This program will set up IPA client. Version 4.10.2 Discovery was successful! Do you want to configure chrony with NTP server or pool address? [no]: n Client hostname: inf-my-tt.DOMAIN Realm: DOMAIN DNS Domain: DOMAIN IPA Server: dc02.DOMAIN BaseDN: dc=domain,dc=domain,dc=domain Continue to configure the system with these values? [no]: y Synchronizing time Configuration of chrony was changed by installer. Attempting to sync time with chronyc. Time synchronization was successful. User authorized to enroll computers: user Password for user@DOMAIN: [5549] 1702285638.745485: ccselect module realm chose cache FILE:/tmp/krbccej_v5664/ccache with client principal user@DOMAIN for server principal ldap/dc02.DOMAIN@DOMAIN [5549] 1702285638.745486: Getting credentials user@DOMAIN -> ldap/dc02.DOMAIN@DOMAIN using ccache FILE:/tmp/krbccej_v5664/ccache [5549] 1702285638.745487: Retrieving user@DOMAIN -> krb5_ccache_conf_data/start_realm@X-CACHECONF: from FILE:/tmp/krbccej_v5664/ccache with result: -1765328243/Matching credential not found (filename: /tmp/krbccej_v5664/ccache) [5549] 1702285638.745488: Retrieving user@DOMAIN -> ldap/dc02.DOMAIN@DOMAIN from FILE:/tmp/krbccej_v5664/ccache with result: -1765328243/Matching credential not found (filename: /tmp/krbccej_v5664/ccache) [5549] 1702285638.745489: Retrieving user@DOMAIN -> krbtgt/DOMAIN@DOMAIN from FILE:/tmp/krbccej_v5664/ccache with result: 0/Success [5549] 1702285638.745490: Starting with TGT for client realm: user@DOMAIN -> krbtgt/DOMAIN@DOMAIN [5549] 1702285638.745491: Requesting tickets for ldap/dc02.DOMAIN@DOMAIN, referrals on [5549] 1702285638.745492: Generated subkey for TGS request: aes256-cts/E95A [5549] 1702285638.745493: etypes requested in TGS request: aes256-sha2, aes128-sha2, aes256-cts, aes128-cts [5549] 1702285638.745495: Encoding request body and padata into FAST request [5549] 1702285638.745496: Sending request (1454 bytes) to DOMAIN [5549] 1702285638.745497: Resolving hostname dc02.DOMAIN [5549] 1702285638.745498: Initiating TCP connection to stream dc02_ip:88 [5549] 1702285638.745499: Sending TCP request to stream dc02_ip:88 [5549] 1702285638.745500: Received answer (1386 bytes) from stream dc02_ip:88 [5549] 1702285638.745501: Terminating TCP connection to stream dc02_ip:88 [5549] 1702285638.745502: Response was from primary KDC [5549] 1702285638.745503: Decoding FAST response [5549] 1702285638.745504: FAST reply key: aes256-cts/C082 [5549] 1702285638.745505: TGS reply is for user@DOMAIN -> ldap/dc02.DOMAIN@DOMAIN with session key aes256-cts/9028 [5549] 1702285638.745506: TGS request result: 0/Success [5549] 1702285638.745507: Received creds for desired service ldap/dc02.DOMAIN@DOMAIN [5549] 1702285638.745508: Storing user@DOMAIN -> ldap/dc02.DOMAIN@DOMAIN in FILE:/tmp/krbccej_v5664/ccache [5549] 1702285638.745509: Creating authenticator for user@DOMAIN -> ldap/dc02.DOMAIN@DOMAIN, seqnum 565269392, subkey aes256-cts/92AA, session key aes256-cts/9028 [5549] 1702285638.745511: Read AP-REP, time 1702285638.745510, subkey aes256-cts/601A, seqnum 1011807753 Successfully retrieved CA cert Subject: CN=Certificate Authority,O=DOMAIN Issuer: CN=Certificate Authority,O=DOMAIN Valid From: 2018-12-14 10:48:38 Valid Until: 2038-12-14 10:48:38 Enrolled in IPA realm DOMAIN [5549] 1702285639.620943: Getting initial credentials for host/inf-my-tt.DOMAIN@DOMAIN [5549] 1702285639.620944: Found entries for host/inf-my-tt.DOMAIN@DOMAIN in keytab: aes256-sha2, aes128-sha2 [5549] 1702285639.620946: Sending unauthenticated request [5549] 1702285639.620947: Sending request (193 bytes) to DOMAIN [5549] 1702285639.620948: Resolving hostname dc02.DOMAIN [5549] 1702285639.620949: Initiating TCP connection to stream dc02_ip:88 [5549] 1702285639.620950: Sending TCP request to stream dc02_ip:88 [5549] 1702285639.620951: Received answer (343 bytes) from stream dc02_ip:88 [5549] 1702285639.620952: Terminating TCP connection to stream dc02_ip:88 [5549] 