 pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:14:26.193203,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:14:26.193228,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:14:26.193249,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 41 03 00 00   00 00 00 00 11 5B 92 2A   ....A... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.193290,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000341-0000-0000-115b-922ae5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.193378, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 06:14:26.193421,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000341-0000-0000-115b-922ae5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 06:14:26.193610,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 41 03 00 00   00 00 00 00 11 5B 92 2A   ....A... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.193657, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 06:14:26.193679, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 06:14:26.193701,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 06:14:26.193739,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 06:14:26.193772,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 06:14:26.193793, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 06:14:26.193812,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.194133, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 06:14:26.194170,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000341-0000-0000-115b-922ae5090000
[2018/06/01 06:14:26.194233,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 41 03 00 00   00 00 00 00 11 5B 92 2A   ....A... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.194272,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 41 03 00 00   00 00 00 00 11 5B 92 2A   ....A... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.194311,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:14:26.194328,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.194404, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:14:26.194446, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527850705 @ 1527850705]
[2018/06/01 06:14:26.194470,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 06:14:26.194504,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 06:14:26.194526, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 06:14:26.194544, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 06:14:26.194588,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 06:14:26.194622,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 06:14:26.194715,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 06:14:26.194737, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 06:14:26.194759,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 06:14:26.194783,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 06:14:26.194802,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 42 03 00 00   00 00 00 00 11 5B 92 2A   ....B... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.194842,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 06:14:26.194859,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000342-0000-0000-115b-922ae5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.194947,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000342-0000-0000-115b-922ae5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 06:14:26.195145,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 42 03 00 00   00 00 00 00 11 5B 92 2A   ....B... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.195184, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 06:14:26.195204, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 06:14:26.195221,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 06:14:26.195238,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 06:14:26.195260,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 06:14:26.195278,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 43 03 00 00   00 00 00 00 11 5B 92 2A   ....C... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.195317,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 06:14:26.195333,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000343-0000-0000-115b-922ae5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.195416,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000343-0000-0000-115b-922ae5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 06:14:26.195487,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 06:14:26.195505,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 43 03 00 00   00 00 00 00 11 5B 92 2A   ....C... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.195543, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 06:14:26.195562,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 06:14:26.195578,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b112a92 (1527851666)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.195675, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527851666
[2018/06/01 06:14:26.195704,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000343-0000-0000-115b-922ae5090000
[2018/06/01 06:14:26.195766,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 43 03 00 00   00 00 00 00 11 5B 92 2A   ....C... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:26.195804,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:14:26.195820,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.195896, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 06:14:26.195937, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527851666 @ 1527851666]
[2018/06/01 06:14:26.195957, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527851666
[2018/06/01 06:14:26.195987, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 06:14:26.196008,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 06:14:26.196149,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 06:14:26.196167, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 06:14:44.812951,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:14:44.813060, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:14:44.813084,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:14:44.813113, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:14:44.813130,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:14:44.813188,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:14:44.813213, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:14:44.813232, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:14:44.813302,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:14:44.813349,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:14:44.813610, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:14:44.813637,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:14:44.813661,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:14:44.813680,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 44 03 00 00   00 00 00 00 11 5B A4 2A   ....D... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:44.813721,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000344-0000-0000-115b-a42ae5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:44.813816,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000344-0000-0000-115b-a42ae5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:14:44.813917,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000344-0000-0000-115b-a42ae5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:14:44.814000,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 44 03 00 00   00 00 00 00 11 5B A4 2A   ....D... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:44.814068,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:14:44.814168,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000344-0000-0000-115b-a42ae5090000
[2018/06/01 06:14:44.814229,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 44 03 00 00   00 00 00 00 11 5B A4 2A   ....D... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:44.814267,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 44 03 00 00   00 00 00 00 11 5B A4 2A   ....D... .....[.*
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:14:44.814304,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:14:44.814321,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:14:44.814393, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:14:44.814417,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:14:44.814434, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:19:44.833046,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:19:44.833152, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:19:44.833176,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:19:44.833209, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:19:44.833226,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:19:44.833301,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:19:44.833328, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:19:44.833348, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:19:44.833427,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:19:44.833481,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:19:44.833748, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:19:44.833777,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:19:44.833802,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:19:44.833823,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 45 03 00 00   00 00 00 00 11 5B D0 2B   ....E... .....[.+
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:19:44.833865,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000345-0000-0000-115b-d02be5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:19:44.833963,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000345-0000-0000-115b-d02be5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:19:44.834070,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000345-0000-0000-115b-d02be5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:19:44.834156,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 45 03 00 00   00 00 00 00 11 5B D0 2B   ....E... .....[.+
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:19:44.834232,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:19:44.834337,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000345-0000-0000-115b-d02be5090000
[2018/06/01 06:19:44.834403,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 45 03 00 00   00 00 00 00 11 5B D0 2B   ....E... .....[.+
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:19:44.834443,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 45 03 00 00   00 00 00 00 11 5B D0 2B   ....E... .....[.+
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:19:44.834481,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:19:44.834498,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:19:44.834571, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:19:44.834600,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:19:44.834618, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:24:44.834813,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:24:44.834962, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:24:44.834980,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:24:44.835012, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:24:44.835029,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:24:44.835092,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:24:44.835118, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:24:44.835138, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:24:44.835210,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:24:44.835259,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:24:44.835526, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:24:44.835554,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:24:44.835579,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:24:44.835599,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 46 03 00 00   00 00 00 00 11 5B FC 2C   ....F... .....[.,
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:24:44.835643,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000346-0000-0000-115b-fc2ce5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:24:44.835741,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000346-0000-0000-115b-fc2ce5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:24:44.835849,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000346-0000-0000-115b-fc2ce5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:24:44.835935,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 46 03 00 00   00 00 00 00 11 5B FC 2C   ....F... .....[.,
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:24:44.836008,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:24:44.836113,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000346-0000-0000-115b-fc2ce5090000
[2018/06/01 06:24:44.836177,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 46 03 00 00   00 00 00 00 11 5B FC 2C   ....F... .....[.,
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:24:44.836217,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 46 03 00 00   00 00 00 00 11 5B FC 2C   ....F... .....[.,
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:24:44.836255,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:24:44.836272,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:24:44.836346, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:24:44.836372,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:24:44.836389, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:29:44.856243,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:29:44.856353, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:29:44.856376,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:29:44.856407, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:29:44.856424,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:29:44.856495,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:29:44.856521, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:29:44.856540, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:29:44.856617,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:29:44.856668,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:29:44.856931, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:29:44.856960,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:29:44.856984,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:29:44.857004,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 47 03 00 00   00 00 00 00 11 5B 28 2E   ....G... .....[(.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:29:44.857045,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000347-0000-0000-115b-282ee5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:29:44.857138,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000347-0000-0000-115b-282ee5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:29:44.857240,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000347-0000-0000-115b-282ee5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:29:44.857323,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 47 03 00 00   00 00 00 00 11 5B 28 2E   ....G... .....[(.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:29:44.857392,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:29:44.857493,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000347-0000-0000-115b-282ee5090000
[2018/06/01 06:29:44.857555,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 47 03 00 00   00 00 00 00 11 5B 28 2E   ....G... .....[(.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:29:44.857592,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 47 03 00 00   00 00 00 00 11 5B 28 2E   ....G... .....[(.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:29:44.857629,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:29:44.857645,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:29:44.857719, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:29:44.857744,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:29:44.857760, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:30:26.600601, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 06:30:26.600648,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 06:30:26.600667, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 06:30:26.600686, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 06:30:26.600717,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 06:30:26.600817,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 06:30:26.600867,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:30:26.600890, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:30:26.600909, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:30:26.600969,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:30:26.601013,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:30:26.601265, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:30:26.601290,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:30:26.601313,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:30:26.601333,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 48 03 00 00   00 00 00 00 11 5B 52 2E   ....H... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.601373,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000348-0000-0000-115b-522ee5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.601460, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 06:30:26.601500,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000348-0000-0000-115b-522ee5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 06:30:26.601684,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 48 03 00 00   00 00 00 00 11 5B 52 2E   ....H... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.601729, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 06:30:26.601750, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 06:30:26.601771,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 06:30:26.601806,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 06:30:26.601837,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 06:30:26.601857, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 06:30:26.601875,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.602174, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 06:30:26.602208,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000348-0000-0000-115b-522ee5090000
[2018/06/01 06:30:26.602268,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 48 03 00 00   00 00 00 00 11 5B 52 2E   ....H... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.602306,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 48 03 00 00   00 00 00 00 11 5B 52 2E   ....H... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.602342,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:30:26.602359,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.602431, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:30:26.602466, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527851666 @ 1527851666]
[2018/06/01 06:30:26.602487,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 06:30:26.602514,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 06:30:26.602535, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 06:30:26.602552, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 06:30:26.602588,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 06:30:26.602621,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 06:30:26.602711,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 06:30:26.602732, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 06:30:26.602751,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 06:30:26.602773,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 06:30:26.602792,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 49 03 00 00   00 00 00 00 11 5B 52 2E   ....I... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.602831,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 06:30:26.602848,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000349-0000-0000-115b-522ee5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.602931,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000349-0000-0000-115b-522ee5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 06:30:26.603100,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 49 03 00 00   00 00 00 00 11 5B 52 2E   ....I... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.603139, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 06:30:26.603158, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 06:30:26.603176,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 06:30:26.603193,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 06:30:26.603215,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 06:30:26.603233,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 4A 03 00 00   00 00 00 00 11 5B 52 2E   ....J... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.603272,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 06:30:26.603288,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034a-0000-0000-115b-522ee5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.603370,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034a-0000-0000-115b-522ee5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 06:30:26.603474,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 06:30:26.603491,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4A 03 00 00   00 00 00 00 11 5B 52 2E   ....J... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.603529, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 06:30:26.603546,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 06:30:26.603563,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b112e52 (1527852626)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.603659, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527852626
[2018/06/01 06:30:26.603692,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034a-0000-0000-115b-522ee5090000
[2018/06/01 06:30:26.603752,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4A 03 00 00   00 00 00 00 11 5B 52 2E   ....J... .....[R.
