<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I was going to ask about the ipa command error on the ipa server and how to fix it. But then I just tried again and it works.<br><br><span style="font-family:monospace,monospace">$ ipa user-show admin<br> User login: admin<br> Last name: Administrator<br> Home directory: /home/zaira/admin<br> Login shell: /bin/bash<br> UID: 1000<br> GID: 1000<br> Account disabled: False<br> Password: True<br> Member of groups: stagiaires, opera, ipausers, trust admins, admins, oldstaff<br> Kerberos keys available: True<br> SSH public key fingerprint: FA:76:85:EF:2A:D1:12:B9:A8:A4:F4:AE:45:B2:63:05 admin@ipasrv (ssh-dss)</span><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Before trying again, I just ran a 'dnf update' and rebooted the server on the new kernel (4.1.8-200.fc22.x86_64).<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Oct 5, 2015 at 4:07 PM, Petr Vobornik <span dir="ltr"><<a href="mailto:pvoborni@redhat.com" target="_blank">pvoborni@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="">On 10/05/2015 12:55 PM, Fujisan wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
It is actually on the ipa server that ipa commands are not working. On ipa<br>
clients, I do not have errors.<br>
<br>
<br>
<br>
On Mon, Oct 5, 2015 at 12:27 PM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>> wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I just noticed I can log in to the web UI with user admin and his password.<br>
<br>
But when I try to configure firefox to use kerberos, I click on "Install<br>
Kerberos Configuration Firefox Extension" button, a message appears saying<br>
"Firefox prevented this site from asking you to install software on your<br>
computer", so I click on the "Allow" button and then another message<br>
appears "The add-on downloaded from this site could not be installed<br>
because it appears to be corrupt.".<br>
</blockquote></blockquote>
<br></span>
Here you hit <a href="https://fedorahosted.org/freeipa/ticket/4906" rel="noreferrer" target="_blank">https://fedorahosted.org/freeipa/ticket/4906</a><br>
<br>
Fix(will be in 4.2.2 release) for this ticket changes the procedure for new versions of Firefox to a manual configuration. Basically the steps for Firefox which are described on page <a href="http://your-ipa.example.test/ipa/config/ssbrowser.html" rel="noreferrer" target="_blank">http://your-ipa.example.test/ipa/config/ssbrowser.html</a><div class=""><div class="h5"><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
And the ipa commands are still not working.<br>
$ ipa user-show admin<br>
ipa: ERROR: cannot connect to '<a href="https://zaira2.opera/ipa/json" rel="noreferrer" target="_blank">https://zaira2.opera/ipa/json</a>':<br>
Unauthorized<br>
<br>
<br>
On Mon, Oct 5, 2015 at 12:13 PM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>> wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I uninstalled the ipa server and reinstalled it. Then restored the backup.<br>
And then the following:<br>
<br>
$ keyctl list @s<br>
3 keys in keyring:<br>
437165764: --alswrv 0 65534 keyring: _uid.0<br>
556579409: --alswrv 0 0 user:<br>
ipa_session_cookie:host/zaira2.opera@OPERA<br>
286806445: ---lswrv 0 65534 keyring: _persistent.0<br>
$ keyctl purge 556579409<br>
purged 0 keys<br>
$ keyctl reap<br>
0 keys reaped<br>
$ ipa user-show admin<br>
ipa: ERROR: cannot connect to '<a href="https://zaira2.opera/ipa/json" rel="noreferrer" target="_blank">https://zaira2.opera/ipa/json</a>':<br>
Unauthorized<br>
$ keyctl list @s<br>
3 keys in keyring:<br>
437165764: --alswrv 0 65534 keyring: _uid.0<br>
556579409: --alswrv 0 0 user:<br>
ipa_session_cookie:host/zaira2.opera@OPERA<br>
286806445: ---lswrv 0 65534 keyring: _persistent.0<br>
<br>
It doesn't seem to purge or to reap.<br>
<br>
<br>
<br>
On Mon, Oct 5, 2015 at 9:17 AM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>> wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Good morning,<br>
<br>
Any suggestion what I should do?<br>
<br>
I still have<br>
<br>
$ ipa user-show admin<br>
