Hi Rob


All those commands work, and give expected results.

I will send you the install logs direct.



From:   Rob Crittenden <rcrit...@redhat.com>
To:     Christopher Lamb/Switzerland/IBM@IBMCH,
            freeipa-users@redhat.com, Jakub Hrozek <jhro...@redhat.com>
Date:   02.06.2015 19:25
Subject:        Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA
            client on EL7.1 -->Not Solved

Christopher Lamb wrote:
> Hi
> To narrow down the cause even further, I reverted HOST10 via VM snapshot
> back to the state after installing linux and configuring ntpd.
> This time I installed ipa-client 4.1 directly (rather then as a dependent
> of our standard server packages). So this machine is a basic install of
> 7.1 + ntpd + ipa-client, with nothing else extra.
> Again I first registered against the old 3.3.3 FreeIPA Server, then
> switched to the new 4.1 Server.
> Once again my FreeIPA user does not authenticate.

I'd start by simlifying things.

Does kinit -kt /etc/krb5.keytab work?

Do basic nss operations work?

getent passwd admin
id admin
groups admin

Seeing the entire ipaclient-install.log after the 7.1 install may be

Cranking up sssd debuglevel may be helpful.


Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to