<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
On 01/23/2013 05:50 PM, Eric Chennells wrote:
<blockquote cite="mid:CD25A91E.FD8B%25eric@zymeworks.com"
type="cite">
<div>Hello,</div>
<div><br>
</div>
<div>I have the unfortunate requirement of needing to authenticate
windows XP clients against freeipa.</div>
<div><br>
</div>
<div>I have followed the instuctions of these two guides:</div>
<div>
<div><a class="moz-txt-link-freetext" href="http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/Using_Microsoft_Windows.html">http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/Using_Microsoft_Windows.html</a></div>
<div><a moz-do-not-send="true"
href="http://freeipa.org/page/Windows_authentication_against_FreeIPA">http://freeipa.org/page/Windows_authentication_against_FreeIPA</a></div>
</div>
<div><br>
</div>
<div>Kerberos is working, because I can do a kinit username and
properly receive a krbtgt principle.</div>
<div><br>
</div>
<div>However on login I get the error "The system could not log
you on".</div>
<div><br>
</div>
<div>For the map user step I did "ksetup /mapuser * *" and have a
local user created with the same username as the IPA user.</div>
</blockquote>
<br>
I do not have windows system to check so it is a pure speculation.
Can it be that the name of the local user actually does not match?<br>
May be there is a typo or may be the name of the user should be the
full principal or vice verse just short name and you have long
one...<br>
Anyways I would have investigated that aspect if I were in the same
situation.<br>
<br>
<blockquote cite="mid:CD25A91E.FD8B%25eric@zymeworks.com"
type="cite">
<div><br>
</div>
<div>Is there a step I am missing? I feel as though I am close
because kerberos is working.</div>
<div><br>
</div>
<div>I am using FreeIPA 2.2 on RHEL 6.3</div>
<div><br>
</div>
<div>Thanks for any tips.</div>
<div><br>
</div>
<div>Eric</div>
<div><br>
</div>
<br>
<br>
Notice of Confidentiality: The information transmitted is intended
only for the<br>
person or entity to which it is addressed and may contain
confidential and/or<br>
privileged material. Any review, re-transmission, dissemination or
other use of <br>
or taking of any action in reliance upon this information by
persons or entities<br>
other than the intended recipient is prohibited. If you received
this in error<br>
please contact the sender immediately by return electronic
transmission and then<br>
immediately delete this transmission including all attachments
without copying,<br>
distributing or disclosing the same.<br>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Freeipa-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a></pre>
</blockquote>
<br>
<br>
<pre class="moz-signature" cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager for IdM portfolio
Red Hat Inc.
-------------------------------
Looking to carve out IT costs?
<a class="moz-txt-link-abbreviated" href="http://www.redhat.com/carveoutcosts/">www.redhat.com/carveoutcosts/</a>
</pre>
</body>
</html>