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:30:26.603789,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:30:26.603807,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.603878, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 06:30:26.603914, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527852626 @ 1527852626]
[2018/06/01 06:30:26.603934, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527852626
[2018/06/01 06:30:26.603961, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 06:30:26.603981,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 06:30:26.604118,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 06:30:26.604136, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 06:34:44.868697,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:34:44.868823, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:34:44.868841,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:34:44.868872, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:34:44.868889,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:34:44.868955,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:34:44.868980, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:34:44.868999, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:34:44.869071,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:34:44.869120,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:34:44.869376, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:34:44.869404,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:34:44.869428,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:34:44.869448,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 4B 03 00 00   00 00 00 00 11 5B 54 2F   ....K... .....[T/
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:34:44.869489,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034b-0000-0000-115b-542fe5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:34:44.869585,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034b-0000-0000-115b-542fe5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:34:44.869687,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034b-0000-0000-115b-542fe5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:34:44.869769,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4B 03 00 00   00 00 00 00 11 5B 54 2F   ....K... .....[T/
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:34:44.869841,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:34:44.869940,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034b-0000-0000-115b-542fe5090000
[2018/06/01 06:34:44.870001,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4B 03 00 00   00 00 00 00 11 5B 54 2F   ....K... .....[T/
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:34:44.870038,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4B 03 00 00   00 00 00 00 11 5B 54 2F   ....K... .....[T/
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:34:44.870075,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:34:44.870092,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:34:44.870163, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:34:44.870187,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:34:44.870204, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:39:44.873087,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:39:44.873182, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:39:44.873201,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:39:44.873231, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:39:44.873249,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:39:44.873316,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:39:44.873343, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:39:44.873363, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:39:44.873440,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:39:44.873492,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:39:44.873768, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:39:44.873798,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:39:44.873823,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:39:44.873844,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 4C 03 00 00   00 00 00 00 11 5B 80 30   ....L... .....[.0
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:39:44.873887,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034c-0000-0000-115b-8030e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:39:44.873985,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034c-0000-0000-115b-8030e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:39:44.874091,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034c-0000-0000-115b-8030e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:39:44.874180,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4C 03 00 00   00 00 00 00 11 5B 80 30   ....L... .....[.0
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:39:44.874252,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:39:44.874357,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034c-0000-0000-115b-8030e5090000
[2018/06/01 06:39:44.874422,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4C 03 00 00   00 00 00 00 11 5B 80 30   ....L... .....[.0
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:39:44.874462,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4C 03 00 00   00 00 00 00 11 5B 80 30   ....L... .....[.0
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:39:44.874501,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:39:44.874518,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:39:44.874593, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:39:44.874621,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:39:44.874640, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:44:44.873794,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:44:44.873889, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:44:44.873919,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:44:44.873960, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:44:44.873985,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:44:44.874072,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:44:44.874109, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:44:44.874137, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:44:44.874231,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:44:44.874296,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:44:44.874666, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:44:44.874704,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:44:44.874738,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:44:44.874767,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 4D 03 00 00   00 00 00 00 11 5B AC 31   ....M... .....[.1
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:44:44.874830,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034d-0000-0000-115b-ac31e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:44:44.874959,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034d-0000-0000-115b-ac31e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:44:44.875103,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034d-0000-0000-115b-ac31e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:44:44.875224,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4D 03 00 00   00 00 00 00 11 5B AC 31   ....M... .....[.1
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:44:44.875317,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:44:44.875424,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034d-0000-0000-115b-ac31e5090000
[2018/06/01 06:44:44.875489,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4D 03 00 00   00 00 00 00 11 5B AC 31   ....M... .....[.1
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:44:44.875527,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4D 03 00 00   00 00 00 00 11 5B AC 31   ....M... .....[.1
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:44:44.875564,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:44:44.875581,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:44:44.875654, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:44:44.875679,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:44:44.875695, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:46:26.970123, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 06:46:26.970168,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 06:46:26.970187, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 06:46:26.970205, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 06:46:26.970234,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 06:46:26.970331,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 06:46:26.970381,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:46:26.970405, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:46:26.970424, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:46:26.970480,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:46:26.970526,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:46:26.970785, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:46:26.970809,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:46:26.970834,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:46:26.970854,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 4E 03 00 00   00 00 00 00 11 5B 12 32   ....N... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.970894,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034e-0000-0000-115b-1232e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.970982, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 06:46:26.971023,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034e-0000-0000-115b-1232e5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 06:46:26.971208,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4E 03 00 00   00 00 00 00 11 5B 12 32   ....N... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.971252, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 06:46:26.971273, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 06:46:26.971294,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 06:46:26.971328,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 06:46:26.971357,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 06:46:26.971378, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 06:46:26.971396,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.971706, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 06:46:26.971742,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034e-0000-0000-115b-1232e5090000
[2018/06/01 06:46:26.971803,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4E 03 00 00   00 00 00 00 11 5B 12 32   ....N... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.971841,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4E 03 00 00   00 00 00 00 11 5B 12 32   ....N... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.971878,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:46:26.971895,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.971970, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:46:26.972007, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527852626 @ 1527852626]
[2018/06/01 06:46:26.972027,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 06:46:26.972055,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 06:46:26.972076, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 06:46:26.972094, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 06:46:26.972131,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 06:46:26.972163,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 06:46:26.972253,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 06:46:26.972274, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 06:46:26.972292,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 06:46:26.972315,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 06:46:26.972333,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 4F 03 00 00   00 00 00 00 11 5B 12 32   ....O... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.972372,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 06:46:26.972388,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034f-0000-0000-115b-1232e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.972472,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000034f-0000-0000-115b-1232e5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 06:46:26.972644,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 4F 03 00 00   00 00 00 00 11 5B 12 32   ....O... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.972684, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 06:46:26.972702, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 06:46:26.972720,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 06:46:26.972737,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 06:46:26.972759,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 06:46:26.972778,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 50 03 00 00   00 00 00 00 11 5B 12 32   ....P... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.972817,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 06:46:26.972834,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000350-0000-0000-115b-1232e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.972915,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000350-0000-0000-115b-1232e5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 06:46:26.972987,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 06:46:26.973004,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 50 03 00 00   00 00 00 00 11 5B 12 32   ....P... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.973041, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 06:46:26.973059,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 06:46:26.973076,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b113212 (1527853586)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.973171, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527853586
[2018/06/01 06:46:26.973201,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000350-0000-0000-115b-1232e5090000
[2018/06/01 06:46:26.973261,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 50 03 00 00   00 00 00 00 11 5B 12 32   ....P... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:46:26.973300,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:46:26.973316,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.973388, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 06:46:26.973423, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527853586 @ 1527853586]
[2018/06/01 06:46:26.973443, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527853586
[2018/06/01 06:46:26.973470, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 06:46:26.973491,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 06:46:26.973650,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 06:46:26.973680, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 06:49:05.404765, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 06:49:05.404870,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 06:49:05.404896, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 06:49:05.404913, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 06:49:05.404943,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 06:49:05.405037,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 06:49:05.405086,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:49:05.405111, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:49:05.405130, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:49:05.405192,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:49:05.405237,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:49:05.405497, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:49:05.405522,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:49:05.405547,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:49:05.405567,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 51 03 00 00   00 00 00 00 11 5B B1 32   ....Q... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:05.405610,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000351-0000-0000-115b-b132e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:49:05.405695, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 06:49:05.405734,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000351-0000-0000-115b-b132e5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 06:49:05.405919,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 51 03 00 00   00 00 00 00 11 5B B1 32   ....Q... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:05.405963, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 06:49:05.405983, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 06:49:05.406005,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 06:49:05.406038,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 06:49:05.406066,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 06:49:05.406087, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 06:49:05.406106,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 06:49:05.406416, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 06:49:05.406451,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000351-0000-0000-115b-b132e5090000
