Hi,

On Fri, Mar 17, 2023 at 2:43 PM Jeremy Tourville via FreeIPA-users <freeipa-users@lists.fedorahosted.org> wrote:
OK, but how do i get them to match again?  Running  ipa-getkeytab doesn't fix it.  klist just keeps incrementing and kvno stays the same.
The command ipa-getkeytab creates a new key, unless it is called with --retrieve (in which case it downloads the existing keys to a keytab file).

In your case, a new key is generated for host/gsil-ipa01.idm.gsil.smil on server gsil-ipa02.idm.x.x. It means that the new key is updated in the LDAP entry on gsil-ipa02.idm.x.x. If the replication is broken, the LDAP entry on gsil-ipa01.idm.gsil.smil still contains the old key, and any kinit against this server will fail if using the new key.

You need to fix replication first, you may give a try at the command "ipa topologysegment-reinitialize".

flo
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue