Unable to log in to IPA web ui - "Login failed due X509_anchors file is not communicating with pki".

Solution Verified - Updated -

Issue

-unable to log in to web UI nor execute any IPA command.

journalctl

gssproxy[910]: gssproxy[951]: (OID: { 1 2 840 113554 1 2 2 }) Unspecified GSS failure.  Minor code may provide more information, No credentials cache found
gssproxy[951]: (OID: { 1 2 840 113554 1 2 2 }) Unspecified GSS failure.  Minor code may provide more information, No credentials cache found
gssproxy[910]: gssproxy[951]: (OID: { 1 2 840 113554 1 2 2 }) Unspecified GSS failure.  Minor code may provide more information, Preauthentication failed
gssproxy[951]: (OID: { 1 2 840 113554 1 2 2 }) Unspecified GSS failure.  Minor code

[Tue Dec 17 14:15:02.340597 2024] [:error] [pid 46425] [remote 10.143.65.59:0]   File "/usr/lib/python2.7/site-packages/ipaserver/rpcserver.py", line 995, in kinit
[Tue Dec 17 14:15:02.340606 2024] [:error] [pid 46425] [remote 10.143.65.59:0]     pkinit_anchors=[paths.KDC_CERT, paths.KDC_CA_BUNDLE_PEM],
[Tue Dec 17 14:15:02.340614 2024] [:error] [pid 46425] [remote 10.143.65.59:0]   File "/usr/lib/python2.7/site-packages/ipalib/install/kinit.py", line 127, in kinit_armor
[Tue Dec 17 14:15:02.340673 2024] [:error] [pid 46425] [remote 10.143.65.59:0]     run(args, env=env, raiseonerr=True, capture_error=True)
[Tue Dec 17 14:15:02.340682 2024] [:error] [pid 46425] [remote 10.143.65.59:0]   File "/usr/lib/python2.7/site-packages/ipapython/ipautil.py", line 563, in run
[Tue Dec 17 14:15:02.340932 2024] [:error] [pid 46425] [remote 10.143.65.59:0]     raise CalledProcessError(p.returncode, arg_string, str(output))
[Tue Dec 17 14:15:02.340984 2024] [:error] [pid 46425] [remote 10.143.65.59:0] CalledProcessError: Command '/usr/bin/kinit -n -c /var/run/ipa/ccaches/armor_46425 -X X509_anchors=FILE:/var/kerberos/krb5kdc/kdc.crt -X X509_anchors=FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pe
m' returned non-zero exit status 1

Environment

  • Red Hat EnterPrise Linux 8
  • Red Hat EnterPrise Linux 9
  • IPA

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content