So here’s a more complete snippet from the host
(ipa204) that can’t push to its partner (ipa203):
[23/Mar/2018:04:09:43.460073218
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.460238115
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.460483444
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.460620709
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.460793082
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.460998306
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.461171061
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.461370548
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.461554598
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=dns,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.462223077
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=ad,cn=etc,dc=XXX,dc=net does not exist
[23/Mar/2018:04:09:43.469236418
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=XXX,dc=net does
not exist[23/Mar/2018:04:09:43.469549785 +0000] - ERR -
NSACLPlugin - acl_parse - The ACL target cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=XXX,dc=net does
not exist
[23/Mar/2018:04:09:43.526348986
+0000] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=automember rebuild membership,cn=tasks,cn=config does not
exist
[23/Mar/2018:04:09:43.543200030
+0000] - ERR - schema-compat-plugin - schema-compat-plugin
tree scan will start in about 5 seconds!
[23/Mar/2018:04:09:43.550151255
+0000] - INFO - slapd_daemon - slapd started. Listening on
All Interfaces port 389 for LDAP requests
[23/Mar/2018:04:09:43.550328761
+0000] - INFO - slapd_daemon - Listening on All Interfaces
port 636 for LDAPS requests
[23/Mar/2018:04:09:43.550525479
+0000] - INFO - slapd_daemon - Listening on
/var/run/slapd-XXX-NET.socket for LDAPI requests
[23/Mar/2018:04:09:47.905572763
+0000] - ERR - NSMMReplicationPlugin - bind_and_check_pwp -
agmt="cn=ipa204-to-ipa203" (ipa203:389) - Replication bind
with GSSAPI auth failed: LDAP error 49 (Invalid credentials)
()
[23/Mar/2018:04:09:50.611808868
+0000] - ERR - schema-compat-plugin - warning: no entries
set up under cn=computers, cn=compat,dc=XXX,dc=net
[23/Mar/2018:04:09:50.612281544
+0000] - ERR - schema-compat-plugin - Finished plugin
initialization.