[2018/06/01 06:49:05.406514,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 51 03 00 00   00 00 00 00 11 5B B1 32   ....Q... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:05.406552,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 51 03 00 00   00 00 00 00 11 5B B1 32   ....Q... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:05.406590,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:49:05.406615,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:49:05.406696, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:49:05.406724, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:554(refresh_sequence_number)
  refresh_sequence_number: LCARS time ok
[2018/06/01 06:49:05.406742, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527853586
[2018/06/01 06:49:05.406775, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 06:49:05.406797,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 06:49:05.406936,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 06:49:05.406954, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 06:49:44.884132,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:49:44.884240, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:49:44.884263,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:49:44.884290, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:49:44.884307,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:49:44.884366,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:49:44.884391, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:49:44.884410, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:49:44.884481,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:49:44.884528,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:49:44.884791, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:49:44.884818,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:49:44.884841,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:49:44.884861,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 52 03 00 00   00 00 00 00 11 5B D8 32   ....R... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:44.884902,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000352-0000-0000-115b-d832e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:49:44.884993,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000352-0000-0000-115b-d832e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:49:44.885092,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000352-0000-0000-115b-d832e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:49:44.885175,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 52 03 00 00   00 00 00 00 11 5B D8 32   ....R... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:44.885242,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:49:44.885341,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000352-0000-0000-115b-d832e5090000
[2018/06/01 06:49:44.885402,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 52 03 00 00   00 00 00 00 11 5B D8 32   ....R... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:44.885441,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 52 03 00 00   00 00 00 00 11 5B D8 32   ....R... .....[.2
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:49:44.885478,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:49:44.885495,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:49:44.885568, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:49:44.885593,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:49:44.885612, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:54:44.899042,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:54:44.899140, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:54:44.899158,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:54:44.899191, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:54:44.899208,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:54:44.899281,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:54:44.899307, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:54:44.899326, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:54:44.899403,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:54:44.899455,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:54:44.899715, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:54:44.899743,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:54:44.899767,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:54:44.899787,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 53 03 00 00   00 00 00 00 11 5B 04 34   ....S... .....[.4
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:54:44.899828,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000353-0000-0000-115b-0434e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:54:44.899922,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000353-0000-0000-115b-0434e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:54:44.900024,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000353-0000-0000-115b-0434e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:54:44.900109,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 53 03 00 00   00 00 00 00 11 5B 04 34   ....S... .....[.4
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:54:44.900181,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:54:44.900286,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000353-0000-0000-115b-0434e5090000
[2018/06/01 06:54:44.900347,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 53 03 00 00   00 00 00 00 11 5B 04 34   ....S... .....[.4
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:54:44.900385,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 53 03 00 00   00 00 00 00 11 5B 04 34   ....S... .....[.4
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:54:44.900422,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:54:44.900439,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:54:44.900510, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:54:44.900535,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:54:44.900552, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 06:59:44.941741,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 06:59:44.941934, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 06:59:44.941952,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 06:59:44.941980, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 06:59:44.941996,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 06:59:44.942054,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 06:59:44.942079, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 06:59:44.942098, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 06:59:44.942168,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 06:59:44.942215,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 06:59:44.942470, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 06:59:44.942496,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 06:59:44.942520,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 06:59:44.942540,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 54 03 00 00   00 00 00 00 11 5B 30 35   ....T... .....[05
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:59:44.942591,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000354-0000-0000-115b-3035e5090000
              result                   : NT_STATUS_OK
[2018/06/01 06:59:44.942711,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000354-0000-0000-115b-3035e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:59:44.942812,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000354-0000-0000-115b-3035e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 06:59:44.942896,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 54 03 00 00   00 00 00 00 11 5B 30 35   ....T... .....[05
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:59:44.942963,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 06:59:44.943063,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000354-0000-0000-115b-3035e5090000
[2018/06/01 06:59:44.943124,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 54 03 00 00   00 00 00 00 11 5B 30 35   ....T... .....[05
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:59:44.943163,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 54 03 00 00   00 00 00 00 11 5B 30 35   ....T... .....[05
  [0010] E5 09 00 00                                        .... 
[2018/06/01 06:59:44.943199,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 06:59:44.943216,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 06:59:44.943288, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 06:59:44.943313,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 06:59:44.943330, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:02:27.353091, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 07:02:27.353131,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 07:02:27.353150, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 07:02:27.353168, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 07:02:27.353201,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 07:02:27.353301,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:02:27.353358,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:02:27.353383, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:02:27.353402, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:02:27.353465,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:02:27.353513,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:02:27.353777, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:02:27.353804,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:02:27.353829,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:02:27.353849,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 55 03 00 00   00 00 00 00 11 5B D3 35   ....U... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.353892,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000355-0000-0000-115b-d335e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.353982, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 07:02:27.354022,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000355-0000-0000-115b-d335e5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 07:02:27.354210,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 55 03 00 00   00 00 00 00 11 5B D3 35   ....U... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.354257, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 07:02:27.354278, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 07:02:27.354302,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 07:02:27.354345,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 07:02:27.354376,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 07:02:27.354398, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 07:02:27.354416,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.354737, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 07:02:27.354773,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000355-0000-0000-115b-d335e5090000
[2018/06/01 07:02:27.354836,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 55 03 00 00   00 00 00 00 11 5B D3 35   ....U... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.354876,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 55 03 00 00   00 00 00 00 11 5B D3 35   ....U... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.354914,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:02:27.354931,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.355006, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:02:27.355049, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527853586 @ 1527853586]
[2018/06/01 07:02:27.355070,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 07:02:27.355103,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 07:02:27.355125, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 07:02:27.355144, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 07:02:27.355186,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 07:02:27.355219,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 07:02:27.355312,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 07:02:27.355333, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 07:02:27.355352,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 07:02:27.355376,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 07:02:27.355395,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 56 03 00 00   00 00 00 00 11 5B D3 35   ....V... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.355434,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 07:02:27.355451,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000356-0000-0000-115b-d335e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.355538,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000356-0000-0000-115b-d335e5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 07:02:27.355718,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 56 03 00 00   00 00 00 00 11 5B D3 35   ....V... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.355758, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 07:02:27.355778, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 07:02:27.355796,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 07:02:27.355813,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 07:02:27.355835,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 07:02:27.355854,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 57 03 00 00   00 00 00 00 11 5B D3 35   ....W... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.355895,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 07:02:27.355912,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000357-0000-0000-115b-d335e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.355996,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000357-0000-0000-115b-d335e5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 07:02:27.356068,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 07:02:27.356085,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 57 03 00 00   00 00 00 00 11 5B D3 35   ....W... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.356124, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 07:02:27.356144,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 07:02:27.356161,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b1135d3 (1527854547)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.356259, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527854547
[2018/06/01 07:02:27.356290,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000357-0000-0000-115b-d335e5090000
[2018/06/01 07:02:27.356350,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 57 03 00 00   00 00 00 00 11 5B D3 35   ....W... .....[.5
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:02:27.356390,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:02:27.356407,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.356481, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 07:02:27.356520, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527854547 @ 1527854547]
[2018/06/01 07:02:27.356541, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527854547
[2018/06/01 07:02:27.356572, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 07:02:27.356593,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 07:02:27.356737,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 07:02:27.356756, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 07:04:44.953049,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:04:44.953136, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:04:44.953154,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:04:44.953185, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:04:44.953203,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:04:44.953272,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:04:44.953299, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:04:44.953319, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:04:44.953433,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:04:44.953486,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:04:44.953753, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:04:44.953782,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:04:44.953806,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:04:44.953827,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 58 03 00 00   00 00 00 00 11 5B 5C 36   ....X... .....[\6
