AD user cannot login RHEL 9 client - [sdap_get_initgr_user] :Cannot canonicalize username
Issue
AD user aduser cannot login RHEL host ldapclient. This error is found in /var/log/secure:
2023-11-15T11:05:51.058090+00:00 ldapclient unix_chkpwd[423992]: password check failed for user (aduser)
2023-11-15T11:05:51.059383+00:00 ldapclient sshd[423971]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.94.70.71 user=aduser
2023-11-15T11:05:51.317907+00:00 ldapclient sshd[423971]: pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.94.70.71 user=aduser
2023-11-15T11:05:51.318092+00:00 ldapclient sshd[423971]: pam_sss(sshd:auth): received for user aduser: 10 (User not known to the underlying authentication module)
Environment
- Red Hat Enterprise Linux 9.3
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.