[Freeipa-users] Unable to enrol servers with principal

Dmitri Pal dpal at redhat.com
Wed Feb 13 22:27:04 UTC 2013


On 02/13/2013 04:57 PM, Charlie Derwent wrote:
>
>
> On Sun, Feb 10, 2013 at 1:48 AM, Rob Crittenden <rcritten at redhat.com
> <mailto:rcritten at redhat.com>> wrote:
>
>     Charlie Derwent wrote:
>
>         Hi
>         Whenever I attempt an unattended installation with a principal and
>         password. The installation fails.
>         I'm using the following syntax for my command
>         ipa-client-install --domain=example.com <http://example.com>
>         <http://example.com>
>         --server=ipa.example.com <http://ipa.example.com>
>         <http://ipa.example.com> --realm=EXAMPLE.COM <http://EXAMPLE.COM>
>         <http://EXAMPLE.COM> --principal=user --password=pass -U
>         --ntp-server=123.123.123.123 --mkhomedir
>         --hostname=server1.example.com <http://server1.example.com>
>         <http://server1.example.com>
>
>         The error I get varies between (in order of frequency)
>         Joining realm failed: /usr/sbin/ipa-join: symbol lookup error:
>         /usr/sbin/ipa-join: undefined symbol: xmlrpc_server_info_set_user
>         and
>
>
>     This is the sort of thing that if you saw once, you should see
>     every time. What version of xmlrpc-c-client is installed?
>
>      
>
> I agree I should be seeing it all the time it's very odd that I'm not,
> the package is xmlrpc-c-client-1.16.24-1206.1840.4.el5.x86_64.rpm 
>
>
>         kinit(v5): Password incorrect while getting initial credentials
>         and
>         Password expired. you must change it now.
>         kinit(v5): Cannot read password while getting initial credentials
>         The password is 100% right as I can kinit on other servers and
>         access
>         the webgui with the same details.
>         OTP's work flawlessly.
>
>
>     The KDC log might have more information.
>
> I'm not in the office right now so I can't check the logs but I assume
> the KDC log is actually on the IPA server?

yes
and the DS access logs too
>  
> Thanks
> Charlie
>
>      
>
>
>  
>
>
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users


-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager for IdM portfolio
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20130213/edded5a6/attachment.htm>


More information about the Freeipa-users mailing list