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:04:44.953869,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000358-0000-0000-115b-5c36e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:04:44.953966,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000358-0000-0000-115b-5c36e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:04:44.954072,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000358-0000-0000-115b-5c36e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:04:44.954166,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 58 03 00 00   00 00 00 00 11 5B 5C 36   ....X... .....[\6
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:04:44.954238,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:04:44.954343,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000358-0000-0000-115b-5c36e5090000
[2018/06/01 07:04:44.954408,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 58 03 00 00   00 00 00 00 11 5B 5C 36   ....X... .....[\6
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:04:44.954447,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 58 03 00 00   00 00 00 00 11 5B 5C 36   ....X... .....[\6
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:04:44.954485,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:04:44.954503,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:04:44.954579, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:04:44.954609,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:04:44.954626, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:09:45.004114,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:09:45.004208, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:09:45.004226,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:09:45.004254, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:09:45.004271,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:09:45.004330,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:09:45.004355, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:09:45.004374, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:09:45.004445,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:09:45.004492,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:09:45.004751, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:09:45.004777,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:09:45.004806,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:09:45.004826,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 59 03 00 00   00 00 00 00 11 5B 89 37   ....Y... .....[.7
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:09:45.004867,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000359-0000-0000-115b-8937e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:09:45.004959,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000359-0000-0000-115b-8937e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:09:45.005058,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000359-0000-0000-115b-8937e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:09:45.005141,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 59 03 00 00   00 00 00 00 11 5B 89 37   ....Y... .....[.7
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:09:45.005208,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:09:45.005309,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000359-0000-0000-115b-8937e5090000
[2018/06/01 07:09:45.005370,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 59 03 00 00   00 00 00 00 11 5B 89 37   ....Y... .....[.7
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:09:45.005408,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 59 03 00 00   00 00 00 00 11 5B 89 37   ....Y... .....[.7
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:09:45.005446,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:09:45.005463,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:09:45.005537, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:09:45.005562,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:09:45.005578, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:14:45.014416,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:14:45.014534, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:14:45.014556,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:14:45.014587, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:14:45.014605,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:14:45.014677,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:14:45.014703, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:14:45.014722, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:14:45.014800,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:14:45.014853,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:14:45.015115, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:14:45.015143,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:14:45.015167,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:14:45.015187,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 5A 03 00 00   00 00 00 00 11 5B B5 38   ....Z... .....[.8
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:14:45.015228,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035a-0000-0000-115b-b538e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:14:45.015323,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035a-0000-0000-115b-b538e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:14:45.015425,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035a-0000-0000-115b-b538e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:14:45.015511,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5A 03 00 00   00 00 00 00 11 5B B5 38   ....Z... .....[.8
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:14:45.015583,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:14:45.015685,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035a-0000-0000-115b-b538e5090000
[2018/06/01 07:14:45.015747,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5A 03 00 00   00 00 00 00 11 5B B5 38   ....Z... .....[.8
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:14:45.015784,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5A 03 00 00   00 00 00 00 11 5B B5 38   ....Z... .....[.8
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:14:45.015821,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:14:45.015838,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:14:45.015911, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:14:45.015936,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:14:45.015953, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:18:27.699153, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 07:18:27.699195,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 07:18:27.699214, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 07:18:27.699231, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 07:18:27.699263,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 07:18:27.699362,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:18:27.699413,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:18:27.699438, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:18:27.699458, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:18:27.699519,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:18:27.699565,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:18:27.699826, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:18:27.699852,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:18:27.699877,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:18:27.699897,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 5B 03 00 00   00 00 00 00 11 5B 93 39   ....[... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.699938,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035b-0000-0000-115b-9339e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.700026, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 07:18:27.700067,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035b-0000-0000-115b-9339e5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 07:18:27.700258,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5B 03 00 00   00 00 00 00 11 5B 93 39   ....[... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.700304, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 07:18:27.700326, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 07:18:27.700347,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 07:18:27.700384,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 07:18:27.700414,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 07:18:27.700436, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 07:18:27.700454,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.700773, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 07:18:27.700809,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035b-0000-0000-115b-9339e5090000
[2018/06/01 07:18:27.700871,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5B 03 00 00   00 00 00 00 11 5B 93 39   ....[... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.700910,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5B 03 00 00   00 00 00 00 11 5B 93 39   ....[... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.700948,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:18:27.700965,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.701041, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:18:27.701078, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527854547 @ 1527854547]
[2018/06/01 07:18:27.701099,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 07:18:27.701128,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 07:18:27.701149, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 07:18:27.701167, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 07:18:27.701205,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 07:18:27.701238,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 07:18:27.701332,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 07:18:27.701353, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 07:18:27.701372,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 07:18:27.701395,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 07:18:27.701414,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 5C 03 00 00   00 00 00 00 11 5B 93 39   ....\... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.701453,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 07:18:27.701470,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035c-0000-0000-115b-9339e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.701559,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035c-0000-0000-115b-9339e5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 07:18:27.701732,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5C 03 00 00   00 00 00 00 11 5B 93 39   ....\... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.701773, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 07:18:27.701792, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 07:18:27.701811,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 07:18:27.701828,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 07:18:27.701851,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 07:18:27.701869,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 5D 03 00 00   00 00 00 00 11 5B 93 39   ....]... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.701909,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 07:18:27.701926,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035d-0000-0000-115b-9339e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.702009,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035d-0000-0000-115b-9339e5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 07:18:27.702081,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 07:18:27.702098,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5D 03 00 00   00 00 00 00 11 5B 93 39   ....]... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.702137, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 07:18:27.702156,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 07:18:27.702174,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b113993 (1527855507)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.702275, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527855507
[2018/06/01 07:18:27.702306,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035d-0000-0000-115b-9339e5090000
[2018/06/01 07:18:27.702367,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5D 03 00 00   00 00 00 00 11 5B 93 39   ....]... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:18:27.702406,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:18:27.702422,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.702498, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 07:18:27.702535, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527855507 @ 1527855507]
[2018/06/01 07:18:27.702555, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527855507
[2018/06/01 07:18:27.702583, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 07:18:27.702604,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 07:18:27.702745,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 07:18:27.702763, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 07:19:45.033009,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:19:45.033119, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:19:45.033144,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:19:45.033179, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:19:45.033205,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:19:45.033279,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:19:45.033314, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:19:45.033341, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:19:45.033429,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:19:45.033491,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:19:45.033866, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:19:45.033902,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:19:45.033936,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:19:45.033965,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 5E 03 00 00   00 00 00 00 11 5B E1 39   ....^... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:19:45.034027,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035e-0000-0000-115b-e139e5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:19:45.034154,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035e-0000-0000-115b-e139e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:19:45.034296,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035e-0000-0000-115b-e139e5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:19:45.034415,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5E 03 00 00   00 00 00 00 11 5B E1 39   ....^... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:19:45.034513,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:19:45.034655,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035e-0000-0000-115b-e139e5090000
[2018/06/01 07:19:45.034743,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5E 03 00 00   00 00 00 00 11 5B E1 39   ....^... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:19:45.034802,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5E 03 00 00   00 00 00 00 11 5B E1 39   ....^... .....[.9
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:19:45.034860,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:19:45.034884,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:19:45.034988, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:19:45.035027,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:19:45.035052, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:24:45.076826,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:24:45.076956, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:24:45.076975,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:24:45.077007, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:24:45.077024,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:24:45.077097,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:24:45.077124, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:24:45.077143, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:24:45.077225,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:24:45.077278,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:24:45.077533, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:24:45.077562,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:24:45.077586,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:24:45.077606,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 5F 03 00 00   00 00 00 00 11 5B 0D 3B   ...._... .....[.;
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:24:45.077647,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035f-0000-0000-115b-0d3be5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:24:45.077740,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035f-0000-0000-115b-0d3be5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:24:45.077842,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035f-0000-0000-115b-0d3be5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:24:45.077924,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5F 03 00 00   00 00 00 00 11 5B 0D 3B   ...._... .....[.;
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:24:45.077996,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:24:45.078096,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 0000035f-0000-0000-115b-0d3be5090000
[2018/06/01 07:24:45.078157,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5F 03 00 00   00 00 00 00 11 5B 0D 3B   ...._... .....[.;
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:24:45.078195,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 5F 03 00 00   00 00 00 00 11 5B 0D 3B   ...._... .....[.;
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:24:45.078232,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:24:45.078250,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:24:45.078321, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:24:45.078346,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:24:45.078363, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:29:45.108533,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:29:45.108655, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:29:45.108676,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:29:45.108703, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:29:45.108720,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:29:45.108779,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:29:45.108804, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:29:45.108823, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:29:45.108894,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:29:45.108941,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:29:45.109194, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:29:45.109221,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:29:45.109244,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:29:45.109264,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 60 03 00 00   00 00 00 00 11 5B 39 3C   ....`... .....[9<
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:29:45.109305,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000360-0000-0000-115b-393ce5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:29:45.109396,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000360-0000-0000-115b-393ce5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:29:45.109498,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000360-0000-0000-115b-393ce5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:29:45.109585,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 60 03 00 00   00 00 00 00 11 5B 39 3C   ....`... .....[9<
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:29:45.109653,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:29:45.109750,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000360-0000-0000-115b-393ce5090000
[2018/06/01 07:29:45.109811,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 60 03 00 00   00 00 00 00 11 5B 39 3C   ....`... .....[9<
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:29:45.109849,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 60 03 00 00   00 00 00 00 11 5B 39 3C   ....`... .....[9<
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:29:45.109886,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:29:45.109903,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:29:45.109973, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:29:45.109998,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:29:45.110015, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:34:27.990603, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 07:34:27.990660,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 07:34:27.990681, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 07:34:27.990699, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 07:34:27.990737,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 07:34:27.990839,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:34:27.990900,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:34:27.990926, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:34:27.990945, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:34:27.991006,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:34:27.991056,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:34:27.991316, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:34:27.991342,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:34:27.991366,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:34:27.991386,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 61 03 00 00   00 00 00 00 11 5B 53 3D   ....a... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.991429,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000361-0000-0000-115b-533de5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.991515, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 07:34:27.991556,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000361-0000-0000-115b-533de5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 07:34:27.991741,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 61 03 00 00   00 00 00 00 11 5B 53 3D   ....a... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.991785, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 07:34:27.991806, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 07:34:27.991828,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 07:34:27.991865,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 07:34:27.991895,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 07:34:27.991916, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 07:34:27.991934,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.992241, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 07:34:27.992277,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000361-0000-0000-115b-533de5090000
[2018/06/01 07:34:27.992340,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 61 03 00 00   00 00 00 00 11 5B 53 3D   ....a... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.992378,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 61 03 00 00   00 00 00 00 11 5B 53 3D   ....a... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.992419,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:34:27.992441,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.992521, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:34:27.992558, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:474(fetch_cache_seqnum)
  fetch_cache_seqnum: timeout [LCARS][1527855507 @ 1527855507]
[2018/06/01 07:34:27.992579,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 07:34:27.992607,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 07:34:27.992627, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 07:34:27.992645, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 07:34:27.992682,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 07:34:27.992714,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 07:34:27.992805,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 07:34:27.992829, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 07:34:27.992848,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 07:34:27.992876,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 07:34:27.992907,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 62 03 00 00   00 00 00 00 11 5B 53 3D   ....b... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.992965,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 07:34:27.992989,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000362-0000-0000-115b-533de5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.993108,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000362-0000-0000-115b-533de5090000
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 07:34:27.993352,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 62 03 00 00   00 00 00 00 11 5B 53 3D   ....b... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.993412, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 07:34:27.993441, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 07:34:27.993466,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 07:34:27.993490,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 07:34:27.993526,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 07:34:27.993552,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 63 03 00 00   00 00 00 00 11 5B 53 3D   ....c... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.993612,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 07:34:27.993636,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000363-0000-0000-115b-533de5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.993755,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000363-0000-0000-115b-533de5090000
              level                    : DomainModifiedInformation (8)
[2018/06/01 07:34:27.993856,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 07:34:27.993880,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 63 03 00 00   00 00 00 00 11 5B 53 3D   ....c... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.993938, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 07:34:27.993964,  5, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 07:34:27.993988,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b113d53 (1527856467)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.994125, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527856467
[2018/06/01 07:34:27.994166,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000363-0000-0000-115b-533de5090000
[2018/06/01 07:34:27.994252,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 63 03 00 00   00 00 00 00 11 5B 53 3D   ....c... .....[S=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:27.994310,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:34:27.994333,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.994442, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 07:34:27.994500, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527856467 @ 1527856467]
[2018/06/01 07:34:27.994528, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527856467
[2018/06/01 07:34:27.994567, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 07:34:27.994597,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 07:34:27.994796,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 07:34:27.994823, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 07:34:45.153113,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:34:45.153204, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:34:45.153223,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [ 2528]: list trusted domains
[2018/06/01 07:34:45.153252, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:34:45.153275,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:34:45.153335,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:34:45.153361, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:34:45.153381, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:34:45.153456,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:34:45.153504,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:34:45.153771, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:34:45.153798,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:34:45.153824,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:34:45.153844,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 64 03 00 00   00 00 00 00 11 5B 65 3D   ....d... .....[e=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:45.153886,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000364-0000-0000-115b-653de5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:45.153983,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000364-0000-0000-115b-653de5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:34:45.154089,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000364-0000-0000-115b-653de5090000
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:34:45.154176,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 64 03 00 00   00 00 00 00 11 5B 65 3D   ....d... .....[e=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:45.154248,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:34:45.154354,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000364-0000-0000-115b-653de5090000
[2018/06/01 07:34:45.154423,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 64 03 00 00   00 00 00 00 11 5B 65 3D   ....d... .....[e=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:45.154463,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 64 03 00 00   00 00 00 00 11 5B 65 3D   ....d... .....[e=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:34:45.154502,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:34:45.154519,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:34:45.154595, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:34:45.154624,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:34:45.154642, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:36:42.695476, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 07:36:42.695528,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 07:36:42.695560, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 07:36:42.695589, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 07:36:42.695629,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000201 (513)
[2018/06/01 07:36:42.695748,  3, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:36:42.695799,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:36:42.695823, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:36:42.695843, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:36:42.695904,  4, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:36:42.695949,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:36:42.696210, 10, pid=2533, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:36:42.696235,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:36:42.696259,  4, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:36:42.696280,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 65 03 00 00   00 00 00 00 11 5B DA 3D   ....e... .....[.=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:36:42.696321,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000365-0000-0000-115b-da3de5090000
              result                   : NT_STATUS_OK
[2018/06/01 07:36:42.696411, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 07:36:42.696450,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000365-0000-0000-115b-da3de5090000
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 07:36:42.696635,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 65 03 00 00   00 00 00 00 11 5B DA 3D   ....e... .....[.=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:36:42.696679, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 07:36:42.696700, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 07:36:42.696722,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 07:36:42.696754,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 07:36:42.696782,  5, pid=2533, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 07:36:42.696803, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 1, status NT_STATUS_OK
[2018/06/01 07:36:42.696821,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_DOM_GRP (2)
                                  name: struct lsa_String
                                      length                   : 0x0008 (8)
                                      size                     : 0x0008 (8)
                                      string                   : *
                                          string                   : 'None'
                                  sid_index                : 0x00000000 (0)
              count                    : *
                  count                    : 0x00000001 (1)
              result                   : NT_STATUS_OK
[2018/06/01 07:36:42.697134, 10, pid=2533, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_OK', mapped count = 1'
[2018/06/01 07:36:42.697170,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000365-0000-0000-115b-da3de5090000
[2018/06/01 07:36:42.697232,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 65 03 00 00   00 00 00 00 11 5B DA 3D   ....e... .....[.=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:36:42.697271,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 65 03 00 00   00 00 00 00 11 5B DA 3D   ....e... .....[.=
  [0010] E5 09 00 00                                        .... 
