>>>>It's impossible to say without any details.

What details do you need?

>>>>What does login mean? It seems to mean ssh but it's unclear.

A ssh login.  A local machine login.  All of the above.

>>>>What output do you get?

Invalid password.  But I know it's the correct password, and I try with the 
<user id>@<domain name> format and that doesn't work either.  Also, if I use a 
local machine account, and try kinit with the same user id and password then it 
works fine.

>>>>What do any of the logs say?

I found something interesting in the secure log.

Failed password for invalid user ad...@xyz.com from <not XYZ.COM FreeIPA Server 
address> port 50203 ssh2

The login is contacting the wrong server to authenticate with.  Where is that 
established in the installation or configuration files?

>>>>Did you apply the same "workaround" everywhere?
The same kerberos work-around, yes, it works so that I can run kinit and it 
finds the Realm KDC.

>>>> Also, I assume you're using webmail, but each response comes in without
any sort of context so its difficult to keep track of the thread using a
typical e-mail client.

No, I am using the website for replies.
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to