<div dir="ltr"><div>yes the space was indeed the culprit... i cleaned up some and login works fine now..<br><br></div>Thanks !!<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Mar 15, 2016 at 1:55 PM, Sumit Bose <span dir="ltr"><<a href="mailto:sbose@redhat.com" target="_blank">sbose@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="HOEnZb"><div class="h5">On Mon, Mar 14, 2016 at 05:50:34PM +0530, Rakesh Rajasekharan wrote:<br>
> I set up freeipa in my environment and works perfectly.<br>
><br>
> But just on one host , I am not able to authenticate. I get a permission<br>
> denied eror.<br>
><br>
> The sssd version I have is 1.12<br>
><br>
> the krb5_child log does point to some error,<br>
> krb5_child.log<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]] [unpack_buffer]<br>
> (0x2000): No old ccache<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]] [unpack_buffer]<br>
> (0x0100): ccname: [FILE:/tmp/krb5cc_5102_XXXXXX] old_ccname: [not set]<br>
> keytab: [/etc/krb5.keytab]<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]]<br>
> [k5c_precreate_ccache] (0x4000): Recreating ccache<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]] [k5c_setup_fast]<br>
> (0x0100): SSSD_KRB5_FAST_PRINCIPAL is set to [host/<a href="mailto:1.1.1.1@TEST.COM">1.1.1.1@TEST.COM</a>]<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]]<br>
> [find_principal_in_keytab] (0x4000): Trying to find principal host/<br>
> <a href="mailto:1.1.1.1@TEST.COM">1.1.1.1@TEST.COM</a> in keytab.<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]] [match_principal]<br>
> (0x1000): Principal matched to the sample (host/<a href="mailto:1.1.1.1@TEST.COM">1.1.1.1@TEST.COM</a>).<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11862]]]] [get_tgt_times]<br>
> (0x1000): FAST ccache must be recreated<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11864]]]] [become_user]<br>
> (0x0200): Trying to become user [0][0].<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11864]]]] [become_user]<br>
> (0x0200): Already user [0].<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11864]]]] [check_fast_ccache]<br>
> (0x2000): Running as [0][0].<br>
> (Mon Mar 14 12:02:27 2016) [[sssd[krb5_child[11864]]]]<br>
> [set_canonicalize_option] (0x0100): SSSD_KRB5_CANONICALIZE is set to [true]<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11864]]]] [create_ccache]<br>
> (0x4000): Initializing ccache of type [FILE]<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [check_fast_ccache]<br>
> (0x0200): FAST TGT was successfully recreated!<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [become_user]<br>
> (0x0200): Trying to become user [5102][701].<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [main] (0x2000):<br>
> Running as [5102][701].<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [k5c_setup]<br>
> (0x2000): Running as [5102][701].<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [set_lifetime_options] (0x0100): Cannot read [SSSD_KRB5_RENEWABLE_LIFETIME]<br>
> from environment.<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [set_lifetime_options] (0x0100): Cannot read [SSSD_KRB5_LIFETIME] from<br>
> environment.<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [set_canonicalize_option] (0x0100): SSSD_KRB5_CANONICALIZE is set to [true]<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [main] (0x0400):<br>
> Will perform online auth<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [tgt_req_child]<br>
> (0x1000): Attempting to get a TGT<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]] [get_and_save_tgt]<br>
> (0x0400): Attempting kinit for realm [<a href="http://TEST.COM" rel="noreferrer" target="_blank">TEST.COM</a>]<br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [sss_child_krb5_trace_cb] (0x4000): [11862] 1457956948.18425: Getting<br>
> initial credentials for <a href="mailto:q-tempuser@TEST.COM">q-tempuser@TEST.COM</a><br>
><br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [sss_child_krb5_trace_cb] (0x4000): [11862] 1457956948.18471: FAST armor<br>
> ccache: MEMORY:/var/lib/sss/db/fast_ccache_TEST.COM<br>
><br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [sss_child_krb5_trace_cb] (0x4000): [11862] 1457956948.18502: Retrieving<br>
> host/<a href="mailto:1.1.1.1@TEST.COM">1.1.1.1@TEST.COM</a> -> krb5_ccache_conf_data/fast_avail/krbtgt\/<a href="http://TEST.COM" rel="noreferrer" target="_blank">TEST.COM</a><br>
> \@TEST.COM@X-CACHECONF: from MEMORY:/var/lib/sss/db/fast_ccache_TEST.COM<br>
> with result: -1765328243/Matching credential not found<br>
><br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [sss_child_krb5_trace_cb] (0x4000): [11862] 1457956948.18545: Sending<br>
> request (189 bytes) to <a href="http://TEST.COM" rel="noreferrer" target="_blank">TEST.COM</a><br>
><br>
> (Mon Mar 14 12:02:28 2016) [[sssd[krb5_child[11862]]]]<br>
> [sss_child_krb5_trace_cb] (0x4000): [11862] 1457956948.187.36: Initiating<br>
> TCP connection to stre<br>
> (END)<br>
<br>
</div></div>Does the krb5_child.log really ends here? If yes, any change the disk is<br>
full?<br>
<br>
bye,<br>
Sumit<br>
<div class="HOEnZb"><div class="h5"><br>
><br>
><br>
> And here are the contents from sssd_domain.log<br>