[2018/06/01 07:36:42.697309,  6, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:36:42.697326,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:36:42.697401, 10, pid=2533, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:36:42.697432, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:554(refresh_sequence_number)
  refresh_sequence_number: LCARS time ok
[2018/06/01 07:36:42.697449, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527856467
[2018/06/01 07:36:42.697483, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-513 -> LCARS\None (NT_STATUS_OK)
[2018/06/01 07:36:42.697505,  1, pid=2533, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : *
                      domain_name              : 'LCARS'
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-513
                              type                     : SID_NAME_DOM_GRP (2)
                              name                     : *
                                  name                     : 'None'
              result                   : NT_STATUS_OK
[2018/06/01 07:36:42.697678,  4, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 07:36:42.697697, 10, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3588 bytes to parent
[2018/06/01 07:36:55.816607,  0, pid=2533, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd.c:281(winbindd_sig_term_handler)
  Got sig[15] terminate (is_parent=0)
[2018/06/01 07:36:55.816736,  5, pid=2533, effective(0, 0), real(0, 0), class=tdb] ../source3/lib/gencache.c:72(gencache_init)
  Opening cache file at /var/db/samba4/gencache.tdb
[2018/06/01 07:36:55.817020,  5, pid=2533, effective(0, 0), real(0, 0), class=tdb] ../source3/lib/gencache.c:123(gencache_init)
  Opening cache file at /var/lock/gencache_notrans.tdb
[2018/06/01 07:37:00.936701,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 33 - private_data=0x0
[2018/06/01 07:37:00.936734,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 13 - private_data=0x0
[2018/06/01 07:37:00.936751,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1028 - private_data=0x0
[2018/06/01 07:37:00.936768,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1027 - private_data=0x0
[2018/06/01 07:37:00.936785,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1029 - private_data=0x0
[2018/06/01 07:37:00.936801,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1280 - private_data=0x0
[2018/06/01 07:37:00.936818,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1033 - private_data=0x0
[2018/06/01 07:37:00.936834,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1 - private_data=0x0
[2018/06/01 07:37:00.936851,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1036 - private_data=0x0
[2018/06/01 07:37:00.936868,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:497(messaging_deregister)
  Deregistering messaging pointer for type 1035 - private_data=0x0
[2018/06/01 07:37:00.936893,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:450(messaging_register)
  Registering messaging pointer for type 1028 - private_data=0x0
[2018/06/01 07:37:00.936922,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:450(messaging_register)
  Registering messaging pointer for type 1027 - private_data=0x0
[2018/06/01 07:37:00.936950,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:450(messaging_register)
  Registering messaging pointer for type 1280 - private_data=0x0
[2018/06/01 07:37:00.936979,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:450(messaging_register)
  Registering messaging pointer for type 1 - private_data=0x0
[2018/06/01 07:37:00.937004,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:450(messaging_register)
  Registering messaging pointer for type 1034 - private_data=0x0
[2018/06/01 07:37:00.937027,  5, pid=99601, effective(0, 0), real(0, 0)] ../source3/lib/messages.c:465(messaging_register)
  Overriding messaging pointer for type 1034 - private_data=0x0
[2018/06/01 07:37:00.937149,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 48
[2018/06/01 07:37:00.937179, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn INIT_CONNECTION
[2018/06/01 07:37:00.937200, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cm.c:2587(set_dc_type_and_flags)
  set_dc_type_and_flags: setting up flags for primary or internal domain
[2018/06/01 07:37:00.937224,  5, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cm.c:2324(set_dc_type_and_flags_connect)
  set_dc_type_and_flags_connect: domain LCARS
[2018/06/01 07:37:00.937405,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:37:00.937435, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe dssetup
[2018/06/01 07:37:00.937455, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe dssetup
[2018/06/01 07:37:00.937548,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:37:00.937614, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection dssetup
[2018/06/01 07:37:00.937641,  5, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cm.c:2360(set_dc_type_and_flags_connect)
  set_dc_type_and_flags_connect: rpccli_ds_getprimarydominfo on domain LCARS failed: (NT_STATUS_RPC_PROCNUM_OUT_OF_RANGE)
[2018/06/01 07:37:00.937678,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:37:00.937700, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:37:00.937719, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:37:00.937758,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:37:00.937803,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy2: struct lsa_OpenPolicy2
          in: struct lsa_OpenPolicy2
              system_name              : NULL
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:37:00.938061, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:37:00.938095,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:37:00.938121,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:37:00.938141,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 01 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.938187,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy2: struct lsa_OpenPolicy2
          out: struct lsa_OpenPolicy2
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000001-0000-0000-115b-ec3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:00.938278,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_QueryInfoPolicy2: struct lsa_QueryInfoPolicy2
          in: struct lsa_QueryInfoPolicy2
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000001-0000-0000-115b-ec3d11850100
              level                    : LSA_POLICY_INFO_DNS (12)
[2018/06/01 07:37:00.938371,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:37:00.938662, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:37:00.938684,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:37:00.938709,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:37:00.938728,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 02 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.938769,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000002-0000-0000-115b-ec3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:00.938855,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_QueryInfoPolicy: struct lsa_QueryInfoPolicy
          in: struct lsa_QueryInfoPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000002-0000-0000-115b-ec3d11850100
              level                    : LSA_POLICY_INFO_ACCOUNT_DOMAIN (5)
[2018/06/01 07:37:00.938927,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 02 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.938970,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_QueryInfoPolicy: struct lsa_QueryInfoPolicy
          out: struct lsa_QueryInfoPolicy
              info                     : *
                  info                     : *
                      info                     : union lsa_PolicyInformation(case 5)
                      account_domain: struct lsa_DomainInfo
                          name: struct lsa_StringLarge
                              length                   : 0x000a (10)
                              size                     : 0x000c (12)
                              string                   : *
                                  string                   : 'LCARS'
                          sid                      : *
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685
              result                   : NT_STATUS_OK
[2018/06/01 07:37:00.939133,  5, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cm.c:2563(set_dc_type_and_flags_connect)
  set_dc_type_and_flags_connect: domain LCARS is NOT in native mode.
[2018/06/01 07:37:00.939156,  5, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cm.c:2566(set_dc_type_and_flags_connect)
  set_dc_type_and_flags_connect: domain LCARS is NOT running active directory.
[2018/06/01 07:37:00.939174, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:37:00.939201,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 48
[2018/06/01 07:37:00.939220, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:37:00.939355,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 20
[2018/06/01 07:37:00.939384, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn LIST_TRUSTDOM
[2018/06/01 07:37:00.939404,  3, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [99600]: list trusted domains
[2018/06/01 07:37:00.939426, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:2835(wb_cache_trusted_domains)
  trusted_domains: [Cached] - doing backend query for info for domain LCARS
[2018/06/01 07:37:00.939444,  3, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:37:00.939479,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:37:00.939502, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:37:00.939521, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:37:00.939566,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:37:00.939600,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:37:00.939858, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:37:00.939881,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:37:00.939906,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:37:00.939926,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 03 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.939966,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000003-0000-0000-115b-ec3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:00.940059,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustedDomainsEx: struct lsa_EnumTrustedDomainsEx
          in: struct lsa_EnumTrustedDomainsEx
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000003-0000-0000-115b-ec3d11850100
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:37:00.940171,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          in: struct lsa_EnumTrustDom
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000003-0000-0000-115b-ec3d11850100
              resume_handle            : *
                  resume_handle            : 0x00000000 (0)
              max_size                 : 0xffffffff (4294967295)
[2018/06/01 07:37:00.940260,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 03 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.940340,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_EnumTrustDom: struct lsa_EnumTrustDom
          out: struct lsa_EnumTrustDom
              resume_handle            : *
                  resume_handle            : 0xffffffff (4294967295)
              domains                  : *
                  domains: struct lsa_DomainList
                      count                    : 0x00000000 (0)
                      domains                  : NULL
              result                   : NT_STATUS_NO_MORE_ENTRIES
[2018/06/01 07:37:00.940454,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000003-0000-0000-115b-ec3d11850100
[2018/06/01 07:37:00.940519,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 03 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.940559,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 03 00 00 00   00 00 00 00 11 5B EC 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:00.940598,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:37:00.940615,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:37:00.940691, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:37:00.940721,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 20
[2018/06/01 07:37:00.940738, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3496 bytes to parent
[2018/06/01 07:37:01.218081, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:69(child_read_request)
  Need to read 36 extra bytes
[2018/06/01 07:37:01.218124,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1387(child_handler)
  child daemon request 56
[2018/06/01 07:37:01.218144, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:512(child_process_request)
  child_process_request: request fn NDRCMD
[2018/06/01 07:37:01.218162, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual_ndr.c:315(winbindd_dual_ndrcmd)
  winbindd_dual_ndrcmd: Running command WBINT_LOOKUPRIDS (LCARS)
[2018/06/01 07:37:01.218194,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          in: struct wbint_LookupRids
              domain_sid               : *
                  domain_sid               : S-1-5-21-1881563143-3349900363-1681061685
              rids                     : *
                  rids: struct wbint_RidArray
                      num_rids                 : 0x00000001 (1)
                      rids: ARRAY(1)
                          rids                     : 0x00000202 (514)
[2018/06/01 07:37:01.218292,  3, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:37:01.218348,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested lsarpc
[2018/06/01 07:37:01.218373, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe lsarpc
[2018/06/01 07:37:01.218395, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe lsarpc
[2018/06/01 07:37:01.218464,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe lsarpc
[2018/06/01 07:37:01.218512,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          in: struct lsa_OpenPolicy
              system_name              : *
                  system_name              : 0x005c (92)
              attr                     : *
                  attr: struct lsa_ObjectAttribute
                      len                      : 0x00000018 (24)
                      root_dir                 : NULL
                      object_name              : NULL
                      attributes               : 0x00000000 (0)
                      sec_desc                 : NULL
                      sec_qos                  : *
                          sec_qos: struct lsa_QosInfo
                              len                      : 0x0000000c (12)
                              impersonation_level      : 0x0002 (2)
                              context_mode             : 0x01 (1)
                              effective_only           : 0x00 (0)
              access_mask              : 0x02000000 (33554432)
                     0: LSA_POLICY_VIEW_LOCAL_INFORMATION
                     0: LSA_POLICY_VIEW_AUDIT_INFORMATION
                     0: LSA_POLICY_GET_PRIVATE_INFORMATION
                     0: LSA_POLICY_TRUST_ADMIN   
                     0: LSA_POLICY_CREATE_ACCOUNT
                     0: LSA_POLICY_CREATE_SECRET 
                     0: LSA_POLICY_CREATE_PRIVILEGE
                     0: LSA_POLICY_SET_DEFAULT_QUOTA_LIMITS
                     0: LSA_POLICY_SET_AUDIT_REQUIREMENTS
                     0: LSA_POLICY_AUDIT_LOG_ADMIN
                     0: LSA_POLICY_SERVER_ADMIN  
                     0: LSA_POLICY_LOOKUP_NAMES  
                     0: LSA_POLICY_NOTIFICATION  
[2018/06/01 07:37:01.218779, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f1fff
[2018/06/01 07:37:01.218805,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _lsa_OpenPolicy2: ACCESS should be DENIED  (requested: 0x000f1fff)
  but overritten by euid == initial uid
[2018/06/01 07:37:01.218830,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _lsa_OpenPolicy2: access GRANTED (requested: 0x000f1fff, granted: 0x000f1fff)
[2018/06/01 07:37:01.218850,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 04 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.218895,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_OpenPolicy: struct lsa_OpenPolicy
          out: struct lsa_OpenPolicy
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000004-0000-0000-115b-ed3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.218983, 10, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:408(dcerpc_lsa_lookup_sids_generic)
  rpccli_lsa_lookup_sids: processing items 0 -- 0 of 1.
[2018/06/01 07:37:01.219024,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          in: struct lsa_LookupSids
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000004-0000-0000-115b-ed3d11850100
              sids                     : *
                  sids: struct lsa_SidArray
                      num_sids                 : 0x00000001 (1)
                      sids                     : *
                          sids: ARRAY(1)
                              sids: struct lsa_SidPtr
                                  sid                      : *
                                      sid                      : S-1-5-21-1881563143-3349900363-1681061685-514
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000000 (0)
                      names                    : NULL
              level                    : LSA_LOOKUP_NAMES_ALL (1)
              count                    : *
                  count                    : 0x00000000 (0)
[2018/06/01 07:37:01.219219,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 04 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.219272, 10, pid=99601, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:813(check_dom_sid_to_level)
  Accepting SID S-1-5-21-1881563143-3349900363-1681061685 in level 1
[2018/06/01 07:37:01.219296, 10, pid=99601, effective(0, 0), real(0, 0)] ../source3/passdb/lookup_sid.c:574(lookup_rids)
  lookup_rids called for domain sid 'S-1-5-21-1881563143-3349900363-1681061685'
[2018/06/01 07:37:01.219319,  5, pid=99601, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 514.
[2018/06/01 07:37:01.219441,  4, pid=99601, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:558(tdbsam_open)
  tdbsam_open: successfully opened /var/db/samba4/private/passdb.tdb
[2018/06/01 07:37:01.219470,  5, pid=99601, effective(0, 0), real(0, 0), class=passdb] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 514 by key RID_00000202.
[2018/06/01 07:37:01.219574, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/lsa/srv_lsa_nt.c:896(_lsa_lookup_sids_internal)
  num_sids 1, mapped_count 0, status NT_STATUS_NONE_MAPPED
[2018/06/01 07:37:01.219601,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_LookupSids: struct lsa_LookupSids
          out: struct lsa_LookupSids
              domains                  : *
                  domains                  : *
                      domains: struct lsa_RefDomainList
                          count                    : 0x00000001 (1)
                          domains                  : *
                              domains: ARRAY(1)
                                  domains: struct lsa_DomainInfo
                                      name: struct lsa_StringLarge
                                          length                   : 0x000a (10)
                                          size                     : 0x000c (12)
                                          string                   : *
                                              string                   : 'LCARS'
                                      sid                      : *
                                          sid                      : S-1-5-21-1881563143-3349900363-1681061685
                          max_size                 : 0x00000020 (32)
              names                    : *
                  names: struct lsa_TransNameArray
                      count                    : 0x00000001 (1)
                      names                    : *
                          names: ARRAY(1)
                              names: struct lsa_TranslatedName
                                  sid_type                 : SID_NAME_UNKNOWN (8)
                                  name: struct lsa_String
                                      length                   : 0x005a (90)
                                      size                     : 0x005a (90)
                                      string                   : *
                                          string                   : 'S-1-5-21-1881563143-3349900363-1681061685-514'
                                  sid_index                : 0xffffffff (4294967295)
              count                    : *
                  count                    : 0x00000000 (0)
              result                   : NT_STATUS_NONE_MAPPED
[2018/06/01 07:37:01.219922, 10, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_client/cli_lsarpc.c:254(dcerpc_lsa_lookup_sids_noalloc)
  LSA_LOOKUPSIDS returned status: 'NT_STATUS_OK', result: 'NT_STATUS_NONE_MAPPED', mapped count = 0'
[2018/06/01 07:37:01.219959,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          in: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000004-0000-0000-115b-ed3d11850100
[2018/06/01 07:37:01.220021,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 04 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.220061,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 04 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.220099,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:37:01.220118,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       lsa_Close: struct lsa_Close
          out: struct lsa_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.220195, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection lsarpc
[2018/06/01 07:37:01.220233,  3, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 07:37:01.220273,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:205(make_internal_rpc_pipe_p)
  Create pipe requested samr
[2018/06/01 07:37:01.220296, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:223(init_pipe_handles)
  init_pipe_handle_list: created handle list for pipe samr
[2018/06/01 07:37:01.220314, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:240(init_pipe_handles)
  init_pipe_handle_list: pipe_handles ref count = 1 for pipe samr
