[Freeipa-users] Re: IPA replica cannot lookup AD trust users (worked before)

2024-04-25 Thread Sumit Bose via FreeIPA-users
Am Thu, Apr 25, 2024 at 03:03:41PM - schrieb slek kus via FreeIPA-users: > Hi, the only replica cannot retrieve AD trust users (one way trust). Trust > agent had been installed on this replica. > I noticed this issue, since clients that point to the replica started to fail > authenticating

[Freeipa-users] Re: Password expired is not requested with Ubuntu clients

2024-04-19 Thread Sumit Bose via FreeIPA-users
Am Fri, Apr 19, 2024 at 05:03:46PM + schrieb Carlos Lopez: > Of course. Here it is: > > # PAM configuration for the Secure Shell service > > # Standard Un*x authentication. > @include common-auth > > # Disallow non-root logins when /etc/nologin exists. > accountrequired

[Freeipa-users] Re: Password expired is not requested with Ubuntu clients

2024-04-19 Thread Sumit Bose via FreeIPA-users
Am Fri, Apr 19, 2024 at 08:56:36AM + schrieb Carlos Lopez via FreeIPA-users: > Good morning, > > I have configured some Ubuntu clientes to authenticate via Kerberos against > my RHEL9 IdM server. Everything works correctly: clients are authenticated, > etc. > > The problem comes when a

[Freeipa-users] Re: Support for Azure AD authentication with on-prem AD forest-trust identities

2024-03-11 Thread Sumit Bose via FreeIPA-users
Am Sun, Mar 10, 2024 at 04:46:45PM +0200 schrieb Alexander Bokovoy via FreeIPA-users: > On Суб, 09 сак 2024, Jonathan Calmels via FreeIPA-users wrote: > > Thanks for the detailed answer, glad we didn't miss anything obvious. > > I just want to add a bit more clarification on what we were

[Freeipa-users] Re: issues ssh'ing as AD user to freeipa client

2023-12-13 Thread Sumit Bose via FreeIPA-users
Am Wed, Dec 13, 2023 at 11:49:00PM + schrieb Ostrom, Erik via FreeIPA-users: > Hi, > > I'm having some issues ssh'ing as an AD user to a freeipa client, but I can > successfully ssh as the same user to the IPA master. > Our IPA domain, ipa.subdomain.contoso.com, is set up with a one-way

[Freeipa-users] Re: Unable to change ID View

2023-09-19 Thread Sumit Bose via FreeIPA-users
Am Tue, Sep 19, 2023 at 01:52:13PM - schrieb Jeremy Tourville via FreeIPA-users: > At one point we tried working with the id view feature in IPA. As a > result of that, our user group now shows up like this: > 861201183(xt...@gsil.org). Prior to the change in IPA this group > showed up as

[Freeipa-users] Re: RedHat and 2FA Problem

2023-09-19 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 18, 2023 at 03:55:32PM - schrieb Sirio Sannipoli via FreeIPA-users: > Hello everyone, > I've already done searches without success, I need someone to point me > in the direction of resolving a strange behavior I'm experiencing on > servers with the RedHat/Centos operating system.

[Freeipa-users] Re: Disable all sssd caching

2023-09-19 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 18, 2023 at 11:34:28AM -0400 schrieb Ranbir via FreeIPA-users: > Hello Everyone, > > Is there a flag to disable all caching in sssd? I know we shouldn't > disable the various caches. However, I'm working on isolating a problem > we're seeing between our firewall and AD. Hi, no,

[Freeipa-users] Re: struggling with RID base on migration from CentOS 7 to 8

2023-07-03 Thread Sumit Bose via FreeIPA-users
Am Sat, Jul 01, 2023 at 03:08:51PM +0200 schrieb Harald Dunkel via FreeIPA-users: > Hi folks, > > still trying to migrate from Centos7 to 8 I get an error message > from ipa-replica-install on the first CentOS 8 host saying > > : > Finalize replication settings > Restarting

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-28 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 28, 2023 at 08:03:58AM +0200 schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > > > > On 28 Jun 2023, at 07:50, Sumit Bose via FreeIPA-users > > wrote: > > > > Am Wed, Jun 28, 2023 at 07:23:58AM +0200 schrieb Francis Augusto > > Mede

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 28, 2023 at 07:23:58AM +0200 schrieb Francis Augusto Medeiros-Logeay: > > > > On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > > wrote: > > > > Am Fri, Jun 23, 2023 at 09:03:55AM +0200 schrieb Francis Augusto > > Medeiros-Logeay via Fr

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
a FreeIPA-users: > >> Hi Sumit, > >> > >>> On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > >>> wrote: > >>> > >>>> > >>>> No. The users are the same on both - same uid, gid, etc, but no > >>&

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
Am Tue, Jun 27, 2023 at 01:32:12PM +0200 schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > Hi Sumit, > > > On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > > wrote: > > > >> > >> No. The users are the same on both - same uid

[Freeipa-users] Re: local root can login but freeipa users can't

2023-06-25 Thread Sumit Bose via FreeIPA-users
Am Fri, Jun 23, 2023 at 12:25:03AM - schrieb barry y via FreeIPA-users: > This happen randomly, local root can login through SSH to the affected system > but for freeipa user, login was successful but there's no prompt. > When successfully logged in, it only display a message saying "Last

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-23 Thread Sumit Bose via FreeIPA-users
Am Fri, Jun 23, 2023 at 09:03:55AM +0200 schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > > > > On 22 Jun 2023, at 14:48, Rob Crittenden via FreeIPA-users > > wrote: > > > > Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: > >> Hi, > >> > >> We have an application that

[Freeipa-users] Re: AD Trust not authenticating users

2023-06-08 Thread Sumit Bose via FreeIPA-users
Am Thu, Jun 08, 2023 at 03:37:12PM - schrieb James Osbourn via FreeIPA-users: > Thanks I will take a look at the link. > > The krb5.conf file looks as follows > includedir /etc/krb5.conf.d/ > includedir /var/lib/sss/pubconf/krb5.include.d/ > > [logging] > default =

[Freeipa-users] Re: AD Trust not authenticating users

2023-06-08 Thread Sumit Bose via FreeIPA-users
Am Thu, Jun 08, 2023 at 11:48:58AM - schrieb James Osbourn via FreeIPA-users: > I have an inherited IPA domain that is a subdomain of an active directory > domain, e.g. ipa.ad1.com as a child of ad1.com. The IPA domain has AD Trust > enabled and a one way domain trust to another AD sub

[Freeipa-users] Re: IPA fails to find certain AD groups

2023-06-07 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 07, 2023 at 05:10:15PM +0200 schrieb Ronald Wimmer via FreeIPA-users: > On 07.06.23 17:07, Ronald Wimmer via FreeIPA-users wrote: > > On 07.06.23 14:27, Ronald Wimmer via FreeIPA-users wrote: > > > When trying to add an AD group in an external group IPA fails to add > > > certain

[Freeipa-users] Re: ipa user-add-cert and org.freedesktop.sssd.infopipe.Users.FindByCertificate into ps12 and mozilla certificate manager

2023-06-01 Thread Sumit Bose via FreeIPA-users
che HTTP > server for several years now. > > On Thu, 1 Jun 2023 18:32:07 +0200 > Jelle de Jong via FreeIPA-users > wrote: > > > On 6/1/23 15:18, Sumit Bose via FreeIPA-users wrote: > > > Am Thu, Jun 01, 2023 at 02:18:40PM +0200 schrieb Jelle de Jong via

[Freeipa-users] Re: ipa user-add-cert and org.freedesktop.sssd.infopipe.Users.FindByCertificate into ps12 and mozilla certificate manager

2023-06-01 Thread Sumit Bose via FreeIPA-users
Am Thu, Jun 01, 2023 at 02:18:40PM +0200 schrieb Jelle de Jong via FreeIPA-users: > Hello everybody, > > I am looking for a way to digitally sign documents by end-users within an > organisation. Hi, correct me if I'm wrong, but to my understanding the certificate is not sufficient for a

[Freeipa-users] Re: SSSD Log stops working - Backtrafe dump ends here

2023-05-11 Thread Sumit Bose via FreeIPA-users
Am Thu, May 11, 2023 at 11:48:45AM - schrieb J N via FreeIPA-users: > > Am Thu, May 04, 2023 at 06:49:06AM - schrieb Finn Fysj via > > FreeIPA-users: > > > > Hi, > > > > the above is part of the access control when a user is trying to log in. > > As the messages says there are no HBAC

[Freeipa-users] Re: SSSD Log stops working - Backtrafe dump ends here

2023-05-08 Thread Sumit Bose via FreeIPA-users
Am Thu, May 04, 2023 at 06:49:06AM - schrieb Finn Fysj via FreeIPA-users: > I've tried to install and re-install the IPAserver on my node. Even tried to > re-provision it. When I look in the SSSD log for my domain I get the > following: > >* (2023-05-04 6:30:59): [be[lab.local]]

[Freeipa-users] Re: Running 'sudo su' creates kerberos ticket for user on old IPA (4.6) not on new 4.10

2023-05-03 Thread Sumit Bose via FreeIPA-users
Am Wed, May 03, 2023 at 02:40:30PM - schrieb Finn Fysj via FreeIPA-users: > > Am Wed, May 03, 2023 at 12:00:16PM - schrieb Finn Fysj via > > FreeIPA-users: > > > > Hi, > > > > the behavior was changed due to > > https://bugzilla.redhat.com/show_bug.cgi?id=1879869 > >

[Freeipa-users] Re: Running 'sudo su' creates kerberos ticket for user on old IPA (4.6) not on new 4.10

2023-05-03 Thread Sumit Bose via FreeIPA-users
Am Wed, May 03, 2023 at 12:00:16PM - schrieb Finn Fysj via FreeIPA-users: > I'm trying to setup new IPA server and when I run 'sudo su' I get > prompted with password, which is fine. > However, when I successfully type my password on a RHEL7 instance > running FreeIPA version 4.6 I get a

[Freeipa-users] Re: access IPA client via ssh does not work

2023-03-20 Thread Sumit Bose via FreeIPA-users
Am Fri, Mar 17, 2023 at 02:21:33PM - schrieb None via FreeIPA-users: > I have a fresh IPA server setup with a trust to an Active Directory. Alls IPA > services are working fine, IPA users can connect to IPA client hosts without > problems. > > I now have added an AD user via creating an ID

[Freeipa-users] Re: Disabled Domain fills IPA client sssd logs

2023-02-17 Thread Sumit Bose via FreeIPA-users
Am Fri, Feb 17, 2023 at 08:51:03AM +0100 schrieb Ronald Wimmer: > > > On 16.02.23 12:18, Sumit Bose wrote: > > Am Thu, Feb 16, 2023 at 12:14:02PM +0100 schrieb Ronald Wimmer via > > FreeIPA-users: > > > We do face the problem that we disabled a domain we do not need and that > > > this

[Freeipa-users] Re: Disabled Domain fills IPA client sssd logs

2023-02-16 Thread Sumit Bose via FreeIPA-users
Am Thu, Feb 16, 2023 at 12:14:02PM +0100 schrieb Ronald Wimmer via FreeIPA-users: > We do face the problem that we disabled a domain we do not need and that > this particular domain fills up sssd logs on the client side. Especially > sssd_nss.log. How could we possibly avoid this behavior? Hi,

[Freeipa-users] Re: Issue with Login PIN Prompting with SSSD and krb5_child.

2023-02-08 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 08, 2023 at 08:37:11AM - schrieb r0 nam1 via FreeIPA-users: > Uploaded logs that were created when logged in: > https://temp.sh/FwJrh/terminallogs.zip > (By 'tail -f' while logging in) Hi, it looks like you have added ipacertmapdata base mapping rule, but there is no user in IPA

[Freeipa-users] Re: Issue with Login PIN Prompting with SSSD and krb5_child.

2023-02-07 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 08, 2023 at 12:45:57AM - schrieb r0 nam1 via FreeIPA-users: > Realized I never set up any mapping rules, fixed that and they match properly. > Looking at the krb5_log now that's working, I see a few lines of interest: > [sss_krb5_prompter] (0x4000): sss_krb5_prompter name [(null)]

[Freeipa-users] Re: Issue with Login PIN Prompting with SSSD and krb5_child.

2023-02-05 Thread Sumit Bose via FreeIPA-users
Am Fri, Feb 03, 2023 at 07:16:58PM - schrieb r0 nam1 via FreeIPA-users: > Apologies for my previous thread mess, I've learned to keep it neat. > > In following my previous thread >

[Freeipa-users] Re: Cannot Login with IPA user account

2023-01-09 Thread Sumit Bose via FreeIPA-users
Am Mon, Jan 09, 2023 at 02:06:44PM - schrieb Damola Azeez via FreeIPA-users: > Hi, > > Here is the krb5_child.log > > https://pastebin.com/zkcSBhAJ Hi, (2023-01-05 14:50:58): [krb5_child[22846]] [get_and_save_tgt] (0x0020): 1709: [-1765328347][Clock skew too great] (2023-01-05 14:50:58):

[Freeipa-users] Re: Cannot Login with IPA user account

2023-01-09 Thread Sumit Bose via FreeIPA-users
Am Mon, Jan 09, 2023 at 12:36:35PM - schrieb Damola Azeez via FreeIPA-users: > Hi, > > here is the domain log from around the same time > > https://pastebin.com/EBQzQ7d0 Hi, thanks, looks like the error is coming from krb5_child: (2023-01-05 14:50:58): [be[domain.com]]

[Freeipa-users] Re: Cannot Login with IPA user account

2023-01-05 Thread Sumit Bose via FreeIPA-users
Am Thu, Jan 05, 2023 at 01:42:11PM - schrieb Damola Azeez via FreeIPA-users: > Here is the link to sssd_pam.log after setting debug value to 9 > > https://pastebin.com/embed_js/U345NVwA Hi, the PAM responders receives (2023-01-05 14:50:58): [pam] [pam_dp_process_reply] (0x0200):

[Freeipa-users] Re: Users can login only sometimes with a IPA-AD trust

2023-01-04 Thread Sumit Bose via FreeIPA-users
Am Wed, Jan 04, 2023 at 01:23:53PM -0300 schrieb tizo: > > > > Hi, > > > > 'Decrypt integrity check failed' typically means that the wrong > > Kerberos password or key was used. Since you are using FAST it might > > either be the user password the user is typing in or the host key which > > was

[Freeipa-users] Re: Users can login only sometimes with a IPA-AD trust

2023-01-04 Thread Sumit Bose via FreeIPA-users
Am Wed, Jan 04, 2023 at 11:52:21AM -0300 schrieb tizo via FreeIPA-users: > We have an IPA-AD trust up and running. The IPA domain is > idm.fnr.gub.uy and the AD (Samba) domain is smb.fnr.gub.uy. Our users > belong to AD. > > We have a couple of Ubuntu 22.04 IPA clients configured. In the first >

[Freeipa-users] Re: Cannot Login with IPA user account

2023-01-02 Thread Sumit Bose via FreeIPA-users
Am Fri, Dec 30, 2022 at 11:17:59AM - schrieb Damola Azeez via FreeIPA-users: > After setting up my IPA environment, I am unable to log in successfully on > some of my Linux servers. When I check /var/log/secure for authentication > logs, I see the errors below > > Dec 30 12:18:31

[Freeipa-users] Re: External IDP Configuration with Okta

2022-11-09 Thread Sumit Bose via FreeIPA-users
Am Wed, Nov 09, 2022 at 08:09:16PM - schrieb Russ Long via FreeIPA-users: > Hello, > > I am working on a test environment to test the integration of Okta as an > external IDP. According to the docs, this is supported, however there is no > okta-specific documentation that I can find. Hi,

[Freeipa-users] Re: IPA-Domain not shown

2022-09-28 Thread Sumit Bose via FreeIPA-users
Am Wed, Sep 28, 2022 at 09:29:46PM +0200 schrieb Ronald Wimmer via FreeIPA-users: > On 28.09.22 20:18, Rob Crittenden wrote: > > Ronald Wimmer via FreeIPA-users wrote: > > > We set up IPA in a new network segment. Everything works fine but when I > > > issue > > > > > > getent passwd

[Freeipa-users] Re: [hbac_evaluate] (0x0100): The rule [somerulename] did not match.

2022-09-23 Thread Sumit Bose via FreeIPA-users
Am Fri, Sep 23, 2022 at 01:07:24PM +0200 schrieb Ronald Wimmer via FreeIPA-users: > I tried to give user access permissions to a specific host but when I try to > log in via ssh I get an error: > > [hbac_evaluate] (0x0100): The rule [somerulename] did not match. Hi, near the log line above

[Freeipa-users] Re: Connection Reset upon kinit

2022-09-19 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 19, 2022 at 11:23:34AM +0200 schrieb Ronald Wimmer: > On 19.09.22 10:41, Sumit Bose via FreeIPA-users wrote: > > Am Mon, Sep 19, 2022 at 08:28:56AM +0200 schrieb Ronald Wimmer via > > FreeIPA-users: > > > On 14.09.22 19:23, Rob Crittenden wrote: > > >

[Freeipa-users] Re: Connection Reset upon kinit

2022-09-19 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 19, 2022 at 08:28:56AM +0200 schrieb Ronald Wimmer via FreeIPA-users: > On 14.09.22 19:23, Rob Crittenden wrote: > > Ronald Wimmer via FreeIPA-users wrote: > > > Hi, > > > > > > on one of our ipa servers kinit stopped working. kinit admin shows an > > > error: > > > > > > kinit:

[Freeipa-users] Re: Access denied for uid [389]

2022-08-14 Thread Sumit Bose via FreeIPA-users
Am Sun, Aug 14, 2022 at 04:34:30PM +0100 schrieb lejeczek via FreeIPA-users: > Hi guys. > > Domain seems to function okey, 'healthcheck' reports no issues, but these > begin to worry me, from sssd_pac.log > ... > (2022-08-14 16:19:52): [pac] [accept_fd_handler] (0x0020): Access denied for > uid

[Freeipa-users] Re: SSSD prompting/2fa

2022-07-10 Thread Sumit Bose via FreeIPA-users
Am Fri, Jul 08, 2022 at 09:28:34PM +0200 schrieb Sigbjorn Lie-Soland: > > > > On 8 Jul 2022, at 12:18, Sumit Bose wrote: > > > > Am Fri, Jul 08, 2022 at 11:47:13AM +0200 schrieb Sigbjorn Lie-Soland: > >> > >> > >>> On 8 Jul 2022, at 08:38, Sumit Bose wrote: > >>> > >>> Am Fri, Jun 03, 2022

[Freeipa-users] Re: SSSD prompting/2fa

2022-07-08 Thread Sumit Bose via FreeIPA-users
Am Fri, Jul 08, 2022 at 11:47:13AM +0200 schrieb Sigbjorn Lie-Soland: > > > > On 8 Jul 2022, at 08:38, Sumit Bose wrote: > > > > Am Fri, Jun 03, 2022 at 09:19:51AM +0200 schrieb Sigbjorn Lie via > > FreeIPA-users: > >> Hi list, > >> > >> When I have a 2FA enabled user account, I receive the

[Freeipa-users] Re: SSSD prompting/2fa

2022-07-08 Thread Sumit Bose via FreeIPA-users
Am Fri, Jun 03, 2022 at 09:19:51AM +0200 schrieb Sigbjorn Lie via FreeIPA-users: > Hi list, > > When I have a 2FA enabled user account, I receive the two password prompt > for sudo at a host, even on hosts where 2FA is not required. This breaks > Ansible for me, when using "become" with Ansible.

[Freeipa-users] Re: Can the UPN searched for in a trust be modied?

2022-06-14 Thread Sumit Bose via FreeIPA-users
Am Tue, Jun 14, 2022 at 12:48:52PM -0400 schrieb Ranbir via FreeIPA-users: > Hello Everyone, > > I have a situation where users' UPN in AD for the domain that my ipa > domain has a trust with has been modified to look nothing like the > domain account. The user name and suffix entered in the UPN

[Freeipa-users] Re: [SSSD] Announcing SSSD 2.7.1

2022-06-08 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 08, 2022 at 01:40:22AM -0400 schrieb Ranbir via FreeIPA-users: > On Thu, 2022-06-02 at 13:33 +0200, Pavel Březina via FreeIPA-users > wrote: > > # SSSD 2.7.1 > > > > > > ### Configuration changes > > > > * New option `implicit_pac_responder` to control if the PAC responder > > is >

[Freeipa-users] Re: krbPrincipalExpiration and ssh keys

2022-06-02 Thread Sumit Bose via FreeIPA-users
Am Thu, Jun 02, 2022 at 02:22:54PM -0400 schrieb Rob Crittenden via FreeIPA-users: > Jim Kinney via FreeIPA-users wrote: > > It seems if valid ssh keys exist, the expired account status doesn't > > block login with ssh keys. Any operation that touches a password is > > blocking. > > Is there a

[Freeipa-users] Re: SSSD login stopped working on Ubuntu 22.04

2022-05-24 Thread Sumit Bose via FreeIPA-users
Am Tue, May 24, 2022 at 07:45:01PM +0530 schrieb Joyce Babu via FreeIPA-users: > Hello Sumit, > > I have generated the logs files. > > Is it okay, if I email the files directly to you? Hi, sure bye, Sumit > > *Thanks and regards,* > Joyce Babu >

