[Freeipa-users] GSSAPI for second hop (SSH)

Robbie Harwood rharwood at redhat.com
Fri Mar 3 18:53:25 UTC 2017


"Jason B. Nance" <jason at tresgeek.net> writes:

> I have a FreeIPA 4.4.0 setup with Active Directory trusts.  Users
> connecting to Linux servers from their domain-joined workstations are
> not required to enter a password for the first connection.  However,
> if they attempt to ssh to a second Linux machine from the first they
> are being prompted for a password.

What is the output if they klist on the first machine they SSH to?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 832 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20170303/800d0c40/attachment.sig>


More information about the Freeipa-users mailing list