This bug report is similar to #1716981. I am getting connection refused error, whenever I do kinit/ klist/ kdestroy. The same krb5.conf file used in another machine works pretty well. Logs from strace ''' அ ~ KRB5_TRACE=/dev/stderr strace -f kinit execve("/usr/bin/kinit", ["kinit"], 0x7ffcc9b91078 /* 53 vars */) = 0 brk(NULL) = 0x55d10986c000 arch_prctl(0x3001 /* ARCH_??? */, 0x7ffec5245c30) = -1 EINVAL (Invalid argument) access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=73495, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 73495, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f018cbd8000 close(3) = 0 openat(AT_FDCWD, "/lib64/libkadm5srv_mit.so.12", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=124344, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018cbd6000 mmap(NULL, 123496, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018cbb7000 mmap(0x7f018cbbe000, 69632, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x7f018cbbe000 mmap(0x7f018cbcf000, 16384, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x18000) = 0x7f018cbcf000 mmap(0x7f018cbd3000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1b000) = 0x7f018cbd3000 close(3) = 0 openat(AT_FDCWD, "/lib64/libkdb5.so.10", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=87504, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 86312, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018cba1000 mmap(0x7f018cba6000, 49152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x5000) = 0x7f018cba6000 mmap(0x7f018cbb2000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) = 0x7f018cbb2000 mmap(0x7f018cbb5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x13000) = 0x7f018cbb5000 close(3) = 0 openat(AT_FDCWD, "/lib64/libkrb5.so.3", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=903184, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 885520, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018cac8000 mmap(0x7f018caea000, 446464, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x22000) = 0x7f018caea000 mmap(0x7f018cb57000, 237568, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8f000) = 0x7f018cb57000 mmap(0x7f018cb91000, 61440, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc9000) = 0x7f018cb91000 mmap(0x7f018cba0000, 784, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018cba0000 close(3) = 0 openat(AT_FDCWD, "/lib64/libcom_err.so.2", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=24584, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 24640, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018cac1000 mmap(0x7f018cac3000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f018cac3000 mmap(0x7f018cac5000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f018cac5000 mmap(0x7f018cac6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f018cac6000 close(3) = 0 openat(AT_FDCWD, "/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 }\2\0\0\0\0\0"..., 832) = 832 pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=2234072, ...}, AT_EMPTY_PATH) = 0 pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784 mmap(NULL, 1957168, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c8e3000 mmap(0x7f018c909000, 1429504, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x26000) = 0x7f018c909000 mmap(0x7f018ca66000, 315392, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x183000) = 0x7f018ca66000 mmap(0x7f018cab3000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1d0000) = 0x7f018cab3000 mmap(0x7f018cab9000, 32048, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018cab9000 close(3) = 0 openat(AT_FDCWD, "/lib64/libgssrpc.so.4", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=139200, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 132800, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c8c2000 mmap(0x7f018c8c8000, 77824, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x6000) = 0x7f018c8c8000 mmap(0x7f018c8db000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x19000) = 0x7f018c8db000 mmap(0x7f018c8e1000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1f000) = 0x7f018c8e1000 close(3) = 0 openat(AT_FDCWD, "/lib64/libgssapi_krb5.so.2", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=359488, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018c8c0000 mmap(NULL, 351032, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c86a000 mmap(0x7f018c876000, 249856, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f018c876000 mmap(0x7f018c8b3000, 40960, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x49000) = 0x7f018c8b3000 mmap(0x7f018c8bd000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x53000) = 0x7f018c8bd000 close(3) = 0 openat(AT_FDCWD, "/lib64/libk5crypto.so.3", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=95496, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 94256, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c852000 mmap(0x7f018c857000, 53248, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x5000) = 0x7f018c857000 mmap(0x7f018c864000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12000) = 0x7f018c864000 mmap(0x7f018c867000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x7f018c867000 mmap(0x7f018c869000, 48, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c869000 close(3) = 0 openat(AT_FDCWD, "/lib64/libkrb5support.so.0", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=67112, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 62096, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c842000 mmap(0x7f018c846000, 32768, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f018c846000 mmap(0x7f018c84e000, 8192, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f018c84e000 mmap(0x7f018c850000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xe000) = 0x7f018c850000 close(3) = 0 openat(AT_FDCWD, "/lib64/libkeyutils.so.1", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=24704, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 24584, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c83b000 mmap(0x7f018c83d000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f018c83d000 mmap(0x7f018c83f000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f018c83f000 mmap(0x7f018c840000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f018c840000 mmap(0x7f018c841000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c841000 close(3) = 0 openat(AT_FDCWD, "/lib64/libcrypto.so.3", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=4443184, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 4350968, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c400000 mmap(0x7f018c4ad000, 2506752, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xad000) = 0x7f018c4ad000 mmap(0x7f018c711000, 757760, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x311000) = 0x7f018c711000 mmap(0x7f018c7ca000, 368640, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3ca000) = 0x7f018c7ca000 mmap(0x7f018c824000, 9208, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c824000 close(3) = 0 openat(AT_FDCWD, "/lib64/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=67576, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 72264, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c829000 mmap(0x7f018c82c000, 36864, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f018c82c000 mmap(0x7f018c835000, 8192, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f018c835000 mmap(0x7f018c837000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xe000) = 0x7f018c837000 mmap(0x7f018c839000, 6728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c839000 close(3) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018c827000 openat(AT_FDCWD, "/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=180952, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 181880, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c3d3000 mmap(0x7f018c3da000, 114688, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x7f018c3da000 mmap(0x7f018c3f6000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x23000) = 0x7f018c3f6000 mmap(0x7f018c3fc000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x29000) = 0x7f018c3fc000 mmap(0x7f018c3fe000, 5752, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c3fe000 close(3) = 0 openat(AT_FDCWD, "/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=107416, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 102408, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c3b9000 mmap(0x7f018c3bc000, 61440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f018c3bc000 mmap(0x7f018c3cb000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12000) = 0x7f018c3cb000 mmap(0x7f018c3d1000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x18000) = 0x7f018c3d1000 mmap(0x7f018c3d2000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f018c3d2000 close(3) = 0 openat(AT_FDCWD, "/lib64/libpcre2-8.so.0", O_RDONLY|O_CLOEXEC) = 3 read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(3, "", {st_mode=S_IFREG|0755, st_size=631104, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 627248, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f018c31f000 mmap(0x7f018c322000, 446464, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f018c322000 mmap(0x7f018c38f000, 163840, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x70000) = 0x7f018c38f000 mmap(0x7f018c3b7000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x97000) = 0x7f018c3b7000 close(3) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018c31d000 mmap(NULL, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018c31a000 arch_prctl(ARCH_SET_FS, 0x7f018c31a840) = 0 set_tid_address(0x7f018c31ab10) = 9261 set_robust_list(0x7f018c31ab20, 24) = 0 rseq(0x7f018c31b160, 0x20, 0, 0x53053053) = 0 mprotect(0x7f018cab3000, 16384, PROT_READ) = 0 mprotect(0x7f018c3b7000, 4096, PROT_READ) = 0 mprotect(0x7f018c3d1000, 4096, PROT_READ) = 0 mprotect(0x7f018c3fc000, 4096, PROT_READ) = 0 mprotect(0x7f018c837000, 4096, PROT_READ) = 0 mprotect(0x7f018c7ca000, 356352, PROT_READ) = 0 mprotect(0x7f018c840000, 4096, PROT_READ) = 0 mprotect(0x7f018c850000, 4096, PROT_READ) = 0 mprotect(0x7f018c867000, 8192, PROT_READ) = 0 mprotect(0x7f018cac6000, 4096, PROT_READ) = 0 mprotect(0x7f018cb91000, 57344, PROT_READ) = 0 mprotect(0x7f018c8bd000, 8192, PROT_READ) = 0 mprotect(0x7f018c8e1000, 4096, PROT_READ) = 0 mprotect(0x7f018cbb5000, 4096, PROT_READ) = 0 mprotect(0x7f018cbd3000, 8192, PROT_READ) = 0 mprotect(0x55d109388000, 4096, PROT_READ) = 0 mprotect(0x7f018cc1b000, 8192, PROT_READ) = 0 prlimit64(0, RLIMIT_STACK, NULL, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0 munmap(0x7f018cbd8000, 73495) = 0 statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0 statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0 getrandom("\x74\x46\xec\x07\x8b\xcb\x0e\x42", 8, GRND_NONBLOCK) = 8 brk(NULL) = 0x55d10986c000 brk(0x55d10988d000) = 0x55d10988d000 access("/etc/selinux/config", F_OK) = 0 openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=224366320, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 224366320, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f017ec00000 close(3) = 0 ioctl(0, TCGETS, {c_iflag=ICRNL|IXON|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 ioctl(1, TCGETS, {c_iflag=ICRNL|IXON|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 ioctl(2, TCGETS, {c_iflag=ICRNL|IXON|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 futex(0x7f018c851288, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7f018c8510d0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7f018cb9fc70, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7f018cb9ffe0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 newfstatat(AT_FDCWD, "/etc/krb5.conf", {st_mode=S_IFREG|0644, st_size=1163, ...}, 0) = 0 openat(AT_FDCWD, "/etc/krb5.conf", O_RDONLY) = 3 fcntl(3, F_SETFD, FD_CLOEXEC) = 0 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=1163, ...}, AT_EMPTY_PATH) = 0 read(3, "includedir /etc/krb5.conf.d/\n\n# "..., 4096) = 1163 openat(AT_FDCWD, "/etc/krb5.conf.d/", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 4 newfstatat(4, "", {st_mode=S_IFDIR|0755, st_size=106, ...}, AT_EMPTY_PATH) = 0 getdents64(4, 0x55d10986f2b0 /* 5 entries */, 32768) = 168 getdents64(4, 0x55d10986f2b0 /* 0 entries */, 32768) = 0 close(4) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//crypto-policies", O_RDONLY) = 4 newfstatat(4, "", {st_mode=S_IFREG|0644, st_size=179, ...}, AT_EMPTY_PATH) = 0 read(4, "[libdefaults]\npermitted_enctypes"..., 4096) = 179 read(4, "", 4096) = 0 close(4) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//enable_sssd_conf_dir", O_RDONLY) = 4 newfstatat(4, "", {st_mode=S_IFREG|0644, st_size=252, ...}, AT_EMPTY_PATH) = 0 read(4, "# This file should normally be i"..., 4096) = 252 openat(AT_FDCWD, "/var/lib/sss/pubconf/krb5.include.d/", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 5 newfstatat(5, "", {st_mode=S_IFDIR|0755, st_size=0, ...}, AT_EMPTY_PATH) = 0 getdents64(5, 0x55d109877400 /* 2 entries */, 32768) = 48 getdents64(5, 0x55d109877400 /* 0 entries */, 32768) = 0 close(5) = 0 read(4, "", 4096) = 0 close(4) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//kcm_default_ccache", O_RDONLY) = 4 newfstatat(4, "", {st_mode=S_IFREG|0644, st_size=474, ...