[Freeipa-users] Re: SSSD login stopped working on Ubuntu 22.04

2022-05-24 Thread Sumit Bose via FreeIPA-users
Am Tue, May 17, 2022 at 08:22:30PM - schrieb Joyce Babu via FreeIPA-users: > Thank you for your response. > > The password I entered is alpha numeric with no special characters. Also, I > tried to login to both the old and new client through SSH from my laptop. So, > it is not a keyboard

[Freeipa-users] Re: SSSD Problem after update

2022-05-24 Thread Sumit Bose via FreeIPA-users
Am Mon, May 23, 2022 at 08:48:46AM +0200 schrieb Ronald Wimmer via FreeIPA-users: > Today I updated all packages on one of our IPA servers. Unfortunately, SSSD > stopped working: Hi, to which package version did you update? bye, Sumit > > [sssd] [main] (0x0010): SSSD couldn't load the

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-17 Thread Sumit Bose via FreeIPA-users
Am Tue, May 17, 2022 at 01:32:15PM - schrieb Bayo A via FreeIPA-users: > Hi Rob, > > The error Client 'host/xxx@XXX' not found in Kerberos > database" which I'm also having in my environment. > > My IPA and AD realms use the same name however I'm not using DNS in my > implementation as

[Freeipa-users] Re: SSSD login stopped working on Ubuntu 22.04

2022-05-17 Thread Sumit Bose via FreeIPA-users
Am Tue, May 17, 2022 at 02:29:24PM - schrieb Joyce Babu via FreeIPA-users: > I have a FreeIPA installation with many Pop!_OS 21.10 clients. Today I > upgraded one of the clients to Pop!_OS 22.04, and I can no longer > authenticate with FreeIPA on the upgraded client. > > In krb5kdc.log file

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-17 Thread Sumit Bose via FreeIPA-users
Am Mon, May 16, 2022 at 01:20:27PM - schrieb Damola Azeez via FreeIPA-users: > What if i use the host file for name resolution? Hi, this would not be sufficient. With careful manual configuration in multiple configuration files you might be able to get some features working. But this would

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-12 Thread Sumit Bose via FreeIPA-users
Am Thu, May 12, 2022 at 09:58:40AM - schrieb Damola Azeez via FreeIPA-users: > From the dig -t SRV _kerberos._tcp.xxx output, > > 192.168.101.160 which is the IPA server didn't show. The other 3 IP addresses > showed up. Those 3 IP addresses act as the DNS server and AD server for the >

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-11 Thread Sumit Bose via FreeIPA-users
Am Wed, May 11, 2022 at 03:10:06PM - schrieb Damola Azeez via FreeIPA-users: > Hi Sumit, Thanks for the assistance. > > Please find the ldap_child.log file in the link below > > https://pastebin.com/pKp1tvCt Hi, thanks for the log. It looks like the KDC with the IP address 192.168.101.160

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-11 Thread Sumit Bose via FreeIPA-users
Am Wed, May 11, 2022 at 02:19:23PM - schrieb Damola Azeez via FreeIPA-users: > Hi, > > The above should be done on the IPA client right? Hi, yes. bye, Sumit > ___ > FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org > To

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-11 Thread Sumit Bose via FreeIPA-users
Am Wed, May 11, 2022 at 12:14:56PM - schrieb Damola Azeez via FreeIPA-users: > Hi, > > Output below Hi, thanks, so this is working as expected, SSSD's ldap_child basically does the same. Can you add 'debug_level = 9' to the [domain/...] section of sssd.conf, restart SSSD, try to lookup some

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-11 Thread Sumit Bose via FreeIPA-users
Am Wed, May 11, 2022 at 08:47:49AM - schrieb Damola Azeez via FreeIPA-users: > Hi, > > below is the output of ipa host-show epmtestapp > > > Host name: epmtestapp.xxx > Platform: x86_64 > Operating system: 4.1.12-124.16.4.el6uek.x86_64 > Certificate: --- > Subject:

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-10 Thread Sumit Bose via FreeIPA-users
Am Tue, May 10, 2022 at 03:57:19PM - schrieb Damola Azeez via FreeIPA-users: > Output of 'klist -k' > > Keytab name: FILE:/etc/krb5.keytab > KVNO Principal > > -- >1 host/epmtestapp.xxx@XXX >1

[Freeipa-users] Re: Unable to Login using LDAP User

2022-05-10 Thread Sumit Bose via FreeIPA-users
Am Tue, May 10, 2022 at 02:17:18PM - schrieb Damola Azeez via FreeIPA-users: > I've installed FreeIPA on all host I manage and everything has been fine > until today when had to reboot the whole hosts. Every other host worked > except one. checking the log file of the server, i saw the below

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-05-02 Thread Sumit Bose via FreeIPA-users
Am Mon, May 02, 2022 at 03:15:05PM -0300 schrieb tizo: > On Mon, May 2, 2022 at 2:36 PM Sumit Bose wrote: > > > > Am Mon, May 02, 2022 at 12:32:34PM -0300 schrieb tizo: > > > On Mon, May 2, 2022 at 11:56 AM Sumit Bose wrote: > > > > > > > > Am Mon, May 02, 2022 at 11:39:40AM -0300 schrieb tizo:

