[Freeipa-users] ipa command line tools failure

Rob Crittenden rcritten at redhat.com
Fri Apr 24 13:51:02 UTC 2009


Nick Gresham wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Hi
> 
> We've been using freeipa on Centos 5 successfully at our medium-scale
> research site for several months now.
> 
> We're currently running freeipa-1.2.1, installed via RPMs built from 
> source.
> 
> However, after the recent upgrade Centos 5.2 ---> Centos 5.3 the ipa
> command line utilities are broken, e.g.
> 
> $ ipa-finduser -v testuser
> Connecting to IPA server: https://xxx.yyy.ac.uk/ipa/xml
> Did not receive Kerberos credentials.
> 
> The web-interface is fine.
> 
> Has anyone else had this problem? Is there a fix or workaround?
> 
> Thanks in advance
> 
> [NG]

See if you have a forwardable ticket:

% klist -f

The flags for your TGT should include F.

Another option is to look in the Apache error log 
(/var/log/httpd/error_log). You may have to set LogLevel debug in 
/etc/httpd/conf/httpd.conf to get more details.

rob




More information about the Freeipa-users mailing list