q\357l\312\315+\277\332\264S\33~\273\365\203\26\313\250Y\7>\316\177\273gC\243\201\226ff\3\34\205\222E\24\325\225Q(TrU`s\231?\30\250\350\336\265\326\230\22\276\37\365\310\316Wm\204J\323\311\n\27\231\233,\214D\303\255\22507\331\324;\255`Kr:d,T\31\204\211\333\234~IPA.\211T\312]\236q\r\34\351,%M\307\365E\310\274G\200\370\337\277I\2268jw\265P\201E\211\346[\3776\244\347/`d-H\226\354/\322\362"\313\211YSs%d\32\332\376 \254\327\3678+\226;\254\10\210\366\211rv\r\266\364m4p\255{\23\342p\236\342h)\240\217\30\26\261B\202\311\245H\24\331\376I8\21\363\\345\347\331k\231\360\303", 335, 0, NULL, 0) = 335 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7f9b7d50) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=3133374048, u64=94685687414368}}) = 0 epoll_wait(0, [{EPOLLIN|EPOLLHUP, {u32=3133374048, u64=94685687414368}}], 1, 2887) = 1 recvfrom(18, "", 1536, 0, NULL, NULL) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected!\n", 84) = 84 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7f9b7cf0) = 0 close(18) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x561dbac3a190][18]\n", 106) = 106 epoll_wait(0, [], 1, 2764) = 0 epoll_wait(0, 0x7ffe7f9b7e30, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=1828663392, ptr=0x7f786cff3060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, <detached ...>
During user authentication, /var/log/sssd/sssd_LDAP.log logged successful mapping of the user certificate to the attributes of the specific user and a successful authentication.
Also, /usr/bin/sss_ssh_authorizedkeys IIN32000000001 after loging out the user outputed the pulic key of the user IIN32000000001 and the /var/log/sssd/sssd_ssh.log logged valid certificate.
Thank you!!
Next step is to try authentication with expired certificate. If I approach some problems, I will let you know.
BR, Hristina M.
On Wed, Mar 25, 2020 at 10:49:55AM -0000, Hristina Marosevic wrote:
On Tue, Mar 24, 2020 at 02:20:17PM -0000, Hristina Marosevic wrote:
Hi,
did you change the 'ca_db' option in sssd.conf? If looks like a wrong path '/home/oracle' is used for the NSS database.
bye, Sumit
Hello,
It was anold configuration - thank you for noticing! After deleting the ca_db option value from the sssd configuration i.e. now, when it has the default value - /etc/pki/nssdb user authentication passed successfully.
/var/log/sssd/sssd_ssh.log ... (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [20372]. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x0100): child [20372] finished successfully. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x1000): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVo q80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMFUwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sK v2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=] is valid. (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected! (Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x561dbac3a190][18]
p11_child-log # log file 2... write(2, "(Wed Mar 25 11:34:44 2020) [[sssd[p11_child[20372]]]] [do_work] (0x0400): Certificate is valid.\n", 96) = 96 # log file 1... write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x1000): Waiting for child [20372].\n", 96) = 96 wait4(20372, [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], WNOHANG, NULL) = 20372 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [child_sig_handler] (0x0100): child [20372] finished successfully.\n", 106) = 106 close(19) = 0 close(22) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [cert_to_ssh_key_done] (0x1000): Certificate [MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DV nBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735"..., 2217) = 2217 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [ssh_protocol_done] (0x4000): Sending reply: success\n", 92) = 92 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLOUT|EPOLLERR|EPOLLHUP, {u32=3133374048, u64=94685687414368}}) = 0 rt_sigaction(SIGCHLD, {SIG_DFL, [], SA_RESTORER, 0x7f78689db630}, NULL, 8) = 0 epoll_wait(0, [{EPOLLIN, {u32=3133299888, u64=94685687340208}}], 1, 2897) = 1 read(3, "\1\0\0\0\0\0\0\0", 8) = 8 epoll_wait(0, [{EPOLLOUT, {u32=3133374048, u64=94685687414368}}], 1, 2897) = 1 sendto(18, "O\1\0\0\341\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\24\0\0\0IIN32000000001@ldap\0\27\1\0\0\0\0\0\7ssh-rsa\0\0\0\3\1\0\1\0\0\1\1\0\217d^\332\27127N?\356\256zW\355\206\306\3368P\253\214\364\35\312\226\360\2208\10\241\2534\347\201I\274\241\340}\177Z\245Q\357l\312\315+\277\332\264S\33~\273\365\203\26\313\250Y\7>\316\177\273gC\243\201\226ff\3\34\205\222E\24\325\225Q(TrU`s\231?\30\250\350\336\265\326\230\22\276\37\365\310\316Wm\204J\323\311\n\27\231\233,\214D\303\255\22507\331\324;\255`Kr:d,T\31\204\211\333\234~IPA.\211T\312]\236q\r\34\351,%M\307\365E\310\274G\200\370\337\277I\2268jw\265P\201E\211\346[\3776\244\347/`d-H\226\354/\322\362"\313\211YSs%d\32\332\376 \254\327\3678+\226;\254\10\210\366\211rv\r\266\364m4p\255{\23\342p\236\342h)\240\217\30\26\261B\202\311\245H\24\331\376I8\21\363\\345\347\331k\231\360\303", 335, 0, NULL, 0) = 335 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7f9b7d50) = 0 epoll_ctl(0, EPOLL_CTL_ADD, 18, {EPOLLIN|EPOLLERR|EPOLLHUP, {u32=3133374048, u64=94685687414368}}) = 0 epoll_wait(0, [{EPOLLIN|EPOLLHUP, {u32=3133374048, u64=94685687414368}}], 1, 2887) = 1 recvfrom(18, "", 1536, 0, NULL, NULL) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_recv] (0x0200): Client disconnected!\n", 84) = 84 epoll_ctl(0, EPOLL_CTL_DEL, 18, 0x7ffe7f9b7cf0) = 0 close(18) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(7, "(Wed Mar 25 11:34:44 2020) [sssd[ssh]] [client_close_fn] (0x2000): Terminated client [0x561dbac3a190][18]\n", 106) = 106 epoll_wait(0, [], 1, 2764) = 0 epoll_wait(0, 0x7ffe7f9b7e30, 1, 10000) = -1 EINTR (Interrupted system call) --- SIGRT_2 {si_signo=SIGRT_2, si_code=SI_TIMER, si_timerid=0, si_overrun=0, si_value={int=1828663392, ptr=0x7f786cff3060}} --- rt_sigreturn({mask=[INT FPE USR1 USR2 PIPE]}) = -1 EINTR (Interrupted system call) epoll_wait(0, <detached ...>
During user authentication, /var/log/sssd/sssd_LDAP.log logged successful mapping of the user certificate to the attributes of the specific user and a successful authentication.
Also, /usr/bin/sss_ssh_authorizedkeys IIN32000000001 after loging out the user outputed the pulic key of the user IIN32000000001 and the /var/log/sssd/sssd_ssh.log logged valid certificate.
Thank you!!
Hi,
glad to hear it is working now. Thanks for your patience.
bye, Sumit
Next step is to try authentication with expired certificate. If I approach some problems, I will let you know.
BR, Hristina M. _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
On Wed, Mar 25, 2020 at 10:49:55AM -0000, Hristina Marosevic wrote:
Hi,
glad to hear it is working now. Thanks for your patience.
bye, Sumit
Hello,
As I was planning, I tried to login with an expired certificate and the authentication failed with error: write(2, "(Wed Mar 25 16:28:59 2020) [[sssd[p11_child[10489]]]] [do_verification] (0x0040): Certificate [(null)][CN=test_sssd,.....] not valid [-8181][Peer's Certificate has expired.].\n", 194) = 194 I also, in some way tested authentication using certificate signed by untrusted authorities i.e. when the root and intermediate CA certificates were not imported correctly I got the error: " Certificate not valid. .....Peer's Certificate is not recognized" This seems to be working properly.
The last scenario which I would like to test is CRL status, but if possiible using offline CRL list instead of OCSP responder. I guess certificate_verification=no_ocsp stays in the sssd section of the sssd configuration, but what else should I do to make sssd chek the revocation status of a user certificate using an offline CRL list, stored somewhere on the machine? This is like that because our lab environment is not connected to internet, and I can not use the OCSP URL given in the user's certificate. Is this workaround possible?
BR, Hristina
On Thu, Mar 26, 2020 at 08:16:31AM -0000, Hristina Marosevic wrote:
On Wed, Mar 25, 2020 at 10:49:55AM -0000, Hristina Marosevic wrote:
Hi,
glad to hear it is working now. Thanks for your patience.
bye, Sumit
Hello,
As I was planning, I tried to login with an expired certificate and the authentication failed with error: write(2, "(Wed Mar 25 16:28:59 2020) [[sssd[p11_child[10489]]]] [do_verification] (0x0040): Certificate [(null)][CN=test_sssd,.....] not valid [-8181][Peer's Certificate has expired.].\n", 194) = 194 I also, in some way tested authentication using certificate signed by untrusted authorities i.e. when the root and intermediate CA certificates were not imported correctly I got the error: " Certificate not valid. .....Peer's Certificate is not recognized" This seems to be working properly.
The last scenario which I would like to test is CRL status, but if possiible using offline CRL list instead of OCSP responder. I guess certificate_verification=no_ocsp stays in the sssd section of the sssd configuration, but what else should I do to make sssd chek the revocation status of a user certificate using an offline CRL list, stored somewhere on the machine? This is like that because our lab environment is not connected to internet, and I can not use the OCSP URL given in the user's certificate. Is this workaround possible?
Hi,
please use crlutil to import a CRL into the NSS database, see man crlutil for details.
HTH
bye, Sumit
BR, Hristina
sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
I successfuly added the CRL list into nssdb. CRL list is in DER format. So, I tested the last scenario, which was vaidation of the revoked user certificate used for authenticatiion using offline CRL list instead of using OCSP. So, just giving info about this: In the [sssd] section of the sssd.conf file, option certificate_validation has value "no_ocsp" and in the log file recorded using strace, this lines were generated: write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [do_verification] (0x0040): Certificate [(null)][CN=test_sssd_revoked.....] not valid [-8102][Certificate key usage inadequate for attempted operation.].\n", 228) = 228 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [main] (0x0040): do_work failed.\n", 87) = 87 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [main] (0x0020): p11_child failed!\n", 89) = 89 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
So, the authentication did not pass, which was excpected. Please confirm that this is the answer that the p11_child should give in case of revoked user certificate. If it is like that, by this step I can confirm that SSSD PKI authentication works properly i.e successfuly verifies trust/time validity/revocation status of the user certificate.
BR, Hristina
On Mon, Mar 30, 2020 at 02:22:44PM -0000, Hristina Marosevic wrote:
Hello,
I successfuly added the CRL list into nssdb. CRL list is in DER format. So, I tested the last scenario, which was vaidation of the revoked user certificate used for authenticatiion using offline CRL list instead of using OCSP. So, just giving info about this: In the [sssd] section of the sssd.conf file, option certificate_validation has value "no_ocsp" and in the log file recorded using strace, this lines were generated: write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [do_verification] (0x0040): Certificate [(null)][CN=test_sssd_revoked.....] not valid [-8102][Certificate key usage inadequate for attempted operation.].\n", 228) = 228 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [do_work] (0x0400): Certificate is NOT valid.\n", 100) = 100 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [main] (0x0040): do_work failed.\n", 87) = 87 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=1931, ...}) = 0 write(2, "(Mon Mar 30 16:12:12 2020) [[sssd[p11_child[25761]]]] [main] (0x0020): p11_child failed!\n", 89) = 89 close(1) = 0 exit_group(1) = ? +++ exited with 1 +++
So, the authentication did not pass, which was excpected. Please confirm that this is the answer that the p11_child should give in case of revoked user certificate.
Hi,
yes, in the way SSSD is using NSS '[-8102][Certificate key usage inadequate for attempted operation.]' is often returned instead of a more specific error message when certificate validation fails.
bye, Sumit
If it is like that, by this step I can confirm that SSSD PKI authentication works properly i.e successfuly verifies trust/time validity/revocation status of the user certificate.
