[Freeipa-users] Re: Unable to create GSSAPI-encrypted LDAP connection

2017-12-04 Thread Aaron Hicks via FreeIPA-users
Hello the list, It looks like sssd's horrible logging messages were to blame. It looks like when the keytab was initially deployed the system time between the IPA server and the host were not quite in sync and the keytab was invalidated. I redeployed the host's keytab (which because SLES lacks

[Freeipa-users] Re: Authentication for ipa cli scripting (wsgi, kerberos)

2017-12-04 Thread skrawczenko--- via FreeIPA-users
Great, it helped. googled it at https://www.redhat.com/archives/freeipa-users/2014-March/msg00044.html Thanks a lot! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Authentication for ipa cli scripting (wsgi, kerberos)

2017-12-04 Thread Florence Blanc-Renaud via FreeIPA-users
On 12/04/2017 03:57 PM, skrawczenko--- via FreeIPA-users wrote: Hello all, i suppose the issue is quite typical but still unable to find any solution. All i need is to run some ipa cli commands from scripts with preliminary kinit I manage to authenticate as kinit -F -k -t That allows me to

[Freeipa-users] Authentication for ipa cli scripting (wsgi, kerberos)

2017-12-04 Thread skrawczenko--- via FreeIPA-users
Hello all, i suppose the issue is quite typical but still unable to find any solution. All i need is to run some ipa cli commands from scripts with preliminary kinit I manage to authenticate as kinit -F -k -t That allows me to use ldap for example, i can do ldapsearch -Y GSSAPI etc However,

[Freeipa-users] Re: Unable to create GSSAPI-encrypted LDAP connection

2017-12-04 Thread James Harrison via FreeIPA-users
UPDATE: The principle info wrong. I did this and the error hasnt shown up since: [root@ipa-02 ~]# ipa-getkeytab --keytab=/etc/krb5.keytab --server ipa-01 -p host/ipa-02 --retrieve Keytab successfully retrieved and stored in: /etc/krb5.keytab Thanks for all your help. On Monday, 4 December

[Freeipa-users] Re: Unable to create GSSAPI-encrypted LDAP connection

2017-12-04 Thread Sumit Bose via FreeIPA-users
On Mon, Dec 04, 2017 at 09:37:41AM +, James Harrison wrote: > I ran the ipa-getkeytab command you suggested below: > This was what I got:BTW: TheIPAUSER is an admin user, but not the "admin" > user. I got the same result with the admin user. > > > ~] IPA-02 #  kinit IPAUSER Password for

[Freeipa-users] Re: Unable to create GSSAPI-encrypted LDAP connection

2017-12-04 Thread James Harrison via FreeIPA-users
I ran the ipa-getkeytab command you suggested below: This was what I got:BTW: TheIPAUSER is an admin user, but not the "admin" user. I got the same result with the admin user. ~] IPA-02 #  kinit IPAUSER Password for x_ipau...@int.example.com: ~] IPA-02 # ipa-getkeytab