as a Linux admin i want to login into my ipa client with a user that is defined in ipa-server UI.
I installed Ipa-server and an Ipa-client on CentOS7.6 I defined Internal DNS on ipa-server and i defined A and PTR records for client on ipa-server. now i can see my client in ipa-UI and i defined a user with name "elham" and i expect that it can login into ipa-client. when i login with root in ipa-client and i do sudo elham, it works and kinit elham works too but when i do ssh into ipa-client with this user, it show "Access denied" i have errors with this context: pam_reply : authentication failure to the client pam_sss: authentication falure
im tired of this issue. please help me if you know the solution.
(what happens)
login into ipa-client successfully
ipa-server 4.6.5-11.el7 ipa-client 4.6.4-10.el7.centos.3
Log file locations:
<!!image> <!!image> <!!image> <!!image> <!!image> <!!image> <!!image> <!!image> <!!image>
<!!image>
Closing, as this is tracked in the community mailing-list:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/RJFBP7ECHACNIXWWFHDAW3M5PQPMPZYU/
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/AJ6KIWGQFCGZU7C6L72WX5IDTZCHCHJN/
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/5ETYVBPPOTQWVSN2QVYD4XZPDTY6IEKR/
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/message/CWH3ILKCF2IMAGOQEXUW3RBUWH6KRAH3/
Please keep the communication in the mailing-list and keep freeipa-users in CC: or To: as mentioned by Rob multiple times.
Metadata Update from @fcami: - Issue close_status updated to: duplicate - Issue status updated to: Closed (was: Open)