[Freeipa-users] HTTP response code is 401, not 200

Rob Crittenden rcritten at redhat.com
Fri Apr 29 15:34:22 UTC 2016


Jose Alvarez R. wrote:
> Hi Users
>
> You can help me?
>
> I have the problem for join a client to my FREEIPA Server. The version
> IPA Server is 3.0 and IP client is 3.0
>
> When I join my client to IPA server show these errors:
>
> [root at ppa ~]# tail –f /var/log/ipaclient-install.log
>
> 2016-04-28T17:26:41Z DEBUG stderr=
>
> 2016-04-28T17:26:41Z DEBUG trying to retrieve CA cert via LDAP from
> ldap://freeipa.cyberfuel.com
>
> 2016-04-28T17:26:41Z DEBUG Existing CA cert and Retrieved CA cert are
> identical
>
> 2016-04-28T17:26:41Z DEBUG args=/usr/sbin/ipa-join -s
> freeipa.cyberfuel.com -b dc=cyberfuel,dc=com
>
> 2016-04-28T17:26:41Z DEBUG stdout=
>
> 2016-04-28T17:26:41Z DEBUG stderr=HTTP response code is 401, not 200
>
> 2016-04-28T17:26:41Z ERROR Joining realm failed: HTTP response code is
> 401, not 200
>
> 2016-04-28T17:26:41Z ERROR Installation failed. Rolling back changes.
>
> 2016-04-28T17:26:41Z ERROR IPA client is not configured on this system.

I'd look in the 389-ds access and error logs on the IPA server to see if 
there are any more details. Look for the BIND from the client and see 
what happens.

More context from the log file might be helpful. I believe if you run 
the client installer with --debug then additional flags are passed to 
ipa-join to include the XML-RPC conversation and that might be useful too.

What account are you using to enroll with, admin?

rob




More information about the Freeipa-users mailing list