[Freeipa-users] Install radius but fail to start in centos7

2018-02-11 Thread barrykfl--- via FreeIPA-users
yum install freeradius freeradius-utils freeradius-ldap freeradius-krb5 succesfuuly. But cannot start with following error and idea? : Unregistered Authentication Agent for unix-process:12922:607417 (system bus name :1.53, object path /org/freedesktop/PolicyKit1/Au ref doc:

[Freeipa-users] Re: kinit -n asking for password on clients

2018-02-11 Thread Alexander Bokovoy via FreeIPA-users
On su, 11 helmi 2018, John Ratliff via FreeIPA-users wrote: When trying to do pkinit, if I do kinit -n on one of the IdM servers, it works fine. If I try on a client machine, it asks me for the password for WELLKNOWN/ANONYMOUS@REALM. I have the pkinit_anchors setup for the realm. As I'm

[Freeipa-users] kinit -n asking for password on clients

2018-02-11 Thread John Ratliff via FreeIPA-users
When trying to do pkinit, if I do kinit -n on one of the IdM servers, it works fine. If I try on a client machine, it asks me for the password for WELLKNOWN/ANONYMOUS@REALM. I have the pkinit_anchors setup for the realm. As I'm trying to do anonymous pkinit, I think I don't need a client

[Freeipa-users] Re: 2FA and kinit

2018-02-11 Thread John Ratliff via FreeIPA-users
On 2/11/2018 7:34 PM, John Ratliff via FreeIPA-users wrote: I don't see anything useful in the logs. If I login with my key via ssh and then do a su - jratliff, it gets me a token. I don't know what su - is doing that the kinit -n steps I saw isn't, but I guess this is a workaround. su -

[Freeipa-users] Re: 2FA and kinit

2018-02-11 Thread John Ratliff via FreeIPA-users
I don't see anything useful in the logs. If I login with my key via ssh and then do a su - jratliff, it gets me a token. I don't know what su - is doing that the kinit -n steps I saw isn't, but I guess this is a workaround. su - as non-root would run PAM stack for you through pam_sss and

[Freeipa-users] Re: 2FA and kinit

2018-02-11 Thread Alexander Bokovoy via FreeIPA-users
On la, 10 helmi 2018, John Ratliff via FreeIPA-users wrote: On 2/6/2018 5:04 PM, Robbie Harwood wrote: John Ratliff via FreeIPA-users writes: I'm having problems with kinit and a 2FA enabled account. When I run kinit by itself, it says 'kinit: Generic