> <a href="http://sssd_test.com" rel="noreferrer" target="_blank">sssd_test.com</a><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> domain: <a href="http://test.com" rel="noreferrer" target="_blank">test.com</a><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> user: q-tempuser<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> service: sshd<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> tty: ssh<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> ruser:<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> rhost: 127.0.0.1<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> authtok type: 1<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> newauthtok type: 0<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> priv: 1<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> cli_pid: 11794<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [pam_print_data] (0x0100):<br>
> logon name: not set<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [ldb] (0x4000): Added timed<br>
> event "ltdb_callback": 0x69e690<br>
><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [ldb] (0x4000): Added timed<br>
> event "ltdb_timeout": 0x69e7b0<br>
><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [ldb] (0x4000): Running<br>
> timer event 0x69e690 "ltdb_callback"<br>
><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [ldb] (0x4000): Destroying<br>
> timer event 0x69e7b0 "ltdb_timeout"<br>
><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [ldb] (0x4000): Ending<br>
> timer event 0x69e690 "ltdb_callback"<br>
><br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]]<br>
> [krb5_auth_prepare_ccache_name] (0x1000): No ccache file for user<br>
> [q-tempuser] found.<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [fo_resolve_service_send]<br>
> (0x0100): Trying to resolve service 'IPA'<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [get_server_status]<br>
> (0x1000): Status of server '<a href="http://ipa-test-master.test.com" rel="noreferrer" target="_blank">ipa-test-master.test.com</a>' is 'working'<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [get_port_status] (0x1000):<br>
> Port status of port 0 for server '<a href="http://ipa-test-master.test.com" rel="noreferrer" target="_blank">ipa-test-master.test.com</a>' is 'working'<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]]<br>
> [fo_resolve_service_activate_timeout] (0x2000): Resolve timeout set to 6<br>
> seconds<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [get_server_status]<br>
> (0x1000): Status of server '<a href="http://ipa-test-master.test.com" rel="noreferrer" target="_blank">ipa-test-master.test.com</a>' is 'working'<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [be_resolve_server_process]<br>
> (0x1000): Saving the first resolved server<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [be_resolve_server_process]<br>
> (0x0200): Found address for server <a href="http://ipa-test-master.test.com" rel="noreferrer" target="_blank">ipa-test-master.test.com</a>: [10.1.6.56]<br>
> TTL 183<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [child_handler_setup]<br>
> (0x2000): Setting up signal handler up for pid [11797]<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [child_handler_setup]<br>
> (0x2000): Signal handler set up for pid [11797]<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [write_pipe_handler]<br>
> (0x0400): All data has been sent!<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [child_sig_handler]<br>
> (0x1000): Waiting for child [11797].<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [child_sig_handler]<br>
> (0x0100): child [11797] finished successfully.<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [read_pipe_handler]<br>
> (0x0400): EOF received, client finished<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [parse_krb5_child_response]<br>
> (0x1000): child response [1432158209][6][8].<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Backend returned: (0, 4, <NULL>) [Success]<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Sending result [4][<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]<br>
> (Mon Mar 14 11:57:12 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [be_pam_handler_callback]<br>
> (0x0100): Sent result [4][<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]<br>
> (Mon Mar 14 11:57:15 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [sbus_dispatch] (0x4000):<br>
> dbus conn: 0x678710<br>
> (Mon Mar 14 11:57:15 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [sbus_dispatch] (0x4000):<br>
> Dispatching.<br>
> (Mon Mar 14 11:57:15 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [sbus_message_handler]<br>
> (0x4000): Received SBUS method [ping]<br>
> (Mon Mar 14 11:57:15 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]] [sbus_get_sender_id_send]<br>
> (0x2000): Not a sysbus message, quit<br>
> (Mon Mar 14 11:57:15 2016) [sssd[be[<a href="http://test.com" rel="noreferrer" target="_blank">test.com</a>]]]<br>
> [sbus_handler_got_caller_id] (0x4000): Received SBUS method [ping]<br>
><br>
><br>
> Not sure what could be wrong here, I think thisused to work fine earlier .<br>
><br>
><br>
> Thanks,<br>
> Rakesh<br>
<br>
</div></div><span class="HOEnZb"><font color="#888888">> --<br>
> Manage your subscription for the Freeipa-users mailing list:<br>
> <a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
> Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br>
<br>
--<br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br>
</font></span></blockquote></div><br></div>