ipa: ERROR: cannot connect to '<a href="https://zaira2.opera/ipa/json" rel="noreferrer" target="_blank">https://zaira2.opera/ipa/json</a>':<br>
Unauthorized<br>
<br>
<br>
Regards.<br>
<br>
<br>
On Fri, Oct 2, 2015 at 5:04 PM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>> wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I only have this:<br>
<br>
$ keyctl list @s<br>
1 key in keyring:<br>
641467419: --alswrv 0 65534 keyring: _uid.0<br>
$<br>
<br>
<br>
<br>
On Fri, Oct 2, 2015 at 5:01 PM, Alexander Bokovoy <<a href="mailto:abokovoy@redhat.com" target="_blank">abokovoy@redhat.com</a>><br>
wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
On Fri, 02 Oct 2015, Fujisan wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I forgot to mention that<br>
<br>
$ ipa user-show admin<br>
ipa: ERROR: cannot connect to '<a href="https://zaira2.opera/ipa/json" rel="noreferrer" target="_blank">https://zaira2.opera/ipa/json</a>':<br>
Unauthorized<br>
<br>
</blockquote>
This is most likely because of the cached session to your server.<br>
<br>
You can check if keyctl list @s<br>
returns you something like<br>
[root@m1 ~]# keyctl list @s<br>
2 keys in keyring:<br>
496745412: --alswrv 0 65534 keyring: _uid.0<br>
215779962: --alswrv 0 0 user:<br>
<a href="mailto:ipa_session_cookie%3Aadmin@EXAMPLE.COM" target="_blank">ipa_session_cookie:admin@EXAMPLE.COM</a><br>
<br>
If so, then notice the key number (215779962) for the session cookie,<br>
and do:<br>
keyctl purge 215779962<br>
keyctl reap<br>
<br>
This should make a next 'ipa ...' command run to ask for new cookie.<br>
<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
On Fri, Oct 2, 2015 at 4:44 PM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>> wrote:<br>
<br>
I still cannot login to the web UI.<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
Here is what I did:<br>
<br>
1. mv /etc/krb5.keytab /etc/krb5.keytab.save<br>
2. kinit admin<br>
Password for admin@OPERA:<br>
3. ipa-getkeytab -s zaira2.opera -p host/zaira2.opera@OPERA -k<br>
/etc/krb5.keytab<br>
4. systemctl restart sssd.service<br>
5. mv /etc/httpd/conf/ipa.keytab /etc/httpd/conf/ipa.keytab.save<br>
6. ipa-getkeytab -s zaira2.opera -p HTTP/zaira2.opera@OPERA -k<br>
/etc/httpd/conf/ipa.keytab<br>
7. systemctl restart httpd.service<br>
<br>
<br>
The log says now:<br>
<br>
Oct 02 16:40:56 zaira2.opera krb5kdc[9065](info): AS_REQ (9 etypes<br>
{18 17<br>
16 23 25 26 1 3 2}) <a href="http://10.0.21.18" rel="noreferrer" target="_blank">10.0.21.18</a>: NEEDED_PREAUTH:<br>
HTTP/zaira2.opera@OPERA<br>
for krbtgt/OPERA@OPERA, Additional pre-authentication required<br>
<br>
<br>
<br>
On Fri, Oct 2, 2015 at 4:25 PM, Alexander Bokovoy <<br>
<a href="mailto:abokovoy@redhat.com" target="_blank">abokovoy@redhat.com</a>><br>
wrote:<br>
<br>
On Fri, 02 Oct 2015, Fujisan wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
Well, I think I messed up when trying to configure cockpit to use<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
kerberos.<br>
<br>
What should I do to fix this?<br>
<br>
I have this on the ipa server:<br>
$ klist -k<br>
Keytab name: FILE:/etc/krb5.keytab<br>
KVNO Principal<br>
----<br>
<br>
<br>
--------------------------------------------------------------------------<br>
2 host/zaira2.opera@OPERA<br>
2 host/zaira2.opera@OPERA<br>
2 host/zaira2.opera@OPERA<br>
2 host/zaira2.opera@OPERA<br>
1 nfs/zaira2.opera@OPERA<br>
1 nfs/zaira2.opera@OPERA<br>
1 nfs/zaira2.opera@OPERA<br>
1 nfs/zaira2.opera@OPERA<br>
3 HTTP/zaira2.opera@OPERA<br>
3 HTTP/zaira2.opera@OPERA<br>
3 HTTP/zaira2.opera@OPERA<br>
3 HTTP/zaira2.opera@OPERA<br>
<br>
You can start by:<br>
<br>
</blockquote>
0. backup every file mentioned below<br>
1. Move /etc/krb5.keytab somewhere<br>
2. kinit as admin<br>
3. ipa-getkeytab -s `hostname` -p host/`hostname` -k<br>
/etc/krb5.keytab<br>
4. restart SSSD<br>
5. Move /etc/httpd/conf/ipa.keytab somewhere<br>
6. ipa-getkeytab -s `hostname` -p HTTP/`hostname` -k<br>
/etc/httpd/conf/ipa.keytab<br>
7. Restart httpd<br>
<br>
Every time you run 'ipa-getkeytab', Kerberos key for the service<br>
specified by you is replaced on the server side so that keys in the<br>