}, AT_EMPTY_PATH) = 0 read(4, "# This file should normally be i"..., 4096) = 474 read(4, "", 4096) = 0 close(4) = 0 read(3, "", 4096) = 0 close(3) = 0 futex(0x7f018c851000, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7f018c3ff500, FUTEX_WAKE_PRIVATE, 2147483647) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDONLY|O_CLOEXEC) = 3 read(3, "", 4095) = 0 close(3) = 0 openat(AT_FDCWD, "/etc/selinux/config", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=1187, ...}, AT_EMPTY_PATH) = 0 read(3, "\n# This file controls the state "..., 4096) = 1187 read(3, "", 4096) = 0 close(3) = 0 futex(0x7f018c3fd1a0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=424715, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs_dist", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=704, ...}, AT_EMPTY_PATH) = 0 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=704, ...}, AT_EMPTY_PATH) = 0 read(3, "/run /var/run\n/run/lock /var/loc"..., 4096) = 704 read(3, "", 4096) = 0 close(3) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 read(3, "", 4096) = 0 close(3) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=424715, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.bin", {st_mode=S_IFREG|0644, st_size=597805, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.bin", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=597805, ...}, AT_EMPTY_PATH) = 0 read(3, "\212\377|\371\5\0\0\0\20\0\0\00010.42 2022-12-11\6\0\0\0"..., 4096) = 4096 lseek(3, 0, SEEK_SET) = 0 mmap(NULL, 597805, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f018c288000 brk(0x55d1098c4000) = 0x55d1098c4000 brk(0x55d1098e5000) = 0x55d1098e5000 mmap(NULL, 491520, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f018c210000 mremap(0x7f018c210000, 491520, 983040, MREMAP_MAYMOVE) = 0x7f017eb10000 close(3) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs", {st_mode=S_IFREG|0644, st_size=15537, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", {st_mode=S_IFREG|0644, st_size=21309, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=21309, ...}, AT_EMPTY_PATH) = 0 read(3, "\212\377|\371\5\0\0\0\20\0\0\00010.42 2022-12-11\6\0\0\0"..., 4096) = 4096 lseek(3, 0, SEEK_SET) = 0 mmap(NULL, 21309, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f018cbe4000 close(3) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local", {st_mode=S_IFREG|0644, st_size=0, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local.bin", 0x7ffec5243390, 0) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local", O_RDONLY|O_CLOEXEC) = 3 newfstatat(3, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 read(3, "", 4096) = 0 lseek(3, 0, SEEK_SET) = 0 read(3, "", 4096) = 0 close(3) = 0 mmap(NULL, 827392, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f017ea46000 munmap(0x7f017eb10000, 983040) = 0 brk(0x55d109906000) = 0x55d109906000 brk(0x55d10992a000) = 0x55d10992a000 brk(0x55d10994d000) = 0x55d10994d000 brk(0x55d109971000) = 0x55d109971000 brk(0x55d109995000) = 0x55d109995000 brk(0x55d1099b8000) = 0x55d1099b8000 brk(0x55d1099dc000) = 0x55d1099dc000 brk(0x55d109a00000) = 0x55d109a00000 brk(0x55d109a23000) = 0x55d109a23000 brk(0x55d109a47000) = 0x55d109a47000 brk(0x55d109a6b000) = 0x55d109a6b000 brk(0x55d109a8e000) = 0x55d109a8e000 brk(0x55d109ab2000) = 0x55d109ab2000 brk(0x55d109ad6000) = 0x55d109ad6000 brk(0x55d109af9000) = 0x55d109af9000 brk(0x55d109b1d000) = 0x55d109b1d000 brk(0x55d109b41000) = 0x55d109b41000 brk(0x55d109b64000) = 0x55d109b64000 brk(0x55d109b88000) = 0x55d109b88000 brk(0x55d109bac000) = 0x55d109bac000 brk(0x55d109bcf000) = 0x55d109bcf000 brk(0x55d109bf3000) = 0x55d109bf3000 brk(0x55d109c17000) = 0x55d109c17000 brk(0x55d109c3a000) = 0x55d109c3a000 brk(0x55d109c5e000) = 0x55d109c5e000 brk(0x55d109c82000) = 0x55d109c82000 brk(0x55d109ca5000) = 0x55d109ca5000 brk(0x55d109cc9000) = 0x55d109cc9000 brk(0x55d109ced000) = 0x55d109ced000 brk(0x55d109d10000) = 0x55d109d10000 brk(0x55d109d34000) = 0x55d109d34000 brk(0x55d109d58000) = 0x55d109d58000 brk(0x55d109d7c000) = 0x55d109d7c000 brk(0x55d109d9f000) = 0x55d109d9f000 brk(0x55d109dc3000) = 0x55d109dc3000 brk(0x55d109de7000) = 0x55d109de7000 brk(0x55d109e0a000) = 0x55d109e0a000 brk(0x55d109e2e000) = 0x55d109e2e000 brk(0x55d109e52000) = 0x55d109e52000 brk(0x55d109e75000) = 0x55d109e75000 brk(0x55d109e99000) = 0x55d109e99000 brk(0x55d109ebd000) = 0x55d109ebd000 brk(0x55d109ee0000) = 0x55d109ee0000 brk(0x55d109f04000) = 0x55d109f04000 brk(0x55d109f28000) = 0x55d109f28000 brk(0x55d109f4b000) = 0x55d109f4b000 brk(0x55d109f6f000) = 0x55d109f6f000 brk(0x55d109f93000) = 0x55d109f93000 brk(0x55d109fb6000) = 0x55d109fb6000 brk(0x55d109fda000) = 0x55d109fda000 brk(0x55d109ffe000) = 0x55d109ffe000 brk(0x55d10a021000) = 0x55d10a021000 brk(0x55d10a045000) = 0x55d10a045000 brk(0x55d10a069000) = 0x55d10a069000 brk(0x55d10a08d000) = 0x55d10a08d000 brk(0x55d10a0b0000) = 0x55d10a0b0000 brk(0x55d10a0d4000) = 0x55d10a0d4000 brk(0x55d10a0f8000) = 0x55d10a0f8000 brk(0x55d10a11b000) = 0x55d10a11b000 brk(0x55d10a13f000) = 0x55d10a13f000 access("/var/run/setrans/.setrans-unix", F_OK) = -1 ENOENT (No such file or directory) futex(0x7f018c3ff648, FUTEX_WAKE_PRIVATE, 2147483647) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/current", O_RDONLY|O_CLOEXEC) = 3 read(3, "unconfined_u:unconfined_r:unconf"..., 4095) = 54 close(3) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 3 write(3, "unconfined_u:object_r:device_t:s"..., 34) = 34 close(3) = 0 openat(AT_FDCWD, "/dev/stderr", O_WRONLY|O_CREAT|O_APPEND, 0600) = 3 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 4 write(4, NULL, 0) = 0 close(4) = 0 munmap(0x7f017ea46000, 827392) = 0 munmap(0x7f018cbe4000, 21309) = 0 munmap(0x7f018c288000, 597805) = 0 socket(AF_UNIX, SOCK_STREAM, 0) = 4 connect(4, {sa_family=AF_UNIX, sun_path="/var/run/.heim_org.h5l.kcm-socket"}, 110) = -1 ECONNREFUSED (Connection refused) close(4) = 0 openat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 4 newfstatat(4, "", {st_mode=S_IFREG|0644, st_size=2998, ...}, AT_EMPTY_PATH) = 0 read(4, "# Locale name alias data base.\n#"..., 4096) = 2998 read(4, "", 4096) = 0 close(4) = 0 openat(AT_FDCWD, "/usr/share/locale/en_IN.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) write(2, "kinit: Connection refused ", 26kinit: Connection refused ) = 26 write(2, "while getting default ccache", 28while getting default ccache) = 28 write(2, "\n", 1 ) = 1 close(3) = 0 exit_group(1) = ? +++ exited with 1 +++ ''' Reproducible: Always Steps to Reproduce: klist, kdestroy, or kinit fails with connection refused
Can you try to reproduce issue and than provide output of following command? sh# lsof /var/run/.heim_org.h5l.kcm-socket /run/.heim_org.h5l.kcm-socket sh# systemctl status sssd-kcm can you see some AVCs? sh# ausearch -m avc -ts recent
Sure. அ ~ kinit kinit: Connection refused while getting default ccache அ ~ sudo kinit kinit: Connection refused while getting default ccache அ ~ sudo lsof /var/run/.heim_org.h5l.kcm-socket /run/.heim_org.h5l.kcm-socket lsof: WARNING: can't stat() fuse.gvfsd-fuse file system /run/user/1000/gvfs Output information may be incomplete. lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc Output information may be incomplete. அ ~ sudo ausearch -m avc -ts recent <no matches> அ ~ KRB5_TRACE=/dev/stderr strace -f kinit execve("/usr/bin/kinit", ["kinit"], 0x7ffc438257b8 /* 63 vars */) = 0 brk(NULL) = 0x5577d97a9000 arch_prctl(0x3001 /* ARCH_??? */, 0x7fff92896890) = -1 EINVAL (Invalid argument) access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=73907, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 73907, PROT_READ, MAP_PRIVATE, 14, 0) = 0x7fa9fbdd7000 close(14) = 0 openat(AT_FDCWD, "/lib64/libkadm5srv_mit.so.12", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=124344, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fbdd5000 mmap(NULL, 123496, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbdb6000 mmap(0x7fa9fbdbd000, 69632, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x7000) = 0x7fa9fbdbd000 mmap(0x7fa9fbdce000, 16384, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x18000) = 0x7fa9fbdce000 mmap(0x7fa9fbdd2000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x1b000) = 0x7fa9fbdd2000 close(14) = 0 openat(AT_FDCWD, "/lib64/libkdb5.so.10", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=87504, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 86312, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbda0000 mmap(0x7fa9fbda5000, 49152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x5000) = 0x7fa9fbda5000 mmap(0x7fa9fbdb1000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x11000) = 0x7fa9fbdb1000 mmap(0x7fa9fbdb4000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x13000) = 0x7fa9fbdb4000 close(14) = 0 openat(AT_FDCWD, "/lib64/libkrb5.so.3", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=903184, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 885520, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbcc7000 mmap(0x7fa9fbce9000, 446464, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x22000) = 0x7fa9fbce9000 mmap(0x7fa9fbd56000, 237568, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x8f000) = 0x7fa9fbd56000 mmap(0x7fa9fbd90000, 61440, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xc9000) = 0x7fa9fbd90000 mmap(0x7fa9fbd9f000, 784, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fbd9f000 close(14) = 0 openat(AT_FDCWD, "/lib64/libcom_err.so.2", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=24584, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 24640, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbcc0000 mmap(0x7fa9fbcc2000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x2000) = 0x7fa9fbcc2000 mmap(0x7fa9fbcc4000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x4000) = 0x7fa9fbcc4000 mmap(0x7fa9fbcc5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x4000) = 0x7fa9fbcc5000 close(14) = 0 openat(AT_FDCWD, "/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 }\2\0\0\0\0\0"..., 832) = 832 pread64(14, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=2234072, ...}, AT_EMPTY_PATH) = 0 pread64(14, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784 mmap(NULL, 1957168, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbae2000 mmap(0x7fa9fbb08000, 1429504, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x26000) = 0x7fa9fbb08000 mmap(0x7fa9fbc65000, 315392, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x183000) = 0x7fa9fbc65000 mmap(0x7fa9fbcb2000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x1d0000) = 0x7fa9fbcb2000 mmap(0x7fa9fbcb8000, 32048, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fbcb8000 close(14) = 0 openat(AT_FDCWD, "/lib64/libgssrpc.so.4", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=139200, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 132800, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fbac1000 mmap(0x7fa9fbac7000, 77824, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x6000) = 0x7fa9fbac7000 mmap(0x7fa9fbada000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x19000) = 0x7fa9fbada000 mmap(0x7fa9fbae0000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x1f000) = 0x7fa9fbae0000 close(14) = 0 openat(AT_FDCWD, "/lib64/libgssapi_krb5.so.2", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=359488, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fbabf000 mmap(NULL, 351032, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fba69000 mmap(0x7fa9fba75000, 249856, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xc000) = 0x7fa9fba75000 mmap(0x7fa9fbab2000, 40960, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x49000) = 0x7fa9fbab2000 mmap(0x7fa9fbabc000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x53000) = 0x7fa9fbabc000 close(14) = 0 openat(AT_FDCWD, "/lib64/libk5crypto.so.3", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=95496, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 94256, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fba51000 mmap(0x7fa9fba56000, 53248, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x5000) = 0x7fa9fba56000 mmap(0x7fa9fba63000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x12000) = 0x7fa9fba63000 mmap(0x7fa9fba66000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x14000) = 0x7fa9fba66000 mmap(0x7fa9fba68000, 48, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fba68000 close(14) = 0 openat(AT_FDCWD, "/lib64/libkrb5support.so.0", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=67112, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 62096, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fba41000 mmap(0x7fa9fba45000, 32768, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x4000) = 0x7fa9fba45000 mmap(0x7fa9fba4d000, 8192, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xc000) = 0x7fa9fba4d000 mmap(0x7fa9fba4f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xe000) = 0x7fa9fba4f000 close(14) = 0 openat(AT_FDCWD, "/lib64/libkeyutils.so.1", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=24704, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 24584, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fba3a000 mmap(0x7fa9fba3c000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x2000) = 0x7fa9fba3c000 mmap(0x7fa9fba3e000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x4000) = 0x7fa9fba3e000 mmap(0x7fa9fba3f000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x4000) = 0x7fa9fba3f000 mmap(0x7fa9fba40000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fba40000 close(14) = 0 openat(AT_FDCWD, "/lib64/libcrypto.so.3", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=4443184, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 4350968, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fb600000 mmap(0x7fa9fb6ad000, 2506752, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xad000) = 0x7fa9fb6ad000 mmap(0x7fa9fb911000, 757760, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x311000) = 0x7fa9fb911000 mmap(0x7fa9fb9ca000, 368640, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x3ca000) = 0x7fa9fb9ca000 mmap(0x7fa9fba24000, 9208, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fba24000 close(14) = 0 openat(AT_FDCWD, "/lib64/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=67576, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 72264, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fba28000 mmap(0x7fa9fba2b000, 36864, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x3000) = 0x7fa9fba2b000 mmap(0x7fa9fba34000, 8192, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xc000) = 0x7fa9fba34000 mmap(0x7fa9fba36000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0xe000) = 0x7fa9fba36000 mmap(0x7fa9fba38000, 6728, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fba38000 close(14) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb5fe000 openat(AT_FDCWD, "/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=180952, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 181880, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fb5d1000 mmap(0x7fa9fb5d8000, 114688, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x7000) = 0x7fa9fb5d8000 mmap(0x7fa9fb5f4000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x23000) = 0x7fa9fb5f4000 mmap(0x7fa9fb5fa000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x29000) = 0x7fa9fb5fa000 mmap(0x7fa9fb5fc000, 5752, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb5fc000 close(14) = 0 openat(AT_FDCWD, "/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=107416, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 102408, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fb5b7000 mmap(0x7fa9fb5ba000, 61440, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x3000) = 0x7fa9fb5ba000 mmap(0x7fa9fb5c9000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x12000) = 0x7fa9fb5c9000 mmap(0x7fa9fb5cf000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x18000) = 0x7fa9fb5cf000 mmap(0x7fa9fb5d0000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb5d0000 close(14) = 0 openat(AT_FDCWD, "/lib64/libpcre2-8.so.0", O_RDONLY|O_CLOEXEC) = 14 read(14, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\0\0\0\0\0\0\0"..., 832) = 832 newfstatat(14, "", {st_mode=S_IFREG|0755, st_size=631104, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 627248, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 14, 0) = 0x7fa9fb51d000 mmap(0x7fa9fb520000, 446464, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x3000) = 0x7fa9fb520000 mmap(0x7fa9fb58d000, 163840, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x70000) = 0x7fa9fb58d000 mmap(0x7fa9fb5b5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 14, 0x97000) = 0x7fa9fb5b5000 close(14) = 0 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb51b000 mmap(NULL, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb518000 arch_prctl(ARCH_SET_FS, 0x7fa9fb518840) = 0 set_tid_address(0x7fa9fb518b10) = 11586 set_robust_list(0x7fa9fb518b20, 24) = 0 rseq(0x7fa9fb519160, 0x20, 0, 0x53053053) = 0 mprotect(0x7fa9fbcb2000, 16384, PROT_READ) = 0 mprotect(0x7fa9fb5b5000, 4096, PROT_READ) = 0 mprotect(0x7fa9fb5cf000, 4096, PROT_READ) = 0 mprotect(0x7fa9fb5fa000, 4096, PROT_READ) = 0 mprotect(0x7fa9fba36000, 4096, PROT_READ) = 0 mprotect(0x7fa9fb9ca000, 356352, PROