Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-07 Thread Sumit Bose
On Tue, Oct 06, 2015 at 03:39:43PM +0200, Alexander Skwar wrote: > Hello Sumit > > ipa-client-install hasn't set krb5_realm. I did that. > > We're using Chef-Solo to manage our systems and I have /etc/sssd/sssd.conf > in chef. So it overwrote, whatever ipa-client-install put there. And that's > h

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-06 Thread Alexander Skwar
Hello Sumit ipa-client-install hasn't set krb5_realm. I did that. We're using Chef-Solo to manage our systems and I have /etc/sssd/sssd.conf in chef. So it overwrote, whatever ipa-client-install put there. And that's how the mistake happened. I think the ipa-client-install discovered everything

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-06 Thread Sumit Bose
On Tue, Oct 06, 2015 at 11:26:42AM +0200, Alexander Skwar wrote: > Hi > > With further debugging, I discovered, that I messed up the > /etc/sssd/sssd.conf file. There, I added: > > … > [domain/customer.company.internal] > > krb5_realm = customer.company.internal > … > > > > Exactly like that.

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-06 Thread Alexander Skwar
Hi With further debugging, I discovered, that I messed up the /etc/sssd/sssd.conf file. There, I added: … [domain/customer.company.internal] krb5_realm = customer.company.internal … Exactly like that. With "krb5_realm = customer.company.internal"; ie. with the realm in lowercase letters. Aft

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-05 Thread Sumit Bose
On Mon, Oct 05, 2015 at 09:00:13AM +0200, Alexander Skwar wrote: > Hi > > Hm, there's nothing at all in the /var/log/sssd/krb5_child.log when I try > to login with SSH and enter a password. Can you try to increase the debug_level to 0xFFF0? > > kinit doesn't work. > > $ kinit -k > kinit: Permi

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-05 Thread Alexander Skwar
Hi Hm, when I'm root, "kinit -k" works: # kinit -k # Just not as a user. As a user, I get the "kinit: Permission denied while getting initial credentials" error message. Regards, Alexander 2015-10-05 9:00 GMT+02:00 Alexander Skwar < alexanders.mailinglists+nos...@gmail.com>: > Hi > > Hm, th

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-05 Thread Alexander Skwar
Hi Hm, there's nothing at all in the /var/log/sssd/krb5_child.log when I try to login with SSH and enter a password. kinit doesn't work. $ kinit -k kinit: Permission denied while getting initial credentials For this test, I was root and then did a "su - user" and then "kinit -k". Also after the

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-02 Thread Jakub Hrozek
On Fri, Oct 02, 2015 at 04:28:57PM +0200, Alexander Skwar wrote: > Hello > > How do I get password authentication to work with freeipa-client > 3.3.4-0ubuntu3.1 on Ubuntu 14.04 for ssh and sudo? > > Long version follows :) > > We've got an IPA server with the Red Hat Identity Management server >

Re: [Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-02 Thread Sumit Bose
On Fri, Oct 02, 2015 at 04:28:57PM +0200, Alexander Skwar wrote: > Hello > > How do I get password authentication to work with freeipa-client > 3.3.4-0ubuntu3.1 on Ubuntu 14.04 for ssh and sudo? > > Long version follows :) > > We've got an IPA server with the Red Hat Identity Management server >

[Freeipa-users] ssh and sudo password authentication not working with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04

2015-10-02 Thread Alexander Skwar
Hello How do I get password authentication to work with freeipa-client 3.3.4-0ubuntu3.1 on Ubuntu 14.04 for ssh and sudo? Long version follows :) We've got an IPA server with the Red Hat Identity Management server on RHEL 7.1 servers; FreeIPA v4.1.0 is being used there. I configured users and gr