Document URL: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.13/html/installing_satellite_server_in_a_connected_network_environment/configuring_external_authentication_satellite#Kerberos_Configuration_in_Web_Browsers_satellite Section Number and Name: 5.3.4. Kerberos Configuration in Web Browsers Describe the issue: There is a note about GPO-PAM mapping. I think this shouldn't be a note. I think this should be in the section 5.3.3. Configuring Direct AD Integration with GSS-Proxy. Because this setting is required (I wasn't able to get AD auth working without it) and it needs to be done on the Satellite, not on the client (running the web browser). Related: https://bugzilla.redhat.com/show_bug.cgi?id=2117523 but it was closed because there is already this KBA: https://access.redhat.com/solutions/6982443 ... however, 1) KBA isn't a proper documentation and 2) this is actually in docs but in a wrong place and incorrectly marked.
Missing that causes this error on login in WebUI or with ticket: PAM authentication failed for user foobar: User not known to the underlying authentication module, referer: <FQDN>
Hello! Currently in progress of making the PR with requested changes. Link to draft PR here: https://github.com/theforeman/foreman-documentation/pull/2307