[Freeipa-users] Additional pre-authentication required, Ticket Wrong ?

Dmitri Pal dpal at redhat.com
Mon Mar 30 01:48:29 UTC 2015


On 03/29/2015 04:47 AM, Matt . wrote:
> Hi Guys,
>
> Now my Certification issues are solved for using a loadbalancer in
> front of my ipa servers I get the following:
>
> Unable to verify your Kerberos credentials
>
> and in my logs:
>
> Additional pre-authentication required.
>
> This happens when I connect throught my loadbalancers, I see my server
> coming ni with the right IP.
>
> When I access my ipa server directly, not using the loadbalancer IP
> between it, my kerberos Ticket is valid.
>
> I get the feeling that when I use my loadbalancers and because of that
> I get a 301 redirect it needs a preauth. I see some issues on
> mailinglists but it doesn't fit my situation.
>
> Why wants it the preauth when I already have a valid ticket and my
> redirect is followed by CURL and posted the right way ?

Can you describe the sequence?
What do you do?

 From the client you try IPA CLI and this is where you see the problem 
even with the valid ticket or is the flow different?

> I hope someone has an idea.
>
> Thanks,
>
> Matt
>


-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager IdM portfolio
Red Hat, Inc.




More information about the Freeipa-users mailing list