[Freeipa-users] HostEnrol role does not seem to work

Rob Crittenden rcritten at redhat.com
Thu Jan 17 18:42:26 UTC 2013


Qing Chang wrote:
> I assigned an IPA user account the "HostEnrol" role and run
> "ipa-client-install",
> when it got to this "User authorized to enroll computers:", I used that
> account,
> then got following:
> Joining realm failed: No permission to join this host to the IPA domain.
> Installation failed. Rolling back changes.
> IPA client is not configured on this system.
>
> Am I missing something here?

What privileges are in the HostEnrol role?

Or can you show the output of this, where tuser1 is the user you're 
trying to enroll with?

% ipa user-show tuser1 --all --raw |grep -i member

rob




More information about the Freeipa-users mailing list