1702285639.620953: Response was from primary KDC [5549] 1702285639.620954: Received error from KDC: -1765328359/Additional pre-authentication required [5549] 1702285639.620957: Preauthenticating using KDC method data [5549] 1702285639.620958: Processing preauth types: PA-PK-AS-REQ (16), PA-PK-AS-REP_OLD (15), PA-PK-AS-REQ_OLD (14), PA-FX-FAST (136), PA-ETYPE-INFO2 (19), PA-PKINIT-KX (147), PA-ENC-TIMESTAMP (2), PA-FX-COOKIE (133) [5549] 1702285639.620959: Selected etype info: etype aes256-cts, salt "DOMAINhostinf-my-tt.DOMAIN", params "" [5549] 1702285639.620960: Received cookie: MIT [5549] 1702285639.620961: PKINIT client has no configured identity; giving up [5549] 1702285639.620962: Preauth module pkinit (147) (info) returned: 0/Success [5549] 1702285639.620963: PKINIT client has no configured identity; giving up [5549] 1702285639.620964: Preauth module pkinit (16) (real) returned: 22/Invalid argument [5549] 1702285639.620965: Retrieving host/inf-my-tt.DOMAIN@DOMAIN from FILE:/etc/krb5.keytab (vno 0, enctype aes256-cts) with result: -1765328203/No key table entry found for host/inf-my-tt.DOMAIN@DOMAIN [5549] 1702285639.620966: Preauth module encrypted_timestamp (2) (real) returned: -1765328203/No key table entry found for host/inf-my-tt.DOMAIN@DOMAIN [5549] 1702285639.620967: Getting initial credentials for host/inf-my-tt.DOMAIN@DOMAIN [5549] 1702285639.620968: Found entries for host/inf-my-tt.DOMAIN@DOMAIN in keytab: aes256-sha2, aes128-sha2 [5549] 1702285639.620970: Sending unauthenticated request [5549] 1702285639.620971: Sending request (193 bytes) to DOMAIN [5549] 1702285639.620972: Resolving hostname dc02.DOMAIN [5549] 1702285639.620973: Initiating TCP connection to stream dc02_ip:88 [5549] 1702285639.620974: Sending TCP request to stream dc02_ip:88 [5549] 1702285639.620975: Received answer (343 bytes) from stream dc02_ip:88 [5549] 1702285639.620976: Terminating TCP connection to stream dc02_ip:88 [5549] 1702285639.620977: Response was from primary KDC [5549] 1702285639.620978: Received error from KDC: -1765328359/Additional pre-authentication required [5549] 1702285639.620981: Preauthenticating using KDC method data [5549] 1702285639.620982: Processing preauth types: PA-PK-AS-REQ (16), PA-PK-AS-REP_OLD (15), PA-PK-AS-REQ_OLD (14), PA-FX-FAST (136), PA-ETYPE-INFO2 (19), PA-PKINIT-KX (147), PA-ENC-TIMESTAMP (2), PA-FX-COOKIE (133) [5549] 1702285639.620983: Selected etype info: etype aes256-cts, salt "DOMAINhostinf-my-tt.DOMAIN", params "" [5549] 1702285639.620984: Received cookie: MIT [5549] 1702285639.620985: PKINIT client has no configured identity; giving up [5549] 1702285639.620986: Preauth module pkinit (147) (info) returned: 0/Success [5549] 1702285639.620987: PKINIT client has no configured identity; giving up [5549] 1702285639.620988: Preauth module pkinit (16) (real) returned: 22/Invalid argument [5549] 1702285639.620989: Retrieving host/inf-my-tt.DOMAIN@DOMAIN from FILE:/etc/krb5.keytab (vno 0, enctype aes256-cts) with result: -1765328203/No key table entry found for host/inf-my-tt.DOMAIN@DOMAIN [5549] 1702285639.620990: Preauth module encrypted_timestamp (2) (real) returned: -1765328203/No key table entry found for host/inf-my-tt.DOMAIN@DOMAIN Please make sure the following ports are opened in the firewall settings: TCP: 80, 88, 389 UDP: 88 (at least one of TCP/UDP ports 88 has to be open) Also note that following ports are necessary for ipa-client working properly after enrollment: TCP: 464 UDP: 464, 123 (if NTP enabled) Failed to obtain host TGT: Major (458752): No credentials were supplied, or the credentials were unavailable or inaccessible, Minor (2529639122): Pre-authentication failed: Invalid argument Installation failed. Rolling back changes. Disabling client Kerberos and LDAP configurations Restoring client configuration files nscd daemon is not installed, skip configuration nslcd daemon is not installed, skip configuration Client uninstall complete.