Roderick Johnstone via FreeIPA-users <freeipa-users@lists.fedorahosted.org> writes:
> [Wed Jun 13 21:30:04.437056 2018] [:error] [pid 29635] ipa: INFO: 401 > Unauthorized: Insufficient access: SASL(-1): generic failure: GSSAPI > Error: The referenced context has expired (Success) This depends slightly on what SASL was trying to do at the time, but basically, each GSSAPI context has a time for which it is valid. This is tied to credential lifetime (akin to ticket lifetime in Kerberos). It's specific to the application's credentials, which means it's a problem on the server. I can't really speak to why the server is keeping contexts around too long, though. Thanks, --Robbie
signature.asc
Description: PGP signature
_______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/message/XFK7JDTM6ZICW6A6Z3QGWEXYVKRYUL4D/