On ti, 03 heinä 2018, skrawczenko--- via FreeIPA-users wrote:
Somehow, the admin account is permanently locked
just a simple reproduction
sh-4.2# kinit admin
kinit: Client's credentials have been revoked while getting initial credentials
sh-4.2# kdestroy -A
sh-4.2# kinit <another admin>
Password for <another admin>@bla-bla
sh-4.2# ipa user-unlock admin
------------------------
Unlocked account "admin"
------------------------
sh-4.2# kdestroy -A
sh-4.2# kinit admin
Password for admin@bla-bla
sh-4.2# kdestroy -A
sh-4.2# kinit admin
kinit: Client's credentials have been revoked while getting initial credentials
And this is apparently related to the previous issue which still persists
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/FY2XZVA5YKB4GYJOABZR3SD6IB7PIL2Z/
Nothing suspicious in the logs or i'm looking at wrong logs.
Any ideas please assist, thanks.
You need to look at /var/log/krb5kdc.log on each master.
--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/message/4K34OQLKNJWUBZTNQTMAXGOXVVAE5V6W/