<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif">No. This is the second attempt after changing the password on first login.</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">If you want I can re-send you the logs but this is the second login logs of this user.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div><div><div><i><span style="font-family:verdana,sans-serif"><br>Best Regards,<br>__________________________________________<br></span></i></div><i><span style="font-family:verdana,sans-serif">Yogesh Sharma<br></span></i></div><span style="font-family:verdana,sans-serif"><i>Email: <a href="mailto:yks0000@gmail.com" target="_blank">yks0000@gmail.com</a> | Web: <span style="color:rgb(0,0,0)"><a href="http://www.initd.in" target="_blank">www.initd.in</a></span></i><br></span></div><span style="font-family:verdana,sans-serif"><br>RHCE, VCE-CIA, RackSpace Cloud U</span><br><a href="http://in.linkedin.com/in/yks0000" target="_blank"><img alt="My LinkedIn Profile" src="https://static.licdn.com/scds/common/u/img/webpromo/btn_myprofile_160x33.png"></a><br><div><span style="font-family:verdana,sans-serif"></span><div><div><br></div></div></div></div></div></div>
<br><div class="gmail_quote">On Fri, Mar 27, 2015 at 12:32 PM, Jakub Hrozek <span dir="ltr"><<a href="mailto:jhrozek@redhat.com" target="_blank">jhrozek@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Fri, Mar 27, 2015 at 10:28:13AM +0530, Yogesh Sharma wrote:<br>
> Hi Jakub,<br>
><br>
> Please find the logs for the user "test" created in IPA.<br>
><br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> Requesting info for [test] from [<ALL>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_getpwnam_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_get_account_info]<br>
> (0x0100): Got request for [4097][1][name=test]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_getpwnam_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [acctinfo_callback] (0x0100):<br>
> Request processed. Returned 0,0,Success<br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> Requesting info for [test] from [<ALL>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_initgroups_search]<br>
> (0x0100): Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_get_account_info]<br>
> (0x0100): Got request for [4099][1][name=test]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[nss]] [nss_cmd_initgroups_search]<br>
> (0x0100): Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [acctinfo_callback] (0x0100):<br>
> Request processed. Returned 0,0,Success<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_get_account_info]<br>
> (0x0100): Got request for [1][1][name=test]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:52 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [acctinfo_callback] (0x0100):<br>
> Request processed. Returned 0,0,Success<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [service_send_ping] (0x0100): Pinging<br>
> <a href="http://sd.int" target="_blank">sd.int</a><br>
> (Fri Mar 27 10:19:56 2015) [sssd] [service_send_ping] (0x0100): Pinging nss<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [service_send_ping] (0x0100): Pinging pam<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [service_send_ping] (0x0100): Pinging ssh<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [service_send_ping] (0x0100): Pinging pac<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [ping_check] (0x0100): Service pam<br>
> replied to ping<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [ping_check] (0x0100): Service pac<br>
> replied to ping<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [ping_check] (0x0100): Service ssh<br>
> replied to ping<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [ping_check] (0x0100): Service nss<br>
> replied to ping<br>
> (Fri Mar 27 10:19:56 2015) [sssd] [ping_check] (0x0100): Service <a href="http://sd.int" target="_blank">sd.int</a><br>
> replied to ping<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> Requesting info for [test] from [<ALL>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getpwnam_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> Requesting info for [test] from [<ALL>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getpwnam_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> Requesting info for [test] from [<ALL>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[nss]] [nss_cmd_getpwnam_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_cmd_authenticate] (0x0100):<br>
> entering pam_cmd_authenticate<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): command:<br>
> PAM_AUTHENTICATE<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): domain:<br>
> not set<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): user: test<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): service:<br>
> sshd<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): tty: ssh<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): ruser:<br>
> not set<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): rhost:<br>
> 125.63.90.34<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): authtok<br>
> type: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100):<br>
> newauthtok type: 0<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): priv: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): cli_pid:<br>
> 16634<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_get_account_info]<br>
> (0x0100): Got request for [3][1][name=test]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sdap_attrs_get_sid_str]<br>
> (0x0080): No [objectSIDString] attribute while id-mapping. [0][Success]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]]<br>
> [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID from [(null)]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_check_user_search] (0x0100):<br>
> Requesting info for [<a href="mailto:test@sd.int">test@sd.int</a>]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_dp_send_req] (0x0100): Sending<br>
> request with the following data:<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): command:<br>
> PAM_AUTHENTICATE<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): domain:<br>
> <a href="http://sd.int" target="_blank">sd.int</a><br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): user: test<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): service:<br>
> sshd<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): tty: ssh<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): ruser:<br>
> not set<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): rhost:<br>
> 125.63.90.34<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): authtok<br>
> type: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100):<br>
> newauthtok type: 0<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): priv: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_print_data] (0x0100): cli_pid:<br>
> 16634<br>
> (Fri Mar 27 10:19:57 2015) [sssd[pam]] [pam_dom_forwarder] (0x0100):<br>
> pam_dp_send_req returned 0<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [acctinfo_callback] (0x0100):<br>
> Request processed. Returned 0,0,Success<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_pam_handler] (0x0100):<br>
> Got request with the following data<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> command: PAM_AUTHENTICATE<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> domain: <a href="http://sd.int" target="_blank">sd.int</a><br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> user: test<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> service: sshd<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> tty: ssh<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> ruser:<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> rhost: 125.63.90.34<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> authtok type: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> newauthtok type: 0<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> priv: 1<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [pam_print_data] (0x0100):<br>
> cli_pid: 16634<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [sss_krb5_cc_verify_ccache]<br>
> (0x0020): 1078: <a href="tel:%5B-1765328190" value="+911765328190">[-1765328190</a>][Credentials cache permissions incorrect]<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [check_old_ccache] (0x0040):<br>
> Cannot check if saved ccache FILE:/tmp/krb5cc_<a href="tel:1312800003" value="+911312800003">1312800003</a>_LTtoQU is valid<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [krb5_auth_send] (0x0020):<br>
> check_if_ccache_file_is_used failed.<br>
> (Fri Mar 27 10:19:57 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [fo_resolve_service_send]<br>
> (0x0100): Trying to resolve service 'IPA'<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]] [unpack_buffer]<br>
> (0x0100): cmd [241] uid [1312800011] gid [1312800011] validate [true]<br>
> enterprise principal [false] offline [false] UPN [<a href="mailto:test@SD.INT">test@SD.INT</a>]<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]] [unpack_buffer]<br>
> (0x0100): ccname: [FILE:/tmp/krb5cc_1312800011_XXXXXX] keytab:<br>
> [/etc/krb5.keytab]<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]]<br>
> [set_lifetime_options] (0x0100): Cannot read [SSSD_KRB5_RENEWABLE_LIFETIME]<br>
> from environment.<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]]<br>
> [set_lifetime_options] (0x0100): Cannot read [SSSD_KRB5_LIFETIME] from<br>
> environment.<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]]<br>
> [set_canonicalize_option] (0x0100): SSSD_KRB5_CANONICALIZE is set to [true]<br>
> (Fri Mar 27 10:19:57 2015) [[sssd[krb5_child[16637]]]] [k5c_setup_fast]<br>
> (0x0100): SSSD_KRB5_FAST_PRINCIPAL is set to [host/<br>
> <a href="mailto:dns-inf-stg-sg1-01.sd.int@SD.INT">dns-inf-stg-sg1-01.sd.int@SD.INT</a>]<br>
> *(Fri Mar 27 10:19:58 2015) [[sssd[krb5_child[16637]]]] [get_and_save_tgt]<br>
> (0x0020): 981: [-1765328361][Password has expired]*<br>
> *(Fri Mar 27 10:20:01 2015) [[sssd[krb5_child[16637]]]] [map_krb5_error]<br>
> (0x0020): 1043: [-1765328360][Preauthentication failed]*<br>
> (Fri Mar 27 10:20:01 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [child_sig_handler] (0x0100):<br>
> child [16637] finished successfully.<br>
> (Fri Mar 27 10:20:01 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [ipa_get_migration_flag_done]<br>
> (0x0100): Password migration is not enabled.<br>
> (Fri Mar 27 10:20:01 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Backend returned: (0, 17, <NULL>) [Success]<br>
> (Fri Mar 27 10:20:01 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Sending result [17][<a href="http://sd.int" target="_blank">sd.int</a>]<br>
> (Fri Mar 27 10:20:01 2015) [sssd[be[<a href="http://sd.int" target="_blank">sd.int</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Sent result [17][<a href="http://sd.int" target="_blank">sd.int</a>]<br>
> (Fri Mar 27 10:20:01 2015) [sssd[pam]] [pam_dp_process_reply] (0x0100):<br>
> received: [17][<a href="http://sd.int" target="_blank">sd.int</a>]<br>
><br>
><br>
><br>
> *We do not see any of the above error when try to login with "admin" user<br>
> created by IPA and able to login. Seems like there is any issue in creating<br>
> user from our side, though not able to figure out.*<br>
<br>
But this is the very first login after the user has been created right?<br>
Then SSH should prompt you for password change and after that, the<br>
second login should use the updated password.<br>
</blockquote></div><br></div>