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-05-02 Thread Sumit Bose via FreeIPA-users
Am Mon, May 02, 2022 at 12:32:34PM -0300 schrieb tizo: > On Mon, May 2, 2022 at 11:56 AM Sumit Bose wrote: > > > > Am Mon, May 02, 2022 at 11:39:40AM -0300 schrieb tizo: > > > > Hi, > > > > > > > > thanks, at least I received your email. Can you run the tests with > > > > "krb5_use_fast = never"

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-05-02 Thread Sumit Bose via FreeIPA-users
Am Mon, May 02, 2022 at 11:39:40AM -0300 schrieb tizo: > > Hi, > > > > thanks, at least I received your email. Can you run the tests with > > "krb5_use_fast = never" and "krb5_use_enterprise_principal = True" again > > but with 'debug_level = 9' in the [domain/...] section of sssd.conf. > > This

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-05-02 Thread Sumit Bose via FreeIPA-users
Am Mon, May 02, 2022 at 09:31:37AM -0300 schrieb tizo: > > > > Hi, > > > > can you try if adding > > > > krb5_use_enterprise_principal = True > > > > help? If not, please send full SSSD logs (everything in /var/log/sssd) > > next time. > > > > bye, > > Sumit > > > > Hi and thanks Sumit. I

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-04-28 Thread Sumit Bose via FreeIPA-users
Am Mon, Apr 25, 2022 at 01:23:05PM -0300 schrieb tizo via FreeIPA-users: > On Mon, Apr 25, 2022 at 12:23 PM tizo wrote: > > > > > Hi, > > > > > > thanks for the logs. The issue does not happen during Kerberos ticket > > > validation, as I thought but while trying to establish the FAST tunnel. > >

[Freeipa-users] Re: error: PAM: User account has expired for

2022-04-27 Thread Sumit Bose via FreeIPA-users
Am Wed, Apr 27, 2022 at 02:50:42PM - schrieb Ben Aveling via FreeIPA-users: > We're having users unable to login on some hosts. > > The error message in /var/log/secure is: > > sshd[29399]: error: PAM: User account has expired for <> from > <> > > The same users can login fine to other

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-04-07 Thread Sumit Bose via FreeIPA-users
Am Thu, Apr 07, 2022 at 05:07:00PM -0300 schrieb Mateo Duffour: > Hi, > > The last answer that we received on bugzilla and on samba lists sais "Your > kpasswd is expecting FAST support which has been added in samba 4.16. So you > either have to disable FAST or upgrade first." > > We've

[Freeipa-users] Re: Login without having to use `@ad_domain` - is it possible?

2022-04-06 Thread Sumit Bose via FreeIPA-users
Am Wed, Apr 06, 2022 at 08:29:21AM - schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > Hi, > I wonder if it is possible to configure a FreeIPA client to assume that > clients logging in are from a trusted AD domain, instead of having those > users to type `username@ad_domain`

[Freeipa-users] Re: IPA AD Authentication not successfull if using alernative logon domain

2022-03-16 Thread Sumit Bose via FreeIPA-users
Am Wed, Mar 16, 2022 at 03:24:40PM - schrieb Florian Wilhelm via FreeIPA-users: > We are successfully running a FreeIPA setup connected to an AD using kerberos > to authenticate. (IPA is used as provider). > Our windows domain name is not identical to our main mail domain. For some > users

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-03-11 Thread Sumit Bose via FreeIPA-users
Am Fri, Mar 11, 2022 at 01:32:50PM -0300 schrieb Mateo Duffour: > Hi, > > I've send the network capture attached, it was made with tcpdump in the IdM > server to the Samba AD DC server, while trying to log in with ssh with user5. Hi, thanks for the network trace. Alexander, can you have a

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-03-10 Thread Sumit Bose via FreeIPA-users
Am Thu, Mar 10, 2022 at 06:11:41PM -0300 schrieb Mateo Duffour: > I made a mistake and copied other log, the log of the test mentioned is: > > Mar 10 18:08:08 idmsrvpru.idmpru.xxx.xxx.xx krb5_child[45687]: Password has > expired > Mar 10 18:08:08 idmsrvpru.idmpru.xxx.xxx.xx krb5_child[45687]:

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-03-10 Thread Sumit Bose via FreeIPA-users
Am Thu, Mar 10, 2022 at 01:34:27PM -0300 schrieb Mateo Duffour: > Hi Sumit, > > I have attached all the files you requested, this test was done with user > usu5 which has its password expired. Hi, thanks for the new logs. Can you check if adding krb5_use_enterprise_principal = True to

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-03-10 Thread Sumit Bose via FreeIPA-users
Am Tue, Mar 08, 2022 at 01:42:53PM -0300 schrieb Mateo Duffour: > Hi, thanks again for the quick reply. > Sorry i did not have the time to test it again until now, i tried your > recomendations. > > Its still behaving the same way than before, so I attached the sssd_pam.log > you requested

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-02-28 Thread Sumit Bose via FreeIPA-users
Am Fri, Feb 25, 2022 at 11:21:55AM -0300 schrieb Mateo Duffour: > Hi, > > I send you attached the files needed, let me know if you need something else. Hi, thanks for the file, they look ok. After looking again at what you send I came across Feb 23 08:14:35 idmsrvpru.idmpru.fnr.gub.uy

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-02-24 Thread Sumit Bose via FreeIPA-users
Am Thu, Feb 24, 2022 at 11:53:07AM -0300 schrieb Mateo Duffour via FreeIPA-users: > Which /etc/pam.d/ config file do you need ? Hi, from the logs below it looks like you are using ssh to log in, so it would be /etc/pam.d/sshd and all the files which might be referenced in that file. bye,