keytabs become unusable.<br>
<br>
I guess cockpit instructions were for something that was not<br>
supposed to<br>
run on IPA master. On IPA master there are already all needed<br>
services<br>
(host/ and HTTP/) and their keytabs are in place.<br>
<br>
<br>
<br>
On Fri, Oct 2, 2015 at 3:45 PM, Alexander Bokovoy <<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<a href="mailto:abokovoy@redhat.com" target="_blank">abokovoy@redhat.com</a>><br>
wrote:<br>
<br>
On Fri, 02 Oct 2015, Fujisan wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
More info:<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
I can initiate a ticket:<br>
$ kdestroy<br>
$ kinit admin<br>
<br>
but cannot view user admin:<br>
$ ipa user-show admin<br>
ipa: ERROR: cannot connect to '<a href="https://zaira2.opera/ipa/json" rel="noreferrer" target="_blank">https://zaira2.opera/ipa/json</a>':<br>
Unauthorized<br>
<br>
$ ipactl status<br>
Directory Service: RUNNING<br>
krb5kdc Service: RUNNING<br>
kadmin Service: RUNNING<br>
named Service: RUNNING<br>
ipa_memcached Service: RUNNING<br>
httpd Service: RUNNING<br>
pki-tomcatd Service: RUNNING<br>
smb Service: RUNNING<br>
winbind Service: RUNNING<br>
ipa-otpd Service: RUNNING<br>
ipa-dnskeysyncd Service: RUNNING<br>
ipa: INFO: The ipactl command was successful<br>
<br>
/var/log/messages:<br>
Oct 2 14:48:55 zaira2 [sssd[ldap_child[4991]]]: Failed to<br>
initialize<br>
credentials using keytab [MEMORY:/etc/krb5.keytab]: Decrypt<br>
integrity<br>
check<br>
failed. Unable to create GSSAPI-encrypted LDAP connection.<br>
<br>
What did you do?<br>
<br>
</blockquote>
<br>
This and the log below about HTTP/zaira2.opera@OPERA show that<br>
you have<br>
different keys in LDAP and in your keytab files for<br>
host/zaira2.opera<br>
and HTTP/zaira2.opera principals. This might happen if somebody<br>
removed<br>
the principals from LDAP (ipa service-del/ipa service-add, or ipa<br>
host-del/ipa host-add) so that they become non-synchronized with<br>
whatever you have in the keytab files.<br>
<br>
<br>
On Fri, Oct 2, 2015 at 2:26 PM, Fujisan <<a href="mailto:fujisan43@gmail.com" target="_blank">fujisan43@gmail.com</a>><br>
wrote:<br>
<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Hello,<br>
<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I cannot login to the web UI anymore.<br>
<br>
The password or username you entered is incorrect.<br>
<br>
Log says:<br>
<br>
Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): AS_REQ (9<br>
etypes<br>
{18 17<br>
16 23 25 26 1 3 2}) <a href="http://10.0.21.18" rel="noreferrer" target="_blank">10.0.21.18</a>: NEEDED_PREAUTH:<br>
HTTP/zaira2.opera@OPERA<br>
for krbtgt/OPERA@OPERA, Additional pre-authentication required<br>
Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): closing down<br>
fd 12<br>
Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): preauth<br>
(encrypted_timestamp) verify failure: Decrypt integrity check<br>
failed<br>
Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): AS_REQ (9<br>
etypes<br>
{18 17<br>
16 23 25 26 1 3 2}) <a href="http://10.0.21.18" rel="noreferrer" target="_blank">10.0.21.18</a>: PREAUTH_FAILED:<br>
HTTP/zaira2.opera@OPERA<br>
for krbtgt/OPERA@OPERA, Decrypt integrity check failed<br>
Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): closing down<br>
fd 12<br>
<br>
<br>
I have no idea what went wrong.<br>
<br>
What can I do?<br>
<br>
Regards,<br>
Fuji<br>
<br>
<br>
<br>
--<br>
<br>
</blockquote>
<br>
</blockquote>
Manage your subscription for the Freeipa-users mailing list:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br>
<br>
<br>
<br>
</blockquote>
--<br>
/ Alexander Bokovoy<br>
<br>
<br>
--<br>
</blockquote></blockquote>
/ Alexander Bokovoy<br>
<br>
<br>
</blockquote>
<br>
<br>
</blockquote></blockquote>
--<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br>
<br>
</blockquote>
<br>
<br>
--<br>
/ Alexander Bokovoy<br>
<br>
</blockquote></blockquote></blockquote></blockquote></blockquote></blockquote>
<br>
<br>
<br></div></div><span class=""><font color="#888888">
-- <br>
Petr Vobornik<br>
</font></span></blockquote></div><br></div></div>