On Wed, Feb 05, 2014 at 01:44:13PM -0500, Mark Gardner wrote:
> Spent some time on this one...
> Some users can login SSO no problem, others have to put in their password.
> Strange as it seems, if the length of the username was greater than 4, the
> SSO worked.
> So firstname.lastname@example.org works, but email@example.com doesn't.
Can you send the mapping you use in krb5.conf? Can you check if there
are .k5login files in the home directories of the users where SSO is
> My guess is something to do with the NetBios name length?
> Fedora 20 IPA Server
> CentOS 6.5 IPA Client
> Win 2012 AD Domain Server
> Setup as IPA as a subdomain of AD.
> AD Domain: test.local
> IPA Domain: hosted.test.local
> Freeipa-users mailing list
Freeipa-users mailing list