<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div id="page" class="clear-block"><div id="main-div" class="column"><div id="main-squeeze"><div id="content"><div id="content-content" class="clear-block"><div id="node-48235" class="node discussion-type clear-block">
<div class="content"><p>Hi THis morning I was asked to reset the user password of one of our IPA/LDAP user accounts.</p><div> <br class="webkit-block-placeholder"></div><p>After I reset the password I tried to logon to a particular ssh machine .</p><p>The system asked to cheange the password as expeceted.</p><p>I entered the NEw Password and the Re enter the the new password after this the system answered with:</p><div> <br class="webkit-block-placeholder"></div><p>passwd: Authentication token manipulation error</p><div> <br class="webkit-block-placeholder"></div><div> <br class="webkit-block-placeholder"></div><p>So in order to test this situation I created a new account and I had the same problem with the new account.</p><p>I try also to reset another user password and I got the same problem.</p><div> <br class="webkit-block-placeholder"></div><p>It seems that I'm not be able to reset anybody user password.</p><div> <br class="webkit-block-placeholder"></div><p>Any ideas????</p><div> <br class="webkit-block-placeholder"></div><p>From the krb5kdc.log</p><p>I get : Nov 19 14:35:31 ldap.webdom.lifesci.ucla.edu
krb5kdc[1610](info): AS_REQ (4 etypes {18 17 16 23}) 164.67.110.65:
PREAUTH_FAILED: <a href="mailto:taccount@myserver.com">taccount@myserver.com</a> for <a href="mailto:kadmin/changepw@myserver.com">kadmin/changepw@myserver.com</a>, Decrypt integrity check failed</p><div> <br class="webkit-block-placeholder"></div><p>from the /var/lib/dirsrv/slapd-server.com/errors file I get:</p><p>ipapwd_setPasswordHistory - [file ipapwd_common.c, line 926]: failed to generate new password history!<br>[19/Nov/2012:14:35:40
-0800] managed-entries-plugin - mep_mod_post_op: Unable to find config
for origin entry "uid=taccount,cn=users,cn=accounts,dc=myserver,dc=com".</p><div> <br class="webkit-block-placeholder"></div><div> <br class="webkit-block-placeholder"></div><p>Any idea on what's going on?</p><div> <br class="webkit-block-placeholder"></div><p>Thank you</p><p>Marcello</p></div></div></div></div></div></div></div></body></html>