Matt Bernstein wrote:
Is there anything interesting related to the ipa_passwd_extop plug-in in the Directory Server errors log (/var/log/dirsrv/slapd-<realm>/errors)?Hi, not sure where better to send this so here goes..I installed Fedora 9 FreeIPA (1.0) a couple of weeks ago, and yum has since upgraded it to 1.1. Things seem to be pretty good, except changing (or setting new) passwords has stopped working. I don't know if the upgrade was the cause of the error, but I thought I'd better mention it.User's interaction: $ kinit -V tim Password for tim TEST EECS QMUL AC UK: Password expired. You must change it now. Enter new password: Enter it again: kinit(v5): Password change failed while getting initial credentialsFrom krb5kdc.log:Jun 23 17:06:43 eagle krb5kdc[1357](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: CLIENT KEY EXPIRED: tim TEST EECS QMUL AC UK for krbtgt/TEST EECS QMUL AC UK TEST EECS QMUL AC UK, Password has expired Jun 23 17:06:43 eagle krb5kdc[1357](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: NEEDED_PREAUTH: tim TEST EECS QMUL AC UK for kadmin/changepw TEST EECS QMUL AC UK, Additional pre-authentication required Jun 23 17:06:45 eagle krb5kdc[1357](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: ISSUE: authtime 1214237205, etypes {rep=18 tkt=18 ses=18}, tim TEST EECS QMUL AC UK for kadmin/changepw TEST EECS QMUL AC UK Jun 23 17:06:46 eagle krb5kdc[1357](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: NEEDED_PREAUTH: kadmin/changepw TEST EECS QMUL AC UK for krbtgt/TEST EECS QMUL AC UK TEST EECS QMUL AC UK, Additional pre-authentication required Jun 23 17:06:46 eagle krb5kdc[1357](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: ISSUE: authtime 1214237206, etypes {rep=18 tkt=18 ses=18}, kadmin/changepw TEST EECS QMUL AC UK for krbtgt/TEST EECS QMUL AC UK TEST EECS QMUL AC UK Jun 23 17:06:46 eagle krb5kdc[1357](info): TGS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.37.95.132: ISSUE: authtime 1214237206, etypes {rep=18 tkt=18 ses=18}, kadmin/changepw TEST EECS QMUL AC UK for ldap/eagle test eecs qmul ac uk TEST EECS QMUL AC UKFrom syslog:Jun 23 17:06:46 eagle kpasswd[1852]: ldap_parse_result(): [Password generation not implemented.#012]Jun 23 17:06:46 eagle kpasswd[1852]: Password change failedSo.. is any of this helpful? It seems from syslog that the ipa_pwd_extop slapi plugin isn't receiving the new password, but I've no idea why.Can anyone help? It's not SELinux or resource starvation, AFAICT.
-NGK
Matt _______________________________________________ Freeipa-devel mailing list Freeipa-devel redhat com https://www.redhat.com/mailman/listinfo/freeipa-devel
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature