When a user changes their password in fas, it syncs to ipa (for use with kinit). In the past this worked because the user that fas used to sync that had a special flag set to make sure the password was not marked expired. Either that flag isn't set anymore or something else changed in the new rhel8 ipa because users who change their password now are being prompted to change it again from kinit.
We need to figure out why thats happening and fix it so users can get kerberos tickets.
@puiterwijk was going to look into this
In the mean time, is there a work around?
This is now fixed.
Metadata Update from @puiterwijk: - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)
Login to comment on this ticket.