Red Hat Identity Management Issues
Hello,
I've been trying to configure the Red Hat Identity Management Server 2.2.0 for Red Hat 6.3 and I've been running into some weird issues with the web GUI.
We've been trying to access the web GUI from Firefox and IE (IE on the Windows side of course) and we are getting intermittent results on the IE side from multiple workstations/servers.
The workstations are running IE7 on Windows XP SP3 and the servers are running IE7 on Windows Server 2003 SP2.
At one moment we are able to log on to the web gui (https://server_name/ipa/ui , https://ip_address/ipa/ui , server_name) and then 30 minutes later we are unable to log in.
We've tried running IE8 on Windows Server 2008 also with the same results.
Under the /user/share/ipa/ipa.conf I changed the krbMethodK5Passwd option to off so it asks for a username and password but other then that I've changed nothing concerning the web gui.
Any thoughts on this?
Responses
Hello,
By default, the IPA Web UI uses Kerberos Negotiate to perform a single sign-on login. This is handled automatically in Firefox if it is properly configured and you have a TGT.
There are some cases where this is not possible, such as an unsupported browser or operating system (Windows for example).
By configuring username/password authentication for the UI allows users to log in even if there are problems with the Kerberos service.
Open the ipa.conf file used by the Apache web service.
# vim /etc/httpd/conf.d/ipa.conf
In the <Location "/ipa"> location definition, change the KrbMethodK5Passwd attribute from off to on.
KrbMethodK5Passwd on
Restart the httpd service:
# service httpd restart
The web server will first attempt to use Kerberos Negotiate to log the user in. If that fails then the user will be presented with a login prompt.
Also ensure that IPA CA cert in also installed in the browser.
Hope this helps.
Best Regards,
Nirupama
Hello,
You have mentioned that issue is randomly/inconsistently occurring. Does clearing cache or cookies from IE fixes it ?
Is IPA server reachable/pingable when issue occur ?
Could you please ensure this network issue while accessing the IPA GUI ?
Nirupama
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
