On Пят, 06 кас 2023, Erik Ostrom via FreeIPA-users wrote:
it seems my pastebin link didn't quite come through as expected... he's the 
link again https://pastebin.com/HW4DcGT0

This error:

(2023-10-05 15:13:36): [krb5_child[325764]] [get_and_save_tgt] (0x0020): [RID#527] 2009: [-1765328377][Error constructing AP-REQ armor: Server krbtgt/[email protected] not found in Kerberos database]

says that SSSD attempted to validate a received Kerberos ticket using
host/.... service principal keytab on the host and failed to do so. This
typically happens when FAST use is enforced on AD side and we only have
a one-way trust to that AD forest.

See
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/planning_identity_management/planning-a-cross-forest-trust-between-idm-and-ad_planning-identity-management#con_kerberos-fast-for-trusted-domains_planning-a-cross-forest-trust-between-idm-and-ad
for more details.



--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to