[Freeipa-users] Unable to authenticate a client user against IPA

Steven Jones Steven.Jones at vuw.ac.nz
Fri Mar 11 00:13:40 UTC 2011


Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [sss_krb5_verify_keytab_ex] (0): Principal [host/Fed14-64-ipacl03.ipa.ac.nz at IPA.AC
.NZ] not found in keytab [default]
(Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [setup_child] (0): Could not verify keytab
(Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [load_backend_module] (0): Error (14) in module (ipa) initialization (sssm_ipa_id
_init)!
(Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [be_process_init] (0): fatal error initializing data providers
(Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [main] (0): Could not initialize backend [14]
(Fri Mar 11 12:47:42 2011) [sssd[be[ipa.ac.nz]]] [sss_krb5_verify_keytab_ex] (0): Principal [host/Fed14-64-ipacl03.ipa.ac.nz at IPA.A
C.NZ] not found in keytab [default]
(Fri Mar 11 12:47:42 2011) [sssd[be[ipa.ac.nz]]] [setup_child] (0): Could not verify keytab
(Fri Mar 11 12:47:42 2011) [sssd[be[ipa.ac.nz]]] [load_backend_module] (0): Error (14) in module (ipa) initialization (sssm_ipa_id
_init)!
(Fri Mar 11 12:47:42 2011) [sssd[be[ipa.ac.nz]]] [be_process_init] (0): fatal error initializing data providers
(Fri Mar 11 12:47:42 2011) [sssd[be[ipa.ac.nz]]] [main] (0): Could not initialize backend [14]
[root at Fed14-64-ipacl03 sssd]#

========================
root at Fed14-64-ipacl03 sssd]# klist -k /etc/krb5.keytab
Keytab name: WRFILE:/etc/krb5.keytab
KVNO Principal
---- --------------------------------------------------------------------------
   1 host/fed14-64-ipacl03.ipa.ac.nz at IPA.AC.NZ
   1 host/fed14-64-ipacl03.ipa.ac.nz at IPA.AC.NZ
   1 host/fed14-64-ipacl03.ipa.ac.nz at IPA.AC.NZ
   1 host/fed14-64-ipacl03.ipa.ac.nz at IPA.AC.NZ
[root at Fed14-64-ipacl03 sssd]#

?

regards
________________________________
From: freeipa-users-bounces at redhat.com [freeipa-users-bounces at redhat.com] on behalf of Dmitri Pal [dpal at redhat.com]
Sent: Friday, 11 March 2011 11:58 a.m.
To: freeipa-users at redhat.com
Subject: Re: [Freeipa-users] Unable to authenticate a client user against IPA

On 03/10/2011 05:37 PM, Steven Jones wrote:
> I have run the in-install script and it wont delete the client in the ipa system, so again I had to delete it via the web gui....I will try re-installing.
>
> A release candidate?
>
> I dont see how....for me a release candidate should pretty much work with the odd bug in an "odd" area....this is still like alpha....major functionality failure, as personally I class being unable to do the very first thing you need to do as a major failure.....
>
> regards
>

Steve,

Sorry but it looks like you are doing something wrong over and over again or there is something mis-configured in your environment.
We are executing tests every day with new and old machines bare metal and VMs.
And everything works so there is definitely something specific to your environment which is different.
May be it is DNS or NTP or something like. We do not know. May be it is a bug that we do not hit because we do not run things in the sequence you run or with configuration you use.

You write a lot of mails to us but few contain any substantial information about your setup.
To troubleshoot we need logs.
There are all sorts of logs and configuration files on the server and on the client.
You do not include them in your emails.
How do you think we can troubleshoot the problems?

If you want us to help please include more detailed information.
I am really sorry that you are experiencing the issues and spending that much time but I do not see a way to help you since we do not have sufficient information to do the troubleshooting.

We will be happy to help you as soon as you provide such information.


Thank you,
Dmitri





More information about the Freeipa-users mailing list