<br>System: Centos 6.2 <br>IPA version : ipa-server-2.1.3-9.el6.x86_64<br><br><br clear="all">Thanks<br>Chandan<br><br><br><br>
<br><br><div class="gmail_quote">On Mon, May 14, 2012 at 2:21 PM, Dmitri Pal <span dir="ltr"><<a href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<u></u>

  
    
  
  <div bgcolor="#ffffff" text="#000000"><div><div class="h5">
    On 05/14/2012 05:09 PM, Chandan Kumar wrote:
    <blockquote type="cite">I am a newbie in IPA and was experimenting it on my
      couple of VMs before considering it for production level.<br>
      <br>
      Installation went fine, however, I am getting the kerberos key
      expiration error at firefox. I am running firefox on the same
      machine where I have installed/configured ipa-server. On googling
      and some help in IRC I checked documentation to trouble shoot it
      as this appear to be a known problem. <br>
      <br>
      Moreover, I did follow<br>
      <br>
      <a href="http://freeipa.org/page/InstallAndDeploy" target="_blank">http://freeipa.org/page/InstallAndDeploy</a><br>
      <a href="http://freeipa.org/page/TroubleshootingGuide" target="_blank">http://freeipa.org/page/TroubleshootingGuide</a><br>
      <br>
      Fire fox logs<br>
      <br>
      1977841888[7fc789f5b040]:   leaving nsAuthGSSAPI::GetNextToken
      [rv=80004005]<br>
      -1977841888[7fc789f5b040]:   using REQ_DELEGATE<br>
      -1977841888[7fc789f5b040]:   service = <a href="http://ipaserver.example.com" target="_blank">ipaserver.example.com</a><br>
      -1977841888[7fc789f5b040]:   using negotiate-gss<br>
      -1977841888[7fc789f5b040]: entering nsAuthGSSAPI::nsAuthGSSAPI()<br>
      -1977841888[7fc789f5b040]: entering nsAuthGSSAPI::Init()<br>
      -1977841888[7fc789f5b040]:
      nsHttpNegotiateAuth::GenerateCredentials() [challenge=Negotiate]<br>
      -1977841888[7fc789f5b040]: entering nsAuthGSSAPI::GetNextToken()<br>
      -1977841888[7fc789f5b040]: gss_init_sec_context() failed:
      Unspecified GSS failure.  Minor code may provide more information<br>
      SPNEGO cannot find mechanisms to negotiate<br>
      -1977841888[7fc789f5b040]:   leaving nsAuthGSSAPI::GetNextToken
      [rv=80004005]<br>
      <br>
      [root@ds var]# klist<br>
      Ticket cache: <a>FILE:/tmp/krb5cc_0</a><br>
      Default principal: <a href="mailto:admin@EXAMPLE.COM" target="_blank">admin@EXAMPLE.COM</a><br>
      <br>
      Valid starting     Expires            Service principal<br>
      05/14/12 13:50:32  05/15/12 13:50:30  krbtgt/<a href="mailto:EXAMPLE.COM@EXAMPLE.COM" target="_blank">EXAMPLE.COM@EXAMPLE.COM</a><br>
      05/14/12 13:53:58  05/15/12 13:50:30  HTTP/<a href="mailto:ipaserver.example.com@EXAMPLE.COM" target="_blank">ipaserver.example.com@EXAMPLE.COM</a><br>
      05/14/12 13:54:13  05/15/12 13:50:30  ldap/<a href="mailto:ipaserver.example.com@EXAMPLE.COM" target="_blank">ipaserver.example.com@EXAMPLE.COM</a><br>
      [root@ds var]# <br>
      <br>
      Output of ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin<br>
      <br>
      at <a href="http://fpaste.org/9hXX/" target="_blank">http://fpaste.org/9hXX/</a><br>
      <br>
      I am not sure what I am missing though. Appreciate any help.<br>
      <br clear="all">
      Thanks<br>
      Chandan<br>
      <br>
      <br>
      <br>
    </blockquote>
    <br></div></div>
    Are you running FF on windows?<br>
    Which version of IPA are you using?<br>
    <br>
    <br>
    <blockquote type="cite">
      <pre><fieldset></fieldset>
_______________________________________________
Freeipa-users mailing list
<a href="mailto:Freeipa-users@redhat.com" target="_blank">Freeipa-users@redhat.com</a>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a></pre><span class="HOEnZb"><font color="#888888">
    </font></span></blockquote><span class="HOEnZb"><font color="#888888">
    <br>
    <br>
    <pre cols="72">-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager IPA project,
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
<a href="http://www.redhat.com/carveoutcosts/" target="_blank">www.redhat.com/carveoutcosts/</a>


</pre>
  </font></span></div>

<br>_______________________________________________<br>
Freeipa-users mailing list<br>
<a href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br></blockquote></div><br>