IPA command based on admin is failing with error "TGT has been revoked"
Issue
- IPA command based on
admin
is failing with error.
Dec 22 07:11:34 ipa01.example.test krb5kdc[1988072](info): TGS_REQ (4 etypes {aes256-cts-hmac-sha384-192(20), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha256-128(19), aes128-cts-hmac- sha1-96(17)}) 192.168.122.7: S4U2PROXY_NO_HEADER_PAC: authtime 1703225487, HTTP/ipa01.example.test@EXAMPLE.TEST for ldap/ipa01.example.test@EXAMPLE.TEST, TGT has been revoked
Dec 22 07:11:34 ipa01.example.test krb5kdc[1988072](info): ... CONSTRAINED-DELEGATION s4u-client=admin@EXAMPLE.TEST
Dec 22 07:11:34 ipa01.example.test krb5kdc[1988072](info): closing down fd 11
Environment
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- IPA 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.