[Freeipa-users] Fw: ssh problem with migrated FreeIPA client on EL7.1 -->Not Solved

Christopher Lamb christopher.lamb at ch.ibm.com
Tue Jun 2 18:04:35 UTC 2015


Hi Rob

Thanks

All those commands work, and give expected results.

I will send you the install logs direct.

Cheers

Chris




From:	Rob Crittenden <rcritten at redhat.com>
To:	Christopher Lamb/Switzerland/IBM at IBMCH,
            freeipa-users at redhat.com, Jakub Hrozek <jhrozek at redhat.com>
Date:	02.06.2015 19:25
Subject:	Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA
            client on EL7.1 -->Not Solved



Christopher Lamb wrote:
>
> Hi
>
> To narrow down the cause even further, I reverted HOST10 via VM snapshot
> back to the state after installing linux and configuring ntpd.
>
> This time I installed ipa-client 4.1 directly (rather then as a dependent
> of our standard server packages). So this machine is a basic install of
EL
> 7.1 + ntpd + ipa-client, with nothing else extra.
>
> Again I first registered against the old 3.3.3 FreeIPA Server, then
> switched to the new 4.1 Server.
>
> Once again my FreeIPA user does not authenticate.

I'd start by simlifying things.

Does kinit -kt /etc/krb5.keytab work?

Do basic nss operations work?

getent passwd admin
id admin
groups admin
etc.

Seeing the entire ipaclient-install.log after the 7.1 install may be
helfpul.

Cranking up sssd debuglevel may be helpful.

rob







More information about the Freeipa-users mailing list