[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread TomK
On 4/25/2017 4:42 PM, Lukas Slebodnik wrote: On (25/04/17 16:35), Tom wrote: We managed to create the key tab entry that worked. We did this earlier and now are at the subject errors instead of the original one. We simply added the working entry into the keytab as a suggested and that moved

[SSSD-users] Re: case sensitivity

2017-04-25 Thread Galen Johnson
So far, this seems to be doing the trick along with https://serverfault.com/questions/310573/problem-with-mixed-cases-in-username. We're still testing but outlook is promising. thanks =G= From: Jakub Hrozek Sent: Tuesday, April 25, 2017 2:30 AM To: ss

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Lukas Slebodnik
On (25/04/17 16:35), Tom wrote: >We managed to create the key tab entry that worked. We did this earlier and >now are at the subject errors instead of the original one. > >We simply added the working entry into the keytab as a suggested and that >moved us to the subject errors. > >The error code

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Tom
Is it possible to email the configuration and logs to RH only? Cheers, Tom Sent from my iPhone > On Apr 25, 2017, at 4:22 PM, Justin Stephenson wrote: > > SSSD searches for a principal to use in the keytab based on the following > priority: > > * Priority of lookup: > 1) our.hostname

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Tom
We managed to create the key tab entry that worked. We did this earlier and now are at the subject errors instead of the original one. We simply added the working entry into the keytab as a suggested and that moved us to the subject errors. The error code now is: 1765328360 which is preceeded

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Justin Stephenson
SSSD searches for a principal to use in the keytab based on the following priority: * Priority of lookup: 1) our.hostname@REALM or host/our.hostname@REALM depending on the input 2) SHORT.HOSTNAME$@REALM (AD domain) 3) host/our.hostname@REALM 4) foobar$@REALM (AD domain

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Lukas Slebodnik
On (25/04/17 15:26), Tom wrote: >Wondering if there are any more suggestions on this topic? > Which version of sssd do you use? Do I understand it correctly that workaround with ldap_sasl_authid does not work? Could you provide log files? It would be good to sanitize just a domain part of hostnam

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread Tom
Wondering if there are any more suggestions on this topic? Cheers, Tom Sent from my iPhone > On Apr 25, 2017, at 3:17 AM, TomK wrote: > >> On 4/25/2017 2:00 AM, TomK wrote: >>> On 4/24/2017 9:40 PM, TomK wrote: On 4/24/2017 12:41 PM, Sumit Bose wrote: > On Mon, Apr 24, 2017 at 12:22:0

[SSSD-users] Re: case sensitivity

2017-04-25 Thread Galen Johnson
thanks...I'll give that a shot... =G= From: Jakub Hrozek Sent: Tuesday, April 25, 2017 2:30 AM To: sssd-users@lists.fedorahosted.org Subject: [SSSD-users] Re: case sensitivity On Mon, Apr 24, 2017 at 07:18:17PM +, Galen Johnson wrote: > Hey, > > > I

[SSSD-users] Using SSSD with a forest trust model

2017-04-25 Thread kn
Hi. I have the following scenario : -'example.com' domain running on premises -'aws.example.com' domain running on 'Amazon Microsoft AD' in VPC with VPN connection to on premises. - One-way trust created from aws.example.com to example.com I´m currently able to log in to a Windows server join

[SSSD-users] Re: 1765328360/Preauthentication failed / 1765328359/Additional pre-authentication required in version sssd 1.13.3 w/ rc4-hmac

2017-04-25 Thread TomK
On 4/25/2017 2:00 AM, TomK wrote: On 4/24/2017 9:40 PM, TomK wrote: On 4/24/2017 12:41 PM, Sumit Bose wrote: On Mon, Apr 24, 2017 at 12:22:02PM -0400, TomK wrote: On 4/21/2017 9:48 PM, TomK wrote: Hey All, We are connecting a set of servers directly with AD. The AD computer object is create