#8093 Ipa user can't login via ssh
Closed: duplicate 4 years ago by fcami. Opened 4 years ago by elhamsadat.

Request for enhancement

as a Linux admin i want to login into my ipa client with a user that is defined in ipa-server UI.

Issue

I installed Ipa-server and an Ipa-client on CentOS7.6
I defined Internal DNS on ipa-server and i defined A and PTR records for client on ipa-server.
now i can see my client in ipa-UI and i defined a user with name "elham" and i expect that it can login into ipa-client.
when i login with root in ipa-client and i do sudo elham, it works and kinit elham works too but
when i do ssh into ipa-client with this user, it show "Access denied"
i have errors with this context:
pam_reply : authentication failure to the client
pam_sss: authentication falure

im tired of this issue. please help me if you know the solution.

Steps to Reproduce

  1. define new user "elham" in ipa UI
  2. SSH to ipa-client with elham
  3. access denied

Actual behavior

(what happens)

Expected behavior

login into ipa-client successfully

Version/Release/Distribution

ipa-server 4.6.5-11.el7
ipa-client 4.6.4-10.el7.centos.3

Additional info:

Log file locations:


krb5.conf

krb5_child.log
ldap_child.log
sssd.conf
krb5_child.logldap_child.logsssd.confsssd.logsssd_lshs.dc.logsssd_nss.logsssd_pac.logsssd_pam.log
sssd.log
sssd_nss.log
sssd_pac.log
sssd_pac.log

Metadata Update from @fcami:
- Issue close_status updated to: duplicate
- Issue status updated to: Closed (was: Open)

4 years ago

Login to comment on this ticket.

Metadata
Attachments 9
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment
Attached 4 years ago View Comment