[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-14 Thread Simo Sorce via FreeIPA-users
On Mon, 2018-05-14 at 14:44 -0400, Josh via FreeIPA-users wrote: > On 05/14/2018 01:29 PM, Alexander Bokovoy wrote: > > Talking with Simo, we realized that since we are using random salt for > > all IPA principals, you need to know the salt when creating a keytab > > entry. You only can retrieve th

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-14 Thread Josh via FreeIPA-users
On 05/14/2018 01:29 PM, Alexander Bokovoy wrote: Talking with Simo, we realized that since we are using random salt for all IPA principals, you need to know the salt when creating a keytab entry. You only can retrieve that via KRB5_TRACE for kinit like I did in https://paste.fedoraproject.org/pas

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-14 Thread Alexander Bokovoy via FreeIPA-users
On ma, 14 touko 2018, Rob Crittenden via FreeIPA-users wrote: Josh via FreeIPA-users wrote: On 05/12/2018 01:53 AM, Alexander Bokovoy wrote: On pe, 11 touko 2018, Josh wrote: On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certifica

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-14 Thread Rob Crittenden via FreeIPA-users
Josh via FreeIPA-users wrote: On 05/12/2018 01:53 AM, Alexander Bokovoy wrote: On pe, 11 touko 2018, Josh wrote: On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please sta

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-13 Thread Josh via FreeIPA-users
On 05/12/2018 01:53 AM, Alexander Bokovoy wrote: On pe, 11 touko 2018, Josh wrote: On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please stay on topic and explain if you c

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-11 Thread Alexander Bokovoy via FreeIPA-users
On pe, 11 touko 2018, Josh wrote: On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please stay on topic and explain if you can why ktutil can't be used as described in https

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-11 Thread Josh via FreeIPA-users
On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please stay on topic and explain if you can why ktutil can't be used as described in https://kb.iu.edu/d/aumh? Does ipa make

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Alexander Bokovoy via FreeIPA-users
On to, 10 touko 2018, Josh via FreeIPA-users wrote: On 05/10/2018 02:21 PM, Robbie Harwood wrote: None via FreeIPA-users writes: Josh writes: Destroy the keytab. Recreate using ipa-getkeytab. I can't use ipa-getkeytab at the moment. Is getting keytab via ktutil not possible at all? Any t

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Josh via FreeIPA-users
On 05/10/2018 02:21 PM, Robbie Harwood wrote: None via FreeIPA-users writes: Josh writes: Destroy the keytab. Recreate using ipa-getkeytab. I can't use ipa-getkeytab at the moment. Is getting keytab via ktutil not possible at all? Any technical details about it? How can you use ktutil bu

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Robbie Harwood via FreeIPA-users
None via FreeIPA-users writes: >> Josh writes: >> >> >> Destroy the keytab. Recreate using ipa-getkeytab. > > I can't use ipa-getkeytab at the moment. Is getting keytab via ktutil > not possible at all? Any technical details about it? How can you use ktutil but not ipa-getkeytab? Maybe let'

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread None via FreeIPA-users
> Josh writes: > > > Destroy the keytab. Recreate using ipa-getkeytab. I can't use ipa-getkeytab at the moment. Is getting keytab via ktutil not possible at all? Any technical details about it? Regards, Josh. ___ FreeIPA-users mailing list -- freei

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Robbie Harwood via FreeIPA-users
Josh via FreeIPA-users writes: > On 05/10/2018 10:26 AM, Rob Crittenden wrote: >> Josh via FreeIPA-users wrote: >>> Greetings, >>> >>> I am trying to follow steps at https://kb.iu.edu/d/aumh to create >>> freeipa admin keytab to use in some scripts but getting an error >>> >>> kinit: Preauthenti

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Josh via FreeIPA-users
On 05/10/2018 10:26 AM, Rob Crittenden wrote: Josh via FreeIPA-users wrote: Greetings, I am trying to follow steps at https://kb.iu.edu/d/aumh to create freeipa admin keytab to use in some scripts but getting an error kinit: Preauthentication failed while getting initial credentials This i

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-10 Thread Rob Crittenden via FreeIPA-users
Josh via FreeIPA-users wrote: Greetings, I am trying to follow steps at https://kb.iu.edu/d/aumh to create freeipa admin keytab to use in some scripts but getting an error kinit: Preauthentication failed while getting initial credentials This is usually Kerberos's way of saying "bad passwor