It is not currently possible to log in with any of the migrated users from an OpenLDAP instance.
Although the UI shows success, the password is not changed. The same behaviour occurs when the admin resets the password of the migrated user manually. Users created in FreeIPA work just fine. But for migrated users the login dialog shows that the user does not exist or the password is incorrect.
It should be possible to login with the migrated user and the set password.
freeipa-server-4.12.1-1.fc40.x86_64 freeipa-client-4.12.1-1.fc40.x86_64 package ipa-server is not installed package ipa-client is not installed 389-ds-base-3.0.2-1.fc40.x86_64 package pki-ca is not installed krb5-server-1.21.2-5.fc40.x86_64
Kerberos Logs with user01 as test user.
Jan 16 14:28:46 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:28:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:28:47 freeipa.test.local krb5kdc[1885](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:28:47 freeipa.test.local krb5kdc[1885](info): closing down fd 11 Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:29 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:29 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:36 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034176, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha384-192(20), ses=aes256-cts-hmac-sha384-192(20)}, admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL Jan 16 14:29:36 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:42 freeipa.test.local krb5kdc[1887](info): TGS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034176, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha1-96(18), ses=aes256-cts-hmac-sha384-192(20)}, admin@TEST.LOCAL for ldap/freeipa.test.local@TEST.LOCAL Jan 16 14:29:42 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:46 freeipa.test.local krb5kdc[1885](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: host/freeipa.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:46 freeipa.test.local krb5kdc[1885](info): closing down fd 11 Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034186, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha384-192(20), ses=aes256-cts-hmac-sha384-192(20)}, host/freeipa.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): TGS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034186, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha1-96(18), ses=aes256-cts-hmac-sha384-192(20)}, host/freeipa.test.local@TEST.LOCAL for ldap/freeipa.test.local@TEST.LOCAL Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: CLIENT KEY EXPIRED: user01@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Password has expired Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): preauth (spake) verify failure: Preauthentication failed Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: PREAUTH_FAILED: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Preauthentication failed Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ : handle_authdata (2) Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: HANDLE_AUTHDATA: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, No such file or directory Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): preauth (spake) verify failure: Preauthentication failed Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: PREAUTH_FAILED: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Preauthentication failed Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): closing down fd 11 Jan 16 14:30:02 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required Jan 16 14:30:02 freeipa.test.local krb5kdc[1887](info): closing down fd 11
getprinc of user01
Authenticating as principal admin/admin@TEST.LOCAL with password. Principal: user01@TEST.LOCAL Expiration date: [never] Last password change: Thu Jan 16 14:11:15 CET 2025 Password expiration date: Thu Jan 16 14:11:15 CET 2025 Maximum ticket life: 1 day 00:00:00 Maximum renewable life: 7 days 00:00:00 Last modified: Thu Jan 16 14:11:15 CET 2025 (root/admin@TEST.LOCAL) Last successful authentication: [never] Last failed authentication: Sun Nov 24 13:42:19 CET 2024 Failed password attempts: 0 Number of keys: 4 Key: vno 6, aes256-cts-hmac-sha384-192:special Key: vno 6, aes128-cts-hmac-sha256-128:special Key: vno 6, aes256-cts-hmac-sha1-96:special Key: vno 6, aes128-cts-hmac-sha1-96:special MKey: vno 1 Attributes: REQUIRES_PRE_AUTH DISALLOW_SVR Policy: [none]
This is not an issue in FreeIPA that needs any fix in the code.
When migrating from data from non-IPA source, ID ranges cannot be set properly (because they don't exist in the original OpenLDAP source) and SIDs cannot be generated. It is an operational problem most likely due to missing SIDs. See https://freeipa.readthedocs.io/en/latest/designs/id-mapping.html for technical details.
Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ : handle_authdata (2) Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: HANDLE_AUTHDATA: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, No such file or directory
handle_authdata problems in krb5kdc.log tell that KDC was unable to issue a ticket with PAC record for the user user1@TEST.LOCAL. This typically happens because this user has no ipaNTSecurityIdentifier attribute in the record.
handle_authdata
krb5kdc.log
user1@TEST.LOCAL
ipaNTSecurityIdentifier
See also https://access.redhat.com/articles/7027037 for some explanation and solutions as well. You need RHEL subscription; using a free Red Hat developer subscription is enough. FreeIPA 4.12.1 should also have a tool ipa-idrange-fix that helps to automate ID range adjustment. Make sure to read its manual page.
ipa-idrange-fix
Oh, sorry, ipa-idrange-fix is part of 4.12.2 release, so it is not in the version you have.
Thank you for the extended explanation!
So it is intended that the UI shows, that the password migration was successful?
These are kind of unrelated actions.
A password can be changed with migration procedure. However, obtaining an active Kerberos ticket requires proper user object setup with a SID assigned to the account.
Closing as this is an operational issue. If you are unable to fix it by following resources I gave, look at the freeipa-users@ mailing list archives for a number of similar investigations over past couple years. There were plenty cases there, demonstrating both how to solve the issues and what data needs to be provided. In case you still stuck, please use the mailing list.
Metadata Update from @abbra: - Issue close_status updated to: worksforme - Issue status updated to: Closed (was: Open)