Hi,
On Fri, Mar 17, 2023 at 2:43 PM Jeremy Tourville via FreeIPA-users <
freeipa-users(a)lists.fedorahosted.org> wrote:
OK, but how do i get them to match again? Running ipa-getkeytab
doesn't
fix it. klist just keeps incrementing and kvno stays the same.
The command ipa-getkeytab creates a new key, unless it is called with
--retrieve (in which case it downloads the existing keys to a keytab file).
In your case, a new key is generated for host/gsil-ipa01.idm.gsil.smil on
server gsil-ipa02.idm.x.x. It means that the new key is updated in the LDAP
entry on gsil-ipa02.idm.x.x. If the replication is broken, the LDAP entry
on gsil-ipa01.idm.gsil.smil still contains the old key, and any kinit
against this server will fail if using the new key.
You need to fix replication first, you may give a try at the command "ipa
topologysegment-reinitialize".
flo
_______________________________________________
FreeIPA-users mailing list -- freeipa-users(a)lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave(a)lists.fedorahosted.org
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedoraho...
Do not reply to spam, report it:
https://pagure.io/fedora-infrastructure/new_issue