[Freeipa-users] Re: IdM with trust relationship with Samba AD DC - User accounts with passwords expired

2022-02-23 Thread Sumit Bose via FreeIPA-users
Am Tue, Feb 22, 2022 at 03:40:27PM -0300 schrieb Mateo Duffour via FreeIPA-users: > Hi, > > We currently have an IdM installation with a trust relationship with a Samba > AD DC. Our user accounts reside on Samba AD DC, we dont have user accounts on > IdM. > We are having a problem with Samba

[Freeipa-users] Re: FreeIPA, kinit with OTP

2022-02-21 Thread Sumit Bose via FreeIPA-users
Am Tue, Feb 22, 2022 at 07:42:18AM +0100 schrieb Michael Schwartzkopff via FreeIPA-users: > On 22.02.22 00:08, Angus Clarke wrote: > > I was meant to have attached the script sorry! > > > > Attached now. > > > > Hope it helps > > Angus > > > > From: Michael

[Freeipa-users] Re: FreeIPA, kinit with OTP

2022-02-21 Thread Sumit Bose via FreeIPA-users
Am Fri, Feb 18, 2022 at 02:06:24PM +0100 schrieb Michael Schwartzkopff via FreeIPA-users: > Hi, > > > I want to use OTP for krb tickets. Plain login works as expected. When I > start kinit user I get the response: > > $ kinit user > > kinit: Generic preauthentication failure while getting

[Freeipa-users] Re: Not possible to find KDC with Autodiscovery

2022-02-16 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 16, 2022 at 03:09:00PM - schrieb David Galarreta via FreeIPA-users: > Hello! > we get the next error when we try to create a kerberos ticket: > kinit: Cannot find KDC for realm "TEST.INTERN" while getting initial > credentials > > /etc/krb5.conf: > [libdefaults] >

[Freeipa-users] Re: Increasing SSSD primary-master reconnection interval

2022-02-10 Thread Sumit Bose via FreeIPA-users
Am Mon, Feb 07, 2022 at 10:09:36PM - schrieb Bill M via FreeIPA-users: > Hi there, > > I've a primary and three secondary servers in the sssd.conf on my IPA > clients. The failover works as expected, and from the logs I can see > the client attempting to reconnect to the primary server every

[Freeipa-users] Re: use ipa-user with xorg

2022-02-09 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 09, 2022 at 11:09:02AM - schrieb Sascha Hartl via FreeIPA-users: > Hello > > could now verify it's not the subdirectory > > i performe a homdirectory-override to /home/testuser in sssd.conf, > the error is the same > > Failed to import environment: Process

[Freeipa-users] Re: use ipa-user with xorg

2022-02-09 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 09, 2022 at 08:57:04AM - schrieb Sascha Hartl via FreeIPA-users: > found this in addition > > [root@host testuser]# cat .xsession-errors > Failed to import environment: Process org.freedesktop.systemd1 exited with > status 1 > /etc/X11/xinit/Xsession: line 88:

[Freeipa-users] Re: use ipa-user with xorg

2022-02-08 Thread Sumit Bose via FreeIPA-users
Am Wed, Feb 09, 2022 at 07:21:33AM - schrieb Sascha Hartl via FreeIPA-users: > Hello > > I'm looking for a solution to use IPA and AD Users via IPA-provider for xorg > Sessions on OL8. > I've found some methods with "access_provider = ad" or "access_provider = > simple" but i use

[Freeipa-users] Re: "getent group -s sss" behaves differently on centos 7 vs centos 8. Why?

2022-02-07 Thread Sumit Bose via FreeIPA-users
le_files_domain = false' will switch off the handling of the local files in SSSD and let glibc and the nss modules collect the group members. HTH bye, Sumit > > On Mon, Feb 7, 2022 at 3:13 AM Sumit Bose via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > >

[Freeipa-users] Re: "getent group -s sss" behaves differently on centos 7 vs centos 8. Why?

2022-02-07 Thread Sumit Bose via FreeIPA-users
Am Thu, Jan 27, 2022 at 04:06:19PM -0600 schrieb Russell Jones via FreeIPA-users: > Hi all, > > I am very confused on why I am not able to enumerate the group members on a > centos 8 machine with the above command, but I can on a centos 7 machine. > > [root@centos8-1 log]# getent group -s sss

[Freeipa-users] Re: SSH with password fails - 7 (Authentication failure)

2022-01-16 Thread Sumit Bose via FreeIPA-users
Am Sun, Jan 16, 2022 at 12:50:28PM + schrieb lejeczek via FreeIPA-users: > Hi guys. > > This have puzzled my and left clueless. > It's a fresh new deployment and still only single master. > Very first & only user and I cannot 'ssh' with password - but krb ticket I > can obtain and 'ssh' with

[Freeipa-users] Re: [pam] [sss_dp_on_reconnect] (0x0010): Could not reconnect to provider.

2022-01-03 Thread Sumit Bose via FreeIPA-users
Am Tue, Dec 21, 2021 at 01:25:20PM - schrieb Alexander Becker via FreeIPA-users: > Hello all, > > since some time we have some cases where a sssd login does not work anymore > and a service restart is necessary. According to analysis, there is a high > disk and CPU usage at that time. >

[Freeipa-users] Re: 2FA - prompting - single_prompt

2022-01-03 Thread Sumit Bose via FreeIPA-users
Am Thu, Dec 23, 2021 at 01:13:32PM +0100 schrieb Winfried de Heiden via FreeIPA-users: > Hi all, > > Using FreeIPA, 2FA can be made optional by enabling "Password" AND "Two > factor authentication (password + OTP)" for a user. For particular hosts the > 2FA now can be made mandatory by enabling

[Freeipa-users] Re: /var/lib/sss/pubconf/krb5.include.d/domain_realm_domain_name file, what for?

