Re: [Freeipa-users] Admin password no more working

2016-08-19 Thread Martin Kosek
On 08/18/2016 04:16 PM, Deepak Dimri wrote: > Hi All, > > While trying to automate IPA client registration programatically, i seems > have > made my admin password out of sync between KDC and > /etc/krb5.keytab. This looks confusing, admin password and /etc/krb5.keytab do not look related. The

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-03 Thread Christopher Lamb
tt ." , Janelle Cc: "freeipa-users@redhat.com" Date: 03.08.2015 08:49 Subject: Re: [Freeipa-users] Admin password not accepted during replica install Sent by:freeipa-users-boun...@redhat.com When this command failed for me, it usually was a proble

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-02 Thread Martin Kosek
When this command failed for me, it usually was a problem with SSSD on the master. The service was down, offline or simply something wrong was with it. On the master, I would try: $ id admin $ ssh admin@localhost # (with password) If that works, try manual $ ssh admin@ipa.master.server # with p

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Matt .
I even checked working version (IPA clusters) and they don't even have this AllowGroups. Am I missing something ? 2015-08-01 22:52 GMT+02:00 Janelle : > which points to the configuration of sssd.conf and/or nsswitch.conf > It is in there. If you say there are no AllowGroups in sshd, it has to be

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Janelle
which points to the configuration of sssd.conf and/or nsswitch.conf It is in there. If you say there are no AllowGroups in sshd, it has to be in one of those 2 places. ~J On 8/1/15 1:26 PM, Matt . wrote: kinit admin works perfectly, that is such strange. 2015-08-01 22:15 GMT+02:00 Janelle :

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Matt .
kinit admin works perfectly, that is such strange. 2015-08-01 22:15 GMT+02:00 Janelle : > lastly -- on the master - do you get the same error if you "kinit admin"? > ~J > > > On 8/1/15 1:05 PM, Matt . wrote: >> >> This actually the most important part, and the GSS Failure concerns me: >> >> debug1

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Janelle
lastly -- on the master - do you get the same error if you "kinit admin"? ~J On 8/1/15 1:05 PM, Matt . wrote: This actually the most important part, and the GSS Failure concerns me: debug1: SSH2_MSG_SERVICE_ACCEPT received debug2: key: /root/.ssh/id_rsa ((nil)), debug2: key: /root/.ssh/id_dsa (

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Matt .
This actually the most important part, and the GSS Failure concerns me: debug1: SSH2_MSG_SERVICE_ACCEPT received debug2: key: /root/.ssh/id_rsa ((nil)), debug2: key: /root/.ssh/id_dsa ((nil)), debug2: key: /root/.ssh/id_ecdsa ((nil)), debug2: key: /root/.ssh/id_ed25519 ((nil)), debug1: Authenticat

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Janelle
What is in the logs on the machine that is failing? Can you login to admin from anywhere? Logs are you best friend. Also, a simply "ssh -vvv" will help. ~J On 8/1/15 12:51 PM, Matt . wrote: Hi, This didn't fix it yet. I wonder if there are any checks I can do as in the very past I was able

Re: [Freeipa-users] Admin password not accepted during replica install

2015-08-01 Thread Matt .
Hi, This didn't fix it yet. I wonder if there are any checks I can do as in the very past I was able to do a simple replica without any issues. Matt 2015-08-01 21:34 GMT+02:00 Janelle : > Double check you do not have "AllowGroups" set in your /etc/ssh/sshd_config > file. If you do, add the "adm

Re: [Freeipa-users] admin password is always expired

2015-02-10 Thread Roderick Johnstone
On 10/02/2015 14:36, Rob Crittenden wrote: Roderick Johnstone wrote: On 10/02/15 07:44, Dmitri Pal wrote: On 02/09/2015 05:35 PM, Roderick Johnstone wrote: Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a go

Re: [Freeipa-users] admin password is always expired

2015-02-10 Thread Rob Crittenden
Roderick Johnstone wrote: > On 10/02/15 07:44, Dmitri Pal wrote: >> On 02/09/2015 05:35 PM, Roderick Johnstone wrote: >>> Hi >>> >>> I seem to have locked myself out of my ipa admin account (on RHEL >>> 6.6). This is an evaluation instance so not too big a deal, but a good >>> learning experience.

Re: [Freeipa-users] admin password is always expired

2015-02-10 Thread Petr Vobornik
On 02/10/2015 12:00 PM, Roderick Johnstone wrote: On 10/02/15 07:44, Dmitri Pal wrote: On 02/09/2015 05:35 PM, Roderick Johnstone wrote: Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a good learning experien

Re: [Freeipa-users] admin password is always expired

2015-02-10 Thread Roderick Johnstone
On 10/02/15 07:44, Dmitri Pal wrote: On 02/09/2015 05:35 PM, Roderick Johnstone wrote: Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a good learning experience. I suspect its some changes that I made to the p

Re: [Freeipa-users] admin password is always expired

2015-02-09 Thread Dmitri Pal
On 02/09/2015 05:35 PM, Roderick Johnstone wrote: Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a good learning experience. I suspect its some changes that I made to the password policy that caused this.

Re: [Freeipa-users] admin password

2011-01-27 Thread Simo Sorce
On Thu, 2011-01-27 at 09:09 -0500, Uzor Ide wrote: > Hi all > > How do I make admin password not to expire immediately after changing > it? It is always set to expire even if you use kpasswd to change it ? Simo. -- Simo Sorce * Red Hat, Inc * New York _