Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-13 Thread Sumit Bose
On Tue, Jan 13, 2015 at 12:48:18PM +0530, Rakesh Rajasekharan wrote: Does it work for the same user from the client if you reset password on the server, authenticate from the client and then force reset again on the server? When I force reset a user, he stil faces the same error token

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-13 Thread Lukas Slebodnik
On (13/01/15 12:48), Rakesh Rajasekharan wrote: This is how I get the logs in krb5_child. when a user tries to authenticate with the random password that I generated, WARNING: Your password has expired. You must change your password now and login again! Changing password for user hq-testuser.

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-13 Thread Rakesh Rajasekharan
Thanks, that worked.. users now able to get the password changed with any issues... Will do few more testing on this but at this point looks like that was the issue ~Rakesh On Tue, Jan 13, 2015 at 1:52 PM, Sumit Bose sb...@redhat.com wrote: On Tue, Jan 13, 2015 at 12:48:18PM +0530, Rakesh

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Rakesh Rajasekharan
The sssd version is 1.11.6 The password does not get changed, whatever password gets generated by ipa user-mod --random stays valid even after attempting the change. krb5_child.log does not have any contents. Thanks, Rakesh On Sun, Jan 11, 2015 at 9:01 PM, Jakub Hrozek jhro...@redhat.com

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Lukas Slebodnik
On (12/01/15 14:12), Rakesh Rajasekharan wrote: The sssd version is 1.11.6 The password does not get changed, whatever password gets generated by ipa user-mod --random stays valid even after attempting the change. krb5_child.log does not have any contents. The logging in sssd is dibsabled by

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Dmitri Pal
On 01/11/2015 04:01 AM, Rakesh Rajasekharan wrote: Hi, I am having some issues with freeipa. Whenever I change the password for any user, He is not able to change the password. and he gets error authentication token manipualtion error Changing password for user hq-testuser. Current

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Rakesh Rajasekharan
This is what I get now a=in the krb5_child.log after setting the debug_level Mon Jan 12 09:51:14 2015) [[sssd[krb5_child[21709 [unpack_buffer] (0x0100): ccname: [FILE:/tmp/krb5cc_71061_XX] keytab: [/etc/krb5.keytab] (Mon Jan 12 09:51:14 2015) [[sssd[krb5_child[21709

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Rakesh Rajasekharan
under /var/log/secure.. have this error passwd: pam_sss(passwd:chauthtok): Password change failed for user hq-testuser: 22 (Authentication token lock busy) On Mon, Jan 12, 2015 at 3:25 PM, Rakesh Rajasekharan rakesh.rajasekha...@gmail.com wrote: This is what I get now a=in the krb5_child.log

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Dmitri Pal
On 01/12/2015 12:55 PM, Rakesh Rajasekharan wrote: This is the full log, Jan 12 17:45:15 10-5-68-5 sshd[29753]: pam_sss(sshd:account): User info message: Password expired. Change your password now. Jan 12 17:45:15 10-5-68-5 sshd[29753]: Accepted password for hq-testuser from 10.5.68.184 port

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Rakesh Rajasekharan
Does it work for the same user from the client if you reset password on the server, authenticate from the client and then force reset again on the server? When I force reset a user, he stil faces the same error token manipulation when tries to login to a client. However, when he tries getting

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Rakesh Rajasekharan
This is the full log, Jan 12 17:45:15 10-5-68-5 sshd[29753]: pam_sss(sshd:account): User info message: Password expired. Change your password now. Jan 12 17:45:15 10-5-68-5 sshd[29753]: Accepted password for hq-testuser from 10.5.68.184 port 54048 ssh2 Jan 12 17:45:16 10-5-68-5 sshd[29753]:

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Jakub Hrozek
On Mon, Jan 12, 2015 at 11:25:16PM +0530, Rakesh Rajasekharan wrote: This is the full log, Sorry, I meant the full krb5_child.log ... -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-12 Thread Jakub Hrozek
On Mon, Jan 12, 2015 at 04:01:32PM +0530, Rakesh Rajasekharan wrote: under /var/log/secure.. have this error passwd: pam_sss(passwd:chauthtok): Password change failed for user hq-testuser: 22 (Authentication token lock busy) It looks like the log was trucated, can you post more context?

Re: [Freeipa-users] freeipa authentication token manipulation error

2015-01-11 Thread Jakub Hrozek
On Sun, Jan 11, 2015 at 02:31:26PM +0530, Rakesh Rajasekharan wrote: Hi, I am having some issues with freeipa. Whenever I change the password for any user, He is not able to change the password. and he gets error authentication token manipualtion error Changing password for user