2021-12-15 Thread Sumit Bose via FreeIPA-users
Am Wed, Dec 15, 2021 at 01:35:49PM -0300 schrieb tizo via FreeIPA-users: > On Wed, Dec 15, 2021 at 10:24 AM tizo wrote: > > > Just another problem of my lab about IPA trusting AD (but very close to > > the end). We have this trust relation between IPA and AD. The IPA server is > > installed on a

[Freeipa-users] Re: Clear sssd cache

2021-12-14 Thread Sumit Bose via FreeIPA-users
Am Tue, Dec 14, 2021 at 01:05:52PM +0100 schrieb Ronald Wimmer via FreeIPA-users: > On 10.12.21 09:50, Florence Blanc-Renaud wrote: > > Hi, > > > > You can have a look at > >

[Freeipa-users] Re: OTP behaviour on Debian

2021-12-14 Thread Sumit Bose via FreeIPA-users
Am Mon, Dec 13, 2021 at 06:14:13PM - schrieb Sam Morris via FreeIPA-users: > You're absolutely right. On Debian in /etc/pam.d/common-auth we have: > > # here are the per-package modules (the "Primary" block) > auth[success=2 default=ignore] pam_unix.so nullok > auth[success=1

[Freeipa-users] Re: OTP behaviour on Debian

2021-12-13 Thread Sumit Bose via FreeIPA-users
Am Mon, Dec 13, 2021 at 01:34:12PM - schrieb Sam Morris via FreeIPA-users: > I enabled OTP for my user. On RHEL and Fedora systems, I get the > expected interactive 'first factor' followed by 'second factor' > prompts which work fine. > > On a Debian system, PAM still only gives me the single

[Freeipa-users] Re: set homedir to /home/%u to AD user with FreeIPA

2021-11-30 Thread Sumit Bose via FreeIPA-users
Am Tue, Nov 30, 2021 at 04:26:11PM +0200 schrieb Alexander Bokovoy via FreeIPA-users: > On ti, 30 marras 2021, Jan Poctavek via FreeIPA-users wrote: > > Hi, > > > > Maybe I'm just missing something very trivial but I have trouble setting > > user homedirs to a value of /home/%u instead of

[Freeipa-users] Re: freeipa upgrade from CentOS7 -> CentOS8 results in SSSD backtrace (but still functional)

2021-11-18 Thread Sumit Bose via FreeIPA-users
Am Wed, Nov 17, 2021 at 03:06:16PM -0500 schrieb Rob Crittenden via FreeIPA-users: > Andrei Neagoe via FreeIPA-users wrote: > > Hey Rob, > > > > Yes, it was an attempt to see if I can "fix" the issue. The problem was > > there even before I added the new range. We have only a handful of users,

[Freeipa-users] Re: klist Valid and expiry dates problem 01/01/70 10:00:00

2021-11-15 Thread Sumit Bose via FreeIPA-users
Am Mon, Nov 15, 2021 at 09:21:43AM - schrieb Tony Delov via FreeIPA-users: > I'm reasonably sure the time is ok (on the client at least). > I actually have been removing the cache and restarting. My ID was not in the > cache. Hi, which version of SSSD are you using? Can you added

[Freeipa-users] Re: cannot find name for group ID x when logging in

2021-11-05 Thread Sumit Bose via FreeIPA-users
Am Thu, Nov 04, 2021 at 11:07:25PM - schrieb Mark Johnson via FreeIPA-users: > Got my authentication working and I populated my directory with users > and groups and assigned group memberships accordingly. I wasn't > getting this issue originally, but now I'm suddenly getting the > "cannot

[Freeipa-users] Re: pam_sss account Access denied (permission denied)

2021-10-27 Thread Sumit Bose via FreeIPA-users
Am Thu, Oct 28, 2021 at 02:16:25AM - schrieb Mark Johnson via FreeIPA-users: > OK, I finally managed to get a successful login using an ldap access filter. > The filter wasn't the real issue. I noticed from the debug logs in sssd that > the DN didn't look right (cn=compat instead of

[Freeipa-users] Re: pam_sss account Access denied (permission denied)

2021-10-27 Thread Sumit Bose via FreeIPA-users
Am Wed, Oct 27, 2021 at 07:58:50AM - schrieb Mark Johnson via FreeIPA-users: > I've been struggling with this all day and I'm getting nowhere. We're > wanting to migrate from a 389-DS authenticated network to FreeIPA. We have a > few Linux servers scattered around the world that

[Freeipa-users] Re: sss_ssh_authorizedkeys vs user certificates

2021-09-23 Thread Sumit Bose via FreeIPA-users
Am Thu, Sep 23, 2021 at 02:12:20PM -0400 schrieb Rob Crittenden via FreeIPA-users: > Radoslaw Kujawa via FreeIPA-users wrote: > > Hi. > > > > On 9/23/21 15:06, Sumit Bose via FreeIPA-users wrote: > >> Am Thu, Sep 23, 2021 at 12:33:25PM +0200 schrieb Radoslaw

  1   2   3   4   >