[Freeipa-users] kinit - gui

Rob Crittenden rcritten at redhat.com
Thu Aug 1 18:26:14 UTC 2013


Hebert, Henry wrote:
> I have inherited an ipa system that has been running fantastic.  However
> the gui is no longer functioning.  I was wondering if this list has seen
> this sort of error in the past.
>
> hostname# kinit admin
> kinit: Clients credentials have been revoked while getting initial
> credentials

This is unrelated to the GUI. It appears that the admin account is 
disabled or locked due to too many failed logins. Using any other user, 
can you do ipa user-show admin?

Look for:

   Account disabled: True

If it is False then try ipa user-status admin see the number of failed 
logins.

rob

>
> so i then tried
> http://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/using-the-ui.html#tab.ui-troubleshooting
>
>
> [hostname]# cat /tmp/moz.log
> 64608032[7fad03b53150]:   using REQ_DELEGATE
> 64608032[7fad03b53150]:   service = hostname
> 64608032[7fad03b53150]:   using negotiate-gss
> 64608032[7fad03b53150]: entering nsAuthGSSAPI::nsAuthGSSAPI()
> 64608032[7fad03b53150]: Attempting to load gss functions
> 64608032[7fad03b53150]: entering nsAuthGSSAPI::Init()
> 64608032[7fad03b53150]: nsHttpNegotiateAuth::GenerateCredentials()
> [challenge=Negotiate]
> 64608032[7fad03b53150]: entering nsAuthGSSAPI::GetNextToken()
> 64608032[7fad03b53150]: gss_init_sec_context() failed: Unspecified GSS
> failure.  Minor code may provide more information
> 64608032[7fad03b53150]:   leaving nsAuthGSSAPI::GetNextToken [rv=80004005]
>
>
> Thanks in advance!
> Henry
>
> --
>
> Henry Hebert
> System Administrator III
>
>
>
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users
>




More information about the Freeipa-users mailing list