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
Hello,
Okay. That concludes al of the test cases as successful. Thank you for your support once again!
BR, Hristina
On Fri, Mar 06, 2020 at 08:09:59AM -0000, Hristina Marosevic wrote:
Hi,
this looks like some progress. Please check p11_child.log which might contain detail why SSSD thinks the certificate is not valid. By default SSSD will check the certificate with the help of the CA certificates and does OCSP if the certificate contains the needed OCSP data.
To disable OCSP, since your system cannot reach the OCSP responder, please add
certificate_verification = no_ocsp
to the [sssd] section of sssd.conf and restart SSSD. For testing you can even use 'no_verification' but this is should not be used in production (see man sssd.conf for details).
Which version of SSSD are you using? Depending on the version you might have to add the CA certificates to different locations, please check the 'ca_db' option described in man sssd.conf for details as well.
bye, Sumit
Can you please check the comment bellow? (I didn't quote your text there, so I am not sure if you got a notification for my comment)
BR, Hristina
On Thu, Mar 05, 2020 at 07:16:45AM -0000, Hristina Marosevic wrote:
Hello,
By using ldapmodify command and ldif file as input.
# ldif file: dn: uid=32000000001,<users_branch,suffix> changetype: modify add: userCertificate;binary userCertificate;binary: MIIGMTCCBBmgAwIBAgIUfYWZ212wMteK0jjnnXd6dqlqkIkwDQYJKoZIhvcNAQELBQAwLTELMAkGA1UEBhMCS1oxHjAcBgNVBAMMFdKw0JrQniAzLjAgKFJTQSBURVNUKTAeFw0xOTA0MDQwODU0NTRaFw0yMTA0MDMwODU0NTRaMIGvMSIwIAYDVQQDDBnQotCV0KHQotCi0J7QkiDQotCV0KHQotCiMRcwFQYDVQQEDA7QotCV0KHQotCi0J7QkjEYMBYGA1UEBRMPSUlOMTIzNDU2Nzg5MDEyMQswCQYDVQQGEwJLWjEVMBMGA1UEBwwM0JDQodCi0JDQndCQMRUwEwYDVQQIDAzQkNCh0KLQkNCd0JAxGzAZBgNVBCoMEtCi0JXQodCi0KLQntCS0JjQpzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI9kXtq5MjdOP+6uelfthsbeOFCrjPQdypbwkDgIoas054FJvKHgfX9apVHvbMrNK7/atFMbfrv1gxbLqFkHPs5/u2dDo4GWZmYDHIWSRRTVlVEoVHJVYHOZPxio6N611pgSvh/1yM5XbYRK08kKF5mbLIxEw62VMDfZ1DutYEtyOmQsVBmEiducfklQQS6JVMpdnnENHOksJU3H9UXIvEeA+N+/SZY4ane1UIFFieZb/zak5y9gZC1Iluwv0vIiy4lZU3MlZBra/iCs1/c4K5Y7rAiI9olydg229G00cK17E+JwnuJoKaCPGBaxQoLJpUgU2f5JOBHzXOXn2WuZ8MMCAwEAAaOCAcQwggHAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKoMOAwMEAQEwHwYDVR0jBBgwFoAUpowWM3y46DVnBj5eQVdVoq80UGgwHQYDVR0OBBYEFLoJ735qnU1Q4y8AEtPdJI2lqQVfMF4GA1UdIARXMF UwUwYHKoMOAwMCBDBIMCEGCCsGAQUFBwIBFhVodHRwOi8vcGtpLmdvdi5rei9jcHMwIwYIKwYBBQUHAgIwFwwVaHR0cDovL3BraS5nb3Yua3ovY3BzMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovY3JsL25jYV9yc2FfdGVzdC5jcmwwPgYDVR0uBDcwNTAzoDGgL4YtaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jcmwvbmNhX2RfcnNhX3Rlc3QuY3JsMHEGCCsGAQUFBwEBBGUwYzA4BggrBgEFBQcwAoYsaHR0cDovL3Rlc3QucGtpLmdvdi5rei9jZXJ0L25jYV9yc2FfdGVzdC5jZXIwJwYIKwYBBQUHMAGGG2h0dHA6Ly90ZXN0LnBraS5nb3Yua3ovb2NzcDANBgkqhkiG9w0BAQsFAAOCAgEACnYpytjbyuV3sRojnlyxEC7HG7BgcDDy6rS/kfOtK6X5+MGCT/zvwksZOumN5Jg5TPdJuKt3ebKJGIBVr474mHFk7Nq0F8WxuAWNffjoL0Lvcuon4Zwq/W8h4t6PYutD4NEauIPEa8X8BGPgMn+YqOc3sfEruXh8rmcSJ/zuT7uw1wD6ZQlNsniioengKIgapDVDHuzoV/r//rEANwIpntAyjXFh+fjx+CDCx2sLxYjlVgyxNzT53mD6ZqsMlg6NrajJe/GvS0A38jKNyxW/DPX06NToWP/hu7M4P2/WiskjKVgOxqQcc4yzTfKV41DmEmGGC7sT1r3YeZ4dH/KQRpjowBOSKmUZq4/XR0yXXhpTDtiiRwXkQgM1p4SKE19bBqGuc76lDgmffPPPj4B+3HZqaprIIDG3YA3/W4rwUoWBQPGGCXpOBvGEQptEHItx4YiEZTQuvdCtlW585kUyol39sKv2uIo/FgycBd8NufOInGCLUgpZec4zVLZN9Shj+M20BMUh+SiGoL/kJAi2XdM 922U3po9a2FbULvJfOlsFY2Z6n+TUZZVXBCUIEE6Ek4tTIGjHWj7uQVGLjw0PcHf11CtrMZO7Y+OTBb/Y0oyUY9JOyzSqhj4rt4nNkzR1vMGVYMNISoXbDgYBaAKuv2oSpG6yQdlufS8M/YWxAWw=
Hi,
you have to load it as a binary. For this frist convert your certificate into DER format with
openssl x509 -in my_cert.cer -outform der -out my_cert.der
and then the ldif should look like
# ldif file: dn: uid=32000000001,<users_branch,suffix> changetype: modify add: userCertificate;binary userCertificate;binary:< file:///path/to/my_cert.der
(see man ldapmodify for details about the file syntax).
bye, Sumit
BR, Hristina _______________________________________________ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.o...
I will try this proposal to check if I get the same error when using the binary format. I will let you know. Thank you for your help!
BR, Hristina
I added the certificate using the ldapmodify option "read from file" and the content for the user certificate retrieved by the ldapsearch on the LDAP server, also the content mapped by SSSD on the sssd client proved that the format of the user certificate was okay. What I get in the sssd_ssh.log is the same errror as before, i.e. "certificate is not valid"
So, now I need to find out only why is this certificate not valid. Is it because of the trust or revocation status that can not be retrieved from the CRL list which can not be downloaded due to the lack of connection to Internet or both.. What is your opinion on this?
BR, Hristina
On Wed, Feb 26, 2020, at 4:38 AM, Hristina Marosevic wrote:
Hello,
I am using SSSD with LDAP directory which provides public keys for each user entry to SSSD. I am not sure if it is possible to configure SSSD not just to accept the private key (provided by the user during the login) and authenticate the user from LDAP (where his public ke is stored), but also to check the:
- trust (validation of the CA used for signing the user's certificate
i.e. public key)
- validity of a user certificate with its public key (its "from" - "to"
dates)
- revocation status (configuration of SSSD with CRL lists or OCSP)
SSSD manages all of these. What it does not manage for SSH is whether the certificate from LDAP actually matches the user, which allows users to grant SSH access "as himself" to anyone else in the organization. (If, as in the case of AD, users can modify their own userCertificate attribute.
or should I manage this on the LDAP side or on application level or somewhere else? I would be grateful if you share your ideas about the possible solutions of this situation!
V/r, James Cassell
Thank you for the explanation!
BR, Hristina
sssd-users@lists.fedorahosted.org