On Monday 21 January 2013 10:30 PM, freeipa-users-requ...@redhat.com wrote:
Send Freeipa-users mailing list submissions to
        freeipa-users@redhat.com

To subscribe or unsubscribe via the World Wide Web, visit
        https://www.redhat.com/mailman/listinfo/freeipa-users
or, via email, send a message with subject or body 'help' to
        freeipa-users-requ...@redhat.com

You can reach the person managing the list at
        freeipa-users-ow...@redhat.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of Freeipa-users digest..."


Today's Topics:

    1. FreeIPA Client Setup in Windows 7 & Ubuntu (Vijay Thakur)
    2. Re: FreeIPA Client Setup in Windows 7 & Ubuntu (Dmitri Pal)


----------------------------------------------------------------------

Message: 1
Date: Mon, 21 Jan 2013 15:15:00 +0530
From: Vijay Thakur<vijay.tha...@loopmethods.com>
To:freeipa-users@redhat.com
Subject: [Freeipa-users] FreeIPA Client Setup in Windows 7 & Ubuntu
Message-ID:<50fd0e1c.1080...@loopmethods.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed

Dear All List Members,


I have installed and configured FreeIPA Server 2.2.1 in Fedora 17. All
is working very fine at server end. I have
successfully configure my Centos 6.0 Box as FreeIPA Client. Now i have
to set up FreeIPA clients of Ubuntu 12.04
and windows 7.  There is no available documentation for Windows 7 and
Ubuntu 12.04. During the first login of
Windows 7 as FreeIPA Client, i have followed the following steps:


(1) Login asus...@xyz.com  and Password: 12345678
(2) Message "Your Password has expired and must be changed".
(3) Changed the Password to new one successfully.
(4) Again login with new credentials.
(5) Windows 7 giving message "The User Name or Password is incorrect".

I have already stopped the Windows 7 firewall.

Guide me about Ubuntu 12.04 as FreeIPA Client setting.

With Warm Wishes,


Vijay Thakur
Here is the logs of server side:

an 22 16:21:02 ds.example.com krb5kdc[1376](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.51.16: NEEDED_PREAUTH: ad...@example.com for krbtgt/example....@example.com, Additional pre-authentication required Jan 22 16:21:02 ds.example.com krb5kdc[1376](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.51.16: ISSUE: authtime 1358851862, etypes {rep=18 tkt=18 ses=18}, ad...@example.com for krbtgt/example....@example.com Jan 22 16:21:02 ds.example.com krb5kdc[1376](info): TGS_REQ (4 etypes {18 17 16 23}) 192.168.51.16: ISSUE: authtime 1358851862, etypes {rep=18 tkt=18 ses=18}, ad...@example.com for ldap/ds.example....@example.com Jan 22 16:34:10 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: CLIENT KEY EXPIRED: vi...@example.com for krbtgt/example....@example.com, Password has expired Jan 22 16:34:25 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: NEEDED_PREAUTH: vi...@example.com for kadmin/chang...@example.com, Additional pre-authentication required Jan 22 16:34:25 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: ISSUE: authtime 1358852665, etypes {rep=18 tkt=18 ses=18}, vi...@example.com for kadmin/chang...@example.com Jan 22 16:34:25 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: NEEDED_PREAUTH: vi...@example.com for krbtgt/example....@example.com, Additional pre-authentication required Jan 22 16:34:25 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: ISSUE: authtime 1358852665, etypes {rep=18 tkt=18 ses=18}, vi...@example.com for krbtgt/example....@example.com Jan 22 16:34:25 ds.example.com krb5kdc[1376](info): TGS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: ISSUE: authtime 1358852665, etypes {rep=18 tkt=18 ses=18}, vi...@example.com for vi...@example.com Jan 22 16:34:29 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: NEEDED_PREAUTH: vi...@example.com for krbtgt/example....@example.com, Additional pre-authentication required Jan 22 16:34:29 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: ISSUE: authtime 1358852669, etypes {rep=18 tkt=18 ses=18}, vi...@example.com for krbtgt/example....@example.com Jan 22 16:34:29 ds.example.com krb5kdc[1376](info): TGS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: UNKNOWN_SERVER: authtime 0, vi...@example.com for host/w...@example.com, Server not found in Kerberos database Jan 22 16:34:54 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: NEEDED_PREAUTH: vi...@example.com for krbtgt/example....@example.com, Additional pre-authentication required Jan 22 16:34:54 ds.example.com krb5kdc[1376](info): preauth (encrypted_timestamp) verify failure: Decrypt integrity check failed Jan 22 16:34:54 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: PREAUTH_FAILED: vi...@example.com for krbtgt/example....@example.com, Decrypt integrity check failed Jan 22 16:34:54 ds.example.com krb5kdc[1376](info): preauth (encrypted_timestamp) verify failure: Decrypt integrity check failed Jan 22 16:34:54 ds.example.com krb5kdc[1376](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 192.168.51.17: PREAUTH_FAILED: vi...@example.com for krbtgt/example....@example.com, Decrypt integrity check failed


Kindly tell me the location of kerberose log file in windows 7?

With Regards,

VJ++


------------------------------ Message: 2 Date: Mon, 21 Jan 2013 07:37:39 -0500 From: Dmitri Pal <d...@redhat.com> To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] FreeIPA Client Setup in Windows 7 & Ubuntu Message-ID: <50fd3693.7060...@redhat.com> Content-Type: text/plain; charset=ISO-8859-1 On 01/21/2013 04:45 AM, Vijay Thakur wrote:
Dear All List Members,


I have installed and configured FreeIPA Server 2.2.1 in Fedora 17. All
is working very fine at server end. I have
successfully configure my Centos 6.0 Box as FreeIPA Client. Now i have
to set up FreeIPA clients of Ubuntu 12.04
and windows 7.  There is no available documentation for Windows 7 and
Ubuntu 12.04. During the first login of
Windows 7 as FreeIPA Client, i have followed the following steps:


(1) Login asus...@xyz.com  and Password: 12345678
(2) Message "Your Password has expired and must be changed".
(3) Changed the Password to new one successfully.
(4) Again login with new credentials.
(5) Windows 7 giving message "The User Name or Password is incorrect".

What did you do to configure Windows 7?
Can you produce kerberos logs from the server and the client?
Any other relevant logs you can find from the client would be helpful too.



I have already stopped the Windows 7 firewall.

Guide me about Ubuntu 12.04 as FreeIPA Client setting.
I would leave this to Ubuntu users to chime in.
I know there have been work done for Ubuntu but we unfortunately I do
not have information on the state of this work.

With Warm Wishes,


Vijay Thakur







_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users


_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Reply via email to