<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><font face="Carlito">Hi all,</font></p>
<font face="Carlito">I tried the FreeIPA webUI, ssh and "su -
otpuser", all the same result.<br>
<br>
Winny<br>
<br>
</font>
<div class="moz-cite-prefix">Op 07-06-16 om 15:02 schreef Alexander
Bokovoy:<br>
</div>
<blockquote cite="mid:20160607130203.zyms26vj3bhztozz@redhat.com"
type="cite">On Tue, 07 Jun 2016, Winfried de Heiden wrote:
<br>
<blockquote type="cite">Hi all,
<br>
<br>
I am trying to setup Freeipa with otp using the freeotp app. All
looks fine,
<br>
adding the user to the FreeOTP app also works fine. The users
looks like:
<br>
ipa user-show otpuser
<br>
User login: otpuser
<br>
First name: otp
<br>
Last name: user
<br>
Home directory: /home/otpuser
<br>
Login shell: /bin/bash
<br>
Email address: <a class="moz-txt-link-abbreviated" href="mailto:otpuser@blabla.bla">otpuser@blabla.bla</a>
<br>
UID: 10011
<br>
GID: 10011
<br>
User authentication types: otp
<br>
Account disabled: False
<br>
Password: True
<br>
Member of groups: ipausers
<br>
Kerberos keys available: True
<br>
<br>
However, trying to login in will fail; /var/log/krb5kdc.log will
tell:
<br>
<br>
Jun 07 14:44:37 ipa.blabla.bla krb5kdc[5887](info): AS_REQ (6
etypes {18 17 16
<br>
23 25 26}) 192.168.1.251: NEEDED_PREAUTH: <a class="moz-txt-link-abbreviated" href="mailto:otpuser@BLABLA.BLA">otpuser@BLABLA.BLA</a> for
krbtgt/
<br>
<a class="moz-txt-link-abbreviated" href="mailto:BLABLA.BLA@BLABLA.BLA">BLABLA.BLA@BLABLA.BLA</a>, Additional pre-authentication required
<br>
Jun 07 14:44:37 ipa.blabla.bla krb5kdc[5887](info): closing down
fd 12
<br>
Jun 07 14:44:42 ipa.blabla.bla krb5kdc[5888](info): preauth
(otp) verify
<br>
failure: Connection timed out
<br>
<br>
I just cannot figure out what's going wrong. What is trying to
connect to
<br>
causing this timeout? (yep, I disabled firewalld for this...)
<br>
</blockquote>
How did you try to login?
<br>
<br>
<br>
</blockquote>
<br>
</body>
</html>