After creating a new account or resetting a users password from the Web UI, the user needs to reset the password on first login. The issue is, they get authentication failed from any server with the exception of the IPA master server. I feel this is a security concern as I don't want just any user having access to the IPA master. How can I allow the users to log into a client server and reset the initial password? This also occurs when a password expires. The user gets authentication failed on the client servers and has to attempt to login on the IPA master server.
What version of FreeIPA and SSSD do you use?
Also are they IPA users or AD users. Workaround may be to reset password in Web UI and then ssh to other server.
Maybe it can be: * https://pagure.io/SSSD/sssd/issue/3426
Metadata Update from @fbarreto: - Issue assigned to fbarreto
I was not able to reproduce it. @tpickeri could you provide some info like: - What version of FreeIPA and SSSD do you use? - What is the topology of server/replicas? - Are they IPA users or AD users?
Closing due to lack of information.
Metadata Update from @pvoborni: - Issue close_status updated to: insufficientinfo - Issue status updated to: Closed (was: Open)