Zack Richards via FreeIPA-users wrote:
> Greetings!
> 
> Old freeipa accounts get  "The password or username you entered is incorrect" 
> when trying to login to UI of any ipa replica with version higher than 4.10.0
> 
> Checked userPassword hash on all replicas, and it identical.
> 
> Tested different base OS docker containers with freeipa-server, no luck.
> 

Your users are likely missing SIDs which are required in newer versions.

run: ipa config-mod --enable-sid --add-sids

AND

watch /var/log/dirsrv/slapd-REALM/errors for errors.

Users who don't exist in an existing idrange[1] will fail. On 4.10.0 the
add sids process stops at each error.

This list has quite a few posts from others who have run into this. I'd
recommend you check them out.

rob

[1] https://www.freeipa.org/page/V3/ID_Ranges

-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to