kinit for an IPA user fails if 2FA(Password + OTP) or passwordless(IDP/passkey) is enabled for that user
Issue
- If 2FA(Password + OTP) is enabled for an IPA user
kinit
fails with:
[root@rhel7-ipa ~]# kinit testuser
kinit: Pre-authentication failed: Invalid argument while getting initial credentials
kinit
fails for IPA user if 2FA(Password + OTP) is enabled for that user:
[root@rhel7-ipa ~]# kinit testuser
kinit: Generic preauthentication failure while getting initial credential
Environment
- Red Hat Enterprise Linux 7.1 or later
- IPA/IdM
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.