UPN of user entry and PAC do not match `NSS return code [-1], request return code [1432158309][PAC check failed]`
Issue
- UPN of user entry and PAC do not match.
- NSS return code
[-1], request return code [1432158309][PAC check failed]
. - Unable to login with AD user.
- UPN check cannot be disabled explicitly but requires
krb5_validate = false
as a work-around.
Environment
- Red Hat Enterprise Linux (RHEL)
sssd-2.7.3-4.el8_7.1.x86_64
sssd-2.7.3-4.el9_1.1.x86_64
- Identity Management (IdM/IPA)
- IPA Client
- Active Directory (AD)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.