On 08/18/2016 04:16 PM, Deepak Dimri wrote:
> Hi All,
>
> While trying to automate IPA client registration programatically, i seems
> have
> made my admin password out of sync between KDC and
> /etc/krb5.keytab.
This looks confusing, admin password and /etc/krb5.keytab do not look related.
The
tt ." , Janelle
Cc: "freeipa-users@redhat.com"
Date: 03.08.2015 08:49
Subject: Re: [Freeipa-users] Admin password not accepted during replica
install
Sent by:freeipa-users-boun...@redhat.com
When this command failed for me, it usually was a proble
When this command failed for me, it usually was a problem with SSSD on the
master. The service was down, offline or simply something wrong was with it.
On the master, I would try:
$ id admin
$ ssh admin@localhost # (with password)
If that works, try manual
$ ssh admin@ipa.master.server # with p
I even checked working version (IPA clusters) and they don't even have
this AllowGroups.
Am I missing something ?
2015-08-01 22:52 GMT+02:00 Janelle :
> which points to the configuration of sssd.conf and/or nsswitch.conf
> It is in there. If you say there are no AllowGroups in sshd, it has to be
which points to the configuration of sssd.conf and/or nsswitch.conf
It is in there. If you say there are no AllowGroups in sshd, it has to
be in one of those 2 places.
~J
On 8/1/15 1:26 PM, Matt . wrote:
kinit admin works perfectly, that is such strange.
2015-08-01 22:15 GMT+02:00 Janelle :
kinit admin works perfectly, that is such strange.
2015-08-01 22:15 GMT+02:00 Janelle :
> lastly -- on the master - do you get the same error if you "kinit admin"?
> ~J
>
>
> On 8/1/15 1:05 PM, Matt . wrote:
>>
>> This actually the most important part, and the GSS Failure concerns me:
>>
>> debug1
lastly -- on the master - do you get the same error if you "kinit admin"?
~J
On 8/1/15 1:05 PM, Matt . wrote:
This actually the most important part, and the GSS Failure concerns me:
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug2: key: /root/.ssh/id_rsa ((nil)),
debug2: key: /root/.ssh/id_dsa (
This actually the most important part, and the GSS Failure concerns me:
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug2: key: /root/.ssh/id_rsa ((nil)),
debug2: key: /root/.ssh/id_dsa ((nil)),
debug2: key: /root/.ssh/id_ecdsa ((nil)),
debug2: key: /root/.ssh/id_ed25519 ((nil)),
debug1: Authenticat
What is in the logs on the machine that is failing? Can you login to
admin from anywhere? Logs are you best friend.
Also, a simply "ssh -vvv" will help.
~J
On 8/1/15 12:51 PM, Matt . wrote:
Hi,
This didn't fix it yet.
I wonder if there are any checks I can do as in the very past I was
able
Hi,
This didn't fix it yet.
I wonder if there are any checks I can do as in the very past I was
able to do a simple replica without any issues.
Matt
2015-08-01 21:34 GMT+02:00 Janelle :
> Double check you do not have "AllowGroups" set in your /etc/ssh/sshd_config
> file. If you do, add the "adm
On 10/02/2015 14:36, Rob Crittenden wrote:
Roderick Johnstone wrote:
On 10/02/15 07:44, Dmitri Pal wrote:
On 02/09/2015 05:35 PM, Roderick Johnstone wrote:
Hi
I seem to have locked myself out of my ipa admin account (on RHEL
6.6). This is an evaluation instance so not too big a deal, but a go
Roderick Johnstone wrote:
> On 10/02/15 07:44, Dmitri Pal wrote:
>> On 02/09/2015 05:35 PM, Roderick Johnstone wrote:
>>> Hi
>>>
>>> I seem to have locked myself out of my ipa admin account (on RHEL
>>> 6.6). This is an evaluation instance so not too big a deal, but a good
>>> learning experience.
On 02/10/2015 12:00 PM, Roderick Johnstone wrote:
On 10/02/15 07:44, Dmitri Pal wrote:
On 02/09/2015 05:35 PM, Roderick Johnstone wrote:
Hi
I seem to have locked myself out of my ipa admin account (on RHEL
6.6). This is an evaluation instance so not too big a deal, but a good
learning experien
On 10/02/15 07:44, Dmitri Pal wrote:
On 02/09/2015 05:35 PM, Roderick Johnstone wrote:
Hi
I seem to have locked myself out of my ipa admin account (on RHEL
6.6). This is an evaluation instance so not too big a deal, but a good
learning experience. I suspect its some changes that I made to the
p
On 02/09/2015 05:35 PM, Roderick Johnstone wrote:
Hi
I seem to have locked myself out of my ipa admin account (on RHEL
6.6). This is an evaluation instance so not too big a deal, but a good
learning experience. I suspect its some changes that I made to the
password policy that caused this.
On Thu, 2011-01-27 at 09:09 -0500, Uzor Ide wrote:
> Hi all
>
> How do I make admin password not to expire immediately after changing
> it?
It is always set to expire even if you use kpasswd to change it ?
Simo.
--
Simo Sorce * Red Hat, Inc * New York
_
16 matches
Mail list logo