#9733 Authentication with Migrated Users fails
Closed: worksforme by abbra. Opened by mfischer.

Issue

It is not currently possible to log in with any of the migrated users from an OpenLDAP instance.

Steps to Reproduce

  1. Create a new OpenLDAP instance and populate it with user data
  2. Clean installation of a FreeIPA instance running on Fedora OS
  3. Run the migration like described in the documentation
  4. All users are migrated
  5. Login with the user using the UI via the migration endpoint -> UI indicates that the password has been successfully reset
  6. Login with the user and password via the UI fails.

Actual behavior

Although the UI shows success, the password is not changed. The same behaviour occurs when the admin resets the password of the migrated user manually.
Users created in FreeIPA work just fine. But for migrated users the login dialog shows that the user does not exist or the password is incorrect.

Expected behavior

It should be possible to login with the migrated user and the set password.

Version/Release/Distribution

freeipa-server-4.12.1-1.fc40.x86_64
freeipa-client-4.12.1-1.fc40.x86_64
package ipa-server is not installed
package ipa-client is not installed
389-ds-base-3.0.2-1.fc40.x86_64
package pki-ca is not installed
krb5-server-1.21.2-5.fc40.x86_64

Additional info:

Kerberos Logs with user01 as test user.

Jan 16 14:28:46 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:28:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:28:47 freeipa.test.local krb5kdc[1885](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:28:47 freeipa.test.local krb5kdc[1885](info): closing down fd 11
Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:12 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:29 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:29 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:36 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034176, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha384-192(20), ses=aes256-cts-hmac-sha384-192(20)}, admin@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL
Jan 16 14:29:36 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:42 freeipa.test.local krb5kdc[1887](info): TGS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034176, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha1-96(18), ses=aes256-cts-hmac-sha384-192(20)}, admin@TEST.LOCAL for ldap/freeipa.test.local@TEST.LOCAL
Jan 16 14:29:42 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:46 freeipa.test.local krb5kdc[1885](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: host/freeipa.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:46 freeipa.test.local krb5kdc[1885](info): closing down fd 11
Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034186, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha384-192(20), ses=aes256-cts-hmac-sha384-192(20)}, host/freeipa.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL
Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): TGS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: ISSUE: authtime 1737034186, etypes {rep=aes256-cts-hmac-sha384-192(20), tkt=aes256-cts-hmac-sha1-96(18), ses=aes256-cts-hmac-sha384-192(20)}, host/freeipa.test.local@TEST.LOCAL for ldap/freeipa.test.local@TEST.LOCAL
Jan 16 14:29:46 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: CLIENT KEY EXPIRED: user01@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Password has expired
Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: NEEDED_PREAUTH: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:54 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): preauth (spake) verify failure: Preauthentication failed
Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: PREAUTH_FAILED: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Preauthentication failed
Jan 16 14:29:56 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ : handle_authdata (2)
Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: HANDLE_AUTHDATA: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, No such file or directory
Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): preauth (spake) verify failure: Preauthentication failed
Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: PREAUTH_FAILED: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Preauthentication failed
Jan 16 14:29:58 freeipa.test.local krb5kdc[1887](info): closing down fd 11
Jan 16 14:30:02 freeipa.test.local krb5kdc[1887](info): AS_REQ (8 etypes {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23), camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 192.168.1.106: NEEDED_PREAUTH: host/server1.test.local@TEST.LOCAL for krbtgt/TEST.LOCAL@TEST.LOCAL, Additional pre-authentication required
Jan 16 14:30:02 freeipa.test.local krb5kdc[1887](info): closing down fd 11

getprinc of user01

Authenticating as principal admin/admin@TEST.LOCAL with password.
Principal: user01@TEST.LOCAL
Expiration date: [never]
Last password change: Thu Jan 16 14:11:15 CET 2025
Password expiration date: Thu Jan 16 14:11:15 CET 2025
Maximum ticket life: 1 day 00:00:00
Maximum renewable life: 7 days 00:00:00
Last modified: Thu Jan 16 14:11:15 CET 2025 (root/admin@TEST.LOCAL)
Last successful authentication: [never]
Last failed authentication: Sun Nov 24 13:42:19 CET 2024
Failed password attempts: 0
Number of keys: 4
Key: vno 6, aes256-cts-hmac-sha384-192:special
Key: vno 6, aes128-cts-hmac-sha256-128:special
Key: vno 6, aes256-cts-hmac-sha1-96:special
Key: vno 6, aes128-cts-hmac-sha1-96:special
MKey: vno 1
Attributes: REQUIRES_PRE_AUTH DISALLOW_SVR
Policy: [none]

This is not an issue in FreeIPA that needs any fix in the code.

When migrating from data from non-IPA source, ID ranges cannot be set properly (because they don't exist in the original OpenLDAP source) and SIDs cannot be generated. It is an operational problem most likely due to missing SIDs. See https://freeipa.readthedocs.io/en/latest/designs/id-mapping.html for technical details.

Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ : handle_authdata (2)
Jan 16 14:29:57 freeipa.test.local krb5kdc[1887](info): AS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 192.168.1.104: HANDLE_AUTHDATA: user01@TEST.LOCAL for kadmin/changepw@TEST.LOCAL, No such file or directory

handle_authdata problems in krb5kdc.log tell that KDC was unable to issue a ticket with PAC record for the user user1@TEST.LOCAL. This typically happens because this user has no ipaNTSecurityIdentifier attribute in the record.

See also https://access.redhat.com/articles/7027037 for some explanation and solutions as well. You need RHEL subscription; using a free Red Hat developer subscription is enough. FreeIPA 4.12.1 should also have a tool ipa-idrange-fix that helps to automate ID range adjustment. Make sure to read its manual page.

Oh, sorry, ipa-idrange-fix is part of 4.12.2 release, so it is not in the version you have.

Thank you for the extended explanation!

So it is intended that the UI shows, that the password migration was successful?

These are kind of unrelated actions.

A password can be changed with migration procedure. However, obtaining an active Kerberos ticket requires proper user object setup with a SID assigned to the account.

Closing as this is an operational issue. If you are unable to fix it by following resources I gave, look at the freeipa-users@ mailing list archives for a number of similar investigations over past couple years. There were plenty cases there, demonstrating both how to solve the issues and what data needs to be provided. In case you still stuck, please use the mailing list.

Metadata Update from @abbra:
- Issue close_status updated to: worksforme
- Issue status updated to: Closed (was: Open)

Metadata