[Freeipa-users] CLIENT KEY EXPIRED right after an ipa-join

Marc Schlinger marc.schlinger at agorabox.org
Fri Jun 11 16:21:07 UTC 2010


hello all,

I'm doing bulk enrollment, with ipa-client-install -w mypassword .

But after this command when I launch #id test-user, I see in the kdc log 
that the client key for my host principal has expired, and the command 
fails.

This is because the host principal has the krbPasswordExpiration set to 
the time at wich the client join.

Am'I missing a step or is this behaviour not normal?

Marc SCHLINGER




More information about the Freeipa-users mailing list