<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kerberos with FreeIPA: password expired in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105058#M46372</link>
    <description>&lt;P&gt;Can you try to create the keytab for the test user, and always do kinit from the keytab ("kinit -kt &amp;lt;keytab-file-name&amp;gt;" command). Ambari service checks are supposed to use the ambari-qa user and the wizard is supposed to create its keytab as well.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2016 19:10:01 GMT</pubDate>
    <dc:creator>pminovic</dc:creator>
    <dc:date>2016-11-18T19:10:01Z</dc:date>
    <item>
      <title>Kerberos with FreeIPA: password expired</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105057#M46371</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/98/emaxwell.html" rel="nofollow noopener noreferrer" target="_blank"&gt;emaxwell&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Following your HCC tutorial on kerberizing cluster with FreeIPA. Run into error where the password for the test principle always expire&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/content/kbentry/59645/ambari-24-kerberos-with-freeipa.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.hortonworks.com/content/kbentry/59645/ambari-24-kerberos-with-freeipa.html&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;Performing kinit using qi1-111516@FIELD.HORTONWORKS.COM
2016-11-15 21:33:42,394 - Execute['/usr/bin/kinit -c /var/lib/ambari-agent/tmp/kerberos_service_check_cc_79b5f4cfa04c21fdbd26a3e07b45366e -kt /etc/security/keytabs/kerberos.service_check.111516.keytab qi1-111516@FIELD.HORTONWORKS.COM'] {'user': 'ambari-qa'}
2016-11-15 21:33:42,460 - File['/var/lib/ambari-agent/tmp/kerberos_service_check_cc_79b5f4cfa04c21fdbd26a3e07b45366e'] {'action': ['delete']}

Command failed after 1 tries&lt;/PRE&gt;&lt;P&gt;I updated password global policy to make it never expire, and the user is using that policy&lt;/P&gt;&lt;PRE&gt;ipa pwpolicy-mod --maxlife=0 --minlife=0 global_policy
&lt;/PRE&gt;&lt;PRE&gt;[root@qwang-hdp ~]# ipa pwpolicy-show --user=qi1-111516
  Group: global_policy
  Max lifetime (days): 0
  Min lifetime (hours): 0
  History size: 0
  Character classes: 0
  Min length: 8
  Max failures: 6
  Failure reset interval: 60
  Lockout duration: 600
&lt;/PRE&gt;&lt;P&gt;But if I kinit with the user, it will ask me to reset the password anyway.&lt;/P&gt;&lt;P&gt;This seems to related to the second requirement of the wizard, but I can't make it work &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9480-screen-shot-2016-11-15-at-42530-pm.png" style="width: 1021px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23601iD23BAA72FF15860C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="9480-screen-shot-2016-11-15-at-42530-pm.png" alt="9480-screen-shot-2016-11-15-at-42530-pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  Greatly appreciate if you could provide some advice. &lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:01:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105057#M46371</guid>
      <dc:creator>qiwang</dc:creator>
      <dc:date>2019-08-19T12:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos with FreeIPA: password expired</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105058#M46372</link>
      <description>&lt;P&gt;Can you try to create the keytab for the test user, and always do kinit from the keytab ("kinit -kt &amp;lt;keytab-file-name&amp;gt;" command). Ambari service checks are supposed to use the ambari-qa user and the wizard is supposed to create its keytab as well.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 19:10:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105058#M46372</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-11-18T19:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos with FreeIPA: password expired</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105059#M46373</link>
      <description>&lt;P&gt;You need a really recent FreeIPA to support --maxlife=0 (https://git.fedorahosted.org/cgit/freeipa.git/commit/?id=d2cb9ed327ee4003598d5e45d80ab7918b89eeed). If you are on supported Redhat or CentOS then you probably you don't have it, unless you rolled your own. &lt;/P&gt;&lt;P&gt;You can find out by checking the krbPasswordExpiration attribute of the user. It shouldn't be there. In that case you can try to set it (http://www.therebel.eu/2015/08/setting-password-expiry-in-ipa/) or update your password policy to a lifetime of say 10 years or so (dont go beyond 2038)&lt;/P&gt;</description>
      <pubDate>Sun, 18 Dec 2016 14:48:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-with-FreeIPA-password-expired/m-p/105059#M46373</guid>
      <dc:creator>bdbruin</dc:creator>
      <dc:date>2016-12-18T14:48:03Z</dc:date>
    </item>
  </channel>
</rss>

