Hello, list.
I have installed freeipa server 4.10.2-8 under RockyLinux and would like to 
setup windows clients to join freeipa domain.
I followed the guide 
When I enter user credentials for the first time windows asks to change 
password, after password is changed it does not login.

After that every attempt results in the "wrong user or password" message. 
Looking at kerberos log it seems that password is correct but windows does not 
let the user in for some reason. In audit log it says that login was refused 
with some error that does not explain anything.
Time is in sync as well as timezone.

There are a lot of posts saying that this should work but I don't have any 
clues where to look. Any ideas what might be wrong?
