Roderick Johnstone via FreeIPA-users
<freeipa-users@lists.fedorahosted.org> writes:

> [Wed Jun 13 21:30:04.437056 2018] [:error] [pid 29635] ipa: INFO: 401 
> Unauthorized: Insufficient access: SASL(-1): generic failure: GSSAPI 
> Error: The referenced context has expired (Success)

This depends slightly on what SASL was trying to do at the time, but
basically, each GSSAPI context has a time for which it is valid.  This
is tied to credential lifetime (akin to ticket lifetime in Kerberos).

It's specific to the application's credentials, which means it's a
problem on the server.  I can't really speak to why the server is
keeping contexts around too long, though.

Thanks,
--Robbie

Attachment: signature.asc
Description: PGP signature

_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/message/XFK7JDTM6ZICW6A6Z3QGWEXYVKRYUL4D/

Reply via email to