IPA Client AD Trust logins fail with Cannot find KDC for realm "AD.REALM" while getting initial credentials
Issue
- Unable to login with AD Trust users on IPA clients
- Succesfully able to resolve SSSD users with
id
command but login fails during PAM authentication. SSSDkrb5_child
logs errors out with
Cannot find KDC for realm "AD.REALM" while getting initial credentials
- The same error can be reproduced with
# kinit aduser@AD.REALM
Environment
- Red Hat Enterprise Linux
- Red Hat Identity Management
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.