#2781 New user is denied authentication
Closed: Invalid None Opened 8 years ago by tbabej.

When trying to log in with a newly created user, I am denied access with Authentication Failure.

Following info can be found in krb5_child.log

(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [sss_child_krb5_trace_cb] (0x4000): [22388] 1441363831.722867: Response was from master KDC

(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [sss_child_krb5_trace_cb] (0x4000): [22388] 1441363831.722910: Received error from KDC: -1765328353/Decrypt integrity check failed

(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [map_krb5_error] (0x0020): 1298: [-1765328353][Decrypt integrity check failed]
(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [k5c_send_data] (0x0200): Received error code 1432158219
(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [pack_response_packet] (0x2000): response packet size: [4]
(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [k5c_send_data] (0x4000): Response sent.
(Fri Sep  4 12:50:31 2015) [[sssd[krb5_child[22388]]]] [main] (0x0400): krb5_child completed successfully

Tomas has a setup that reproduces the error. We should take a look on Monday as we'll be in close proximity.

priority: major => blocker

We did the investigation, and found out that this was a machine specific issue. The fast ccache contained a old key for the IPA server from the previous installation.

Fields changed

priority: blocker => minor

Fields changed

resolution: => invalid
status: new => closed

Metadata Update from @tbabej:
- Issue set to the milestone: NEEDS_TRIAGE

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3822

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata