Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1029354
Description of problem: ipa-client-install fail due fail to obtain host TGT. ipa-client-install --domain ipa.baseos.qe -p <principa> -w <pass> -U Discovery was successful! Hostname: x86-64-v11.ipa.baseos.qe Realm: IPA.BASEOS.QE DNS Domain: ipa.baseos.qe IPA Server: sec-ipa1.ipa.baseos.qe BaseDN: dc=ipa,dc=baseos,dc=qe Removed old keys for realm IPA.BASEOS.QE from /etc/krb5.keytab Synchronizing time with KDC... Enrolled in IPA realm IPA.BASEOS.QE Failed to obtain host TGT. Installation failed. Rolling back changes. IPA client is not configured on this system. ipa-client-install log contains: 2013-11-12T08:37:53Z DEBUG stderr=Failed to retrieve encryption type Camellia-128 CTS mode with CMAC (#25) Failed to retrieve encryption type Camellia-256 CTS mode with CMAC (#26) Keytab successfully retrieved and stored in: /etc/krb5.keytab Certificate subject base is: O=IPA.BASEOS.QE 2013-11-12T08:37:53Z INFO Enrolled in IPA realm IPA.BASEOS.QE .... 2013-11-12T08:37:53Z DEBUG stderr=kinit: Keytab contains no suitable keys for host/x86-64-v11.ipa.baseos.qe@IPA.BASEOS.QE while getting initial credentials 2013-11-12T08:37:53Z ERROR Failed to obtain host TGT. Version-Release number of selected component (if applicable): ipa-client-3.3.3-3.el7 krb5-libs-1.11.3-31.el7 How reproducible: always Steps to Reproduce: 1.run ipa-client-install 2. 3. Actual results: Expected results: Additional info:
See [discussion in downstream bug], especially https://bugzilla.redhat.com/show_bug.cgi?id=1029354#c24 Comment 24.
Moving to next month iteration.
master: 89ab877[[BR]] ipa-3-3: e2625b6
Metadata Update from @mkosek: - Issue assigned to tbabej - Issue set to the milestone: FreeIPA 3.3.x - 2013/12 (bug fixing)
Login to comment on this ticket.