<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    On 11/19/2012 05:51 PM, Marcello Giannoni UCLA wrote:
    <blockquote cite="mid:B19BE416-5138-4EDC-94AC-F4D4A9B15186@ucla.edu"
      type="cite"><br>
      <div id="page" class="clear-block">
        <div id="main-div" class="column">
          <div id="main-squeeze">
            <div id="content">
              <div id="content-content" class="clear-block">
                <div id="node-48235" class="node discussion-type
                  clear-block">
                  <div class="content">
                    <p>Hi THis morning I was asked to reset the user
                      password of one of our IPA/LDAP user accounts.</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>After I reset the password I tried to logon to a
                      particular ssh machine .</p>
                    <p>The system asked to cheange the password as
                      expeceted.</p>
                    <p>I entered the NEw Password and the Re enter the
                      the new password after this the system answered
                      with:</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>passwd: Authentication token manipulation error</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>So in order to test this situation I created a
                      new account and I had the same problem with the
                      new account.</p>
                    <p>I try also to reset another user password and I
                      got the same problem.</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>It seems that I'm not be able to reset anybody
                      user password.</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>Any ideas????</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>From the krb5kdc.log</p>
                    <p>I get : Nov 19 14:35:31
                      ldap.webdom.lifesci.ucla.edu krb5kdc[1610](info):
                      AS_REQ (4 etypes {18 17 16 23}) 164.67.110.65:
                      PREAUTH_FAILED: <a moz-do-not-send="true"
                        href="mailto:taccount@myserver.com">taccount@myserver.com</a>
                      for <a moz-do-not-send="true"
                        href="mailto:kadmin/changepw@myserver.com">kadmin/changepw@myserver.com</a>,
                      Decrypt integrity check failed</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>from the /var/lib/dirsrv/slapd-server.com/errors
                      file I get:</p>
                    <p>ipapwd_setPasswordHistory - [file
                      ipapwd_common.c, line 926]: failed to generate new
                      password history!<br>
                      [19/Nov/2012:14:35:40 -0800]
                      managed-entries-plugin - mep_mod_post_op: Unable
                      to find config for origin entry
                      "uid=taccount,cn=users,cn=accounts,dc=myserver,dc=com".</p>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>Any idea on what's going on?</p>
                  </div>
                </div>
              </div>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
    Something is really mis configured on the server.<br>
    When the user tries to change password his password policy needs to
    be read from lDAP. Password policy depends on the groups the user is
    a member of so effectively the policy is merged from different
    policies. That merge is failing because the DS plugin configuration
    is missing.<br>
    <br>
    Does this happen on all your replicas?<br>
    If not and other replicas that you have work correctly, I would
    suggest considering re-installation of the current replica. But to
    make it work, I suggest you ask JR on #freeipa for exact steps as he
    has a lot of expertise on recycling replicas. <br>
    <br>
    <br>
    <blockquote cite="mid:B19BE416-5138-4EDC-94AC-F4D4A9B15186@ucla.edu"
      type="cite">
      <div id="page" class="clear-block">
        <div id="main-div" class="column">
          <div id="main-squeeze">
            <div id="content">
              <div id="content-content" class="clear-block">
                <div id="node-48235" class="node discussion-type
                  clear-block">
                  <div class="content">
                    <div> <br class="webkit-block-placeholder">
                    </div>
                    <p>Thank you</p>
                    <p>Marcello</p>
                  </div>
                </div>
              </div>
            </div>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Freeipa-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a></pre>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager for IdM portfolio
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
<a class="moz-txt-link-abbreviated" href="http://www.redhat.com/carveoutcosts/">www.redhat.com/carveoutcosts/</a>


</pre>
  </body>
</html>