[Freeipa-users] Cannot loging via SSH with AD user TO IPA Domain.

Genadi Postrilko genadipost at gmail.com
Thu Jan 2 20:37:14 UTC 2014


Hi all.

I have a running IPA Server (3.0.0-37) on RHEL 6.2.
I'm trying  to create Trust between IPA server and AD (In different DNS
domains). I followed the red hat guide
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/pdf/Identity_Management_Guide/Red_Hat_Enterprise_Linux-6-Identity_Management_Guide-en-US.pdf
.

When i completed the needed step to create the trust and retrieved a krb
ticket from the AD server:

[root at ipaserver ~]# kinit Administrator at ADDC.COM
Password for Administrator at ADDC.COM:
[root at ipaserver ~]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: Administrator at ADDC.COM

Valid starting     Expires            Service principal
01/02/14 12:20:30  01/02/14 22:20:34  krbtgt/ADDC.COM at ADDC.COM
        renew until 01/03/14 12:20:30

But when i try to connect to the IPA server via SHH (Putty) i get "Access
denied" message:

login as: Administrator at ADDC.COM
Administrator at ADDC.COM@192.168.227.128's password:
Access denied

Any ideas on what i could have done wrong in the process of creating the
trust?

Thank you in advance.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140102/cd7b58c9/attachment.htm>


More information about the Freeipa-users mailing list