Hi Rob,

Thanks for the reply. I did reset the user password multiple times to a simple 
password, still having same issue.

Gady

-----Original Message-----
From: Rob Crittenden [mailto:rcrit...@redhat.com] 
Sent: April 18, 2016 2:25 PM
To: Gady Notrica; freeipa-users@redhat.com
Subject: Re: [Freeipa-users] NEEDED_PREAUTH: Additional pre-authentication 
required - User can't access any centos server

Gady Notrica wrote:
> Hi guys,
>
>  From the ipa server, I am having issue with the single user. Everyone 
> else is fine, just this one single user and no help anywhere online.
>
> Please help!

Decrypt integrity check failed almost always means bad password.

rob

>
> Thank you
>
> Apr 15 15:43:36 ipa.domain.com krb5kdc[2568](info): AS_REQ (6 etypes 
> {18
> 17 16 23 25 26}) 172.20.10.40: *NEEDED_PREAUTH*: 
> bcos...@ipa.domain.com for krbtgt/ipa.domain....@ipa.domain.com, 
> *Additional pre-authentication
> required*
>
> Apr 15 15:43:36 ipa.domain.com krb5kdc[2568](info): closing down fd 12
>
> Apr 15 15:43:41 ipa.domain.com krb5kdc[2565](info): preauth
> (encrypted_timestamp) verify failure: *Decrypt integrity check failed*
>
> Apr 15 15:43:41 ipa.domain.com krb5kdc[2565](info): AS_REQ (6 etypes 
> {18
> 17 16 23 25 26}) 172.20.10.40: *PREAUTH_FAILED*: 
> bcos...@ipa.domain.com for krbtgt/ipa.domain....@ipa.domain.com, 
> Decrypt integrity check failed
>
> Apr 15 15:43:41 ipa.domain.com krb5kdc[2565](info): closing down fd 12
>
> Apr 15 15:43:49 ipa.domain.com krb5kdc[2568](info): AS_REQ (6 etypes 
> {18
> 17 16 23 25 26}) 172.20.10.40: *NEEDED_PREAUTH*: 
> bcos...@ipa.domain.com for krbtgt/ipa.domain....@ipa.domain.com, 
> *Additional pre-authentication
> required*
>
> Apr 15 15:43:49 ipa.domain.com krb5kdc[2568](info): closing down fd 12
>
> Apr 15 15:43:55 ipa.domain.com krb5kdc[2565](info): preauth
> (encrypted_timestamp) verify failure: *Decrypt integrity check failed*
>
> Apr 15 15:43:55 ipa.domain.com krb5kdc[2565](info): AS_REQ (6 etypes 
> {18
> 17 16 23 25 26}) 172.20.10.40: *PREAUTH_FAILED*: 
> bcos...@ipa.domain.com for krbtgt/ipa.domain....@ipa.domain.com, 
> Decrypt integrity check failed
>
>
>
>


-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to