[Freeipa-users] More SSO Strangeness

Sumit Bose sbose at redhat.com
Thu Feb 6 08:35:07 UTC 2014


On Wed, Feb 05, 2014 at 01:44:13PM -0500, Mark Gardner wrote:
> Okay,
> 
> Spent some time on this one...
> Some users can login SSO no problem, others have to put in their password.
> 
> Strange as it seems,  if the length of the username was greater than 4, the
> SSO worked.
> So markg at test.local works, but mark at test.local doesn't.

Can you send the mapping you use in krb5.conf? Can you check if there
are .k5login files in the home directories of the users where SSO is
working?

bye,
Sumit

> 
> My guess is something to do with the NetBios name length?
> 
> Fedora 20 IPA Server
> CentOS 6.5 IPA Client
> Win 2012 AD Domain Server
> 
> Setup as IPA as a subdomain of AD.
> AD Domain: test.local
> IPA Domain: hosted.test.local

> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users




More information about the Freeipa-users mailing list