[2018/06/01 07:37:01.220354,  4, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_ncacn_np.c:245(make_internal_rpc_pipe_p)
  Created internal pipe samr
[2018/06/01 07:37:01.220387,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          in: struct samr_Connect2
              system_name              : NULL
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_ACCESS_CONNECT_TO_SERVER
                     0: SAMR_ACCESS_SHUTDOWN_SERVER
                     0: SAMR_ACCESS_INITIALIZE_SERVER
                     0: SAMR_ACCESS_CREATE_DOMAIN
                     0: SAMR_ACCESS_ENUM_DOMAINS 
                     0: SAMR_ACCESS_LOOKUP_DOMAIN
[2018/06/01 07:37:01.220482,  5, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3860(_samr_Connect2)
  _samr_Connect2: 3860
[2018/06/01 07:37:01.220509, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f003f
[2018/06/01 07:37:01.220530,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_Connect2: ACCESS should be DENIED  (requested: 0x000f003f)
  but overritten by euid == initial uid
[2018/06/01 07:37:01.220554,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_Connect2: access GRANTED (requested: 0x000f003f, granted: 0x000f003f)
[2018/06/01 07:37:01.220573,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[1] [0000] 00 00 00 00 05 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.220615,  5, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3889(_samr_Connect2)
  _samr_Connect2: 3889
[2018/06/01 07:37:01.220632,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Connect2: struct samr_Connect2
          out: struct samr_Connect2
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000005-0000-0000-115b-ed3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.220719,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          in: struct samr_OpenDomain
              connect_handle           : *
                  connect_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000005-0000-0000-115b-ed3d11850100
              access_mask              : 0x02000000 (33554432)
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_1
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_1
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_INFO_2
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_2
                     0: SAMR_DOMAIN_ACCESS_CREATE_USER
                     0: SAMR_DOMAIN_ACCESS_CREATE_GROUP
                     0: SAMR_DOMAIN_ACCESS_CREATE_ALIAS
                     0: SAMR_DOMAIN_ACCESS_LOOKUP_ALIAS
                     0: SAMR_DOMAIN_ACCESS_ENUM_ACCOUNTS
                     0: SAMR_DOMAIN_ACCESS_OPEN_ACCOUNT
                     0: SAMR_DOMAIN_ACCESS_SET_INFO_3
              sid                      : *
                  sid                      : S-1-5-21-1881563143-3349900363-1681061685
[2018/06/01 07:37:01.220895,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 05 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.220938, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_connect_info
[2018/06/01 07:37:01.220957, 10, pid=99601, effective(0, 0), real(0, 0)] ../libcli/security/access_check.c:58(se_map_generic)
  se_map_generic(): mapped mask 0xb0000000 to 0x000f07ff
[2018/06/01 07:37:01.220976,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:84(access_check_object)
  access_check_object: user rights access mask [0x3f0]
[2018/06/01 07:37:01.220993,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:95(access_check_object)
  _samr_OpenDomain: ACCESS should be DENIED  (requested: 0x000f040f)
  but overritten by euid == initial uid
[2018/06/01 07:37:01.221017,  4, pid=99601, effective(0, 0), real(0, 0)] ../source3/rpc_server/srv_access_check.c:117(access_check_object)
  _samr_OpenDomain: access GRANTED (requested: 0x000f040f, granted: 0x000f07ff)
[2018/06/01 07:37:01.221036,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:304(create_rpc_handle_internal)
  Opened policy hnd[2] [0000] 00 00 00 00 06 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.221076,  5, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:501(_samr_OpenDomain)
  _samr_OpenDomain: 501
[2018/06/01 07:37:01.221094,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_OpenDomain: struct samr_OpenDomain
          out: struct samr_OpenDomain
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000006-0000-0000-115b-ed3d11850100
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.221180,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          in: struct samr_QueryDomainInfo
              domain_handle            : *
                  domain_handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000006-0000-0000-115b-ed3d11850100
              level                    : DomainModifiedInformation (8)
[2018/06/01 07:37:01.221253,  5, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3493(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3493
[2018/06/01 07:37:01.221271,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 06 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.221309, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:523(_policy_handle_find)
  found handle of type struct samr_domain_info
[2018/06/01 07:37:01.221332,  5, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/samr/srv_samr_nt.c:3583(_samr_QueryDomainInfo)
  _samr_QueryDomainInfo: 3583
[2018/06/01 07:37:01.221350,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_QueryDomainInfo: struct samr_QueryDomainInfo
          out: struct samr_QueryDomainInfo
              info                     : *
                  info                     : *
                      info                     : union samr_DomainInfo(case 8)
                      info8: struct samr_DomInfo8
                          sequence_num             : 0x000000005b113ded (1527856621)
                          domain_create_time       : NTTIME(0)
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.221458, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_rpc.c:850(rpc_sequence_number)
  domain_sequence_number: for domain LCARS is 1527856621
[2018/06/01 07:37:01.221490,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          in: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000006-0000-0000-115b-ed3d11850100
[2018/06/01 07:37:01.221552,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:339(find_policy_by_hnd_internal)
  Found policy hnd[0] [0000] 00 00 00 00 06 00 00 00   00 00 00 00 11 5B ED 3D   ........ .....[.=
  [0010] 11 85 01 00                                        .... 
[2018/06/01 07:37:01.221592,  6, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:388(close_policy_hnd)
  Closed policy
[2018/06/01 07:37:01.221609,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       samr_Close: struct samr_Close
          out: struct samr_Close
              handle                   : *
                  handle: struct policy_handle
                      handle_type              : 0x00000000 (0)
                      uuid                     : 00000000-0000-0000-0000-000000000000
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.221684, 10, pid=99601, effective(0, 0), real(0, 0), class=rpc_srv] ../source3/rpc_server/rpc_handles.c:418(close_policy_by_pipe)
  Deleted handle list for RPC connection samr
[2018/06/01 07:37:01.221726, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:513(wcache_store_seqnum)
  wcache_store_seqnum: success [LCARS][1527856621 @ 1527856621]
[2018/06/01 07:37:01.221747, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:599(refresh_sequence_number)
  refresh_sequence_number: LCARS seq number is now 1527856621
[2018/06/01 07:37:01.221785, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_cache.c:1008(wcache_save_sid_to_name)
  wcache_save_sid_to_name: S-1-5-21-1881563143-3349900363-1681061685-514 -> LCARS\(null) (NT_STATUS_NONE_MAPPED)
[2018/06/01 07:37:01.221810,  1, pid=99601, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:468(ndr_print_function_debug)
       wbint_LookupRids: struct wbint_LookupRids
          out: struct wbint_LookupRids
              domain_name              : *
                  domain_name              : NULL
              names                    : *
                  names: struct wbint_Principals
                      num_principals           : 1
                      principals: ARRAY(1)
                          principals: struct wbint_Principal
                              sid                      : S-1-5-21-1881563143-3349900363-1681061685-514
                              type                     : SID_NAME_UNKNOWN (8)
                              name                     : NULL
              result                   : NT_STATUS_OK
[2018/06/01 07:37:01.221939,  4, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1395(child_handler)
  Finished processing child request 56
[2018/06/01 07:37:01.221957, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:104(child_write_response)
  Writing 3548 bytes to parent
[2018/06/01 07:38:01.232945, 10, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1602(fork_domain_child)
  fork_domain_child: domain LCARS no longer in 'startup' mode.
[2018/06/01 07:39:54.071005,  0, pid=99601, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd.c:281(winbindd_sig_term_handler)
  Got sig[15] terminate (is_parent=0)
[2018/06/01 07:39:54.071111,  5, pid=99601, effective(0, 0), real(0, 0), class=tdb] ../source3/lib/gencache.c:72(gencache_init)
  Opening cache file at /var/db/samba4/gencache.tdb
[2018/06/01 07:39:54.071407,  5, pid=99601, effective(0, 0), real(0, 0), class=tdb] ../source3/lib/gencache.c:123(gencache_init)
  Opening cache file at /var/lock/gencache_notrans.tdb
[2018/06/01 07:39:54.602615,  3] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [  137]: list trusted domains
[2018/06/01 07:39:54.602701,  3] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
[2018/06/01 07:39:54.699309,  3] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:39:54.699563,  5] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 514.
[2018/06/01 07:39:54.699711,  4] ../source3/passdb/pdb_tdb.c:558(tdbsam_open)
  tdbsam_open: successfully opened /var/db/samba4/private/passdb.tdb
[2018/06/01 07:39:54.699746,  5] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 514 by key RID_00000202.
[2018/06/01 07:39:54.699952,  3] ../source3/winbindd/winbindd_samr.c:896(sam_sequence_number)
  samr: sequence number
[2018/06/01 07:39:57.316467,  3] ../source3/winbindd/winbindd_samr.c:601(sam_rids_to_names)
  sam_rids_to_names for LCARS
[2018/06/01 07:39:57.316655,  5] ../source3/passdb/pdb_interface.c:1749(lookup_global_sam_rid)
  lookup_global_sam_rid: looking up RID 513.
[2018/06/01 07:39:57.316694,  5] ../source3/passdb/pdb_tdb.c:658(tdbsam_getsampwrid)
  pdb_getsampwrid (TDB): error looking up RID 513 by key RID_00000201.
[2018/06/01 07:39:57.316722,  5] ../source3/passdb/pdb_interface.c:1884(pdb_default_lookup_rids)
  lookup_rids: None:2
[2018/06/01 07:41:34.315505,  0] ../source3/winbindd/winbindd.c:281(winbindd_sig_term_handler)
  Got sig[15] terminate (is_parent=0)
[2018/06/01 07:41:40.762893,  3] ../source3/winbindd/winbindd_misc.c:161(winbindd_dual_list_trusted_domains)
  [  614]: list trusted domains
[2018/06/01 07:41:40.762963,  3] ../source3/winbindd/winbindd_samr.c:227(sam_trusted_domains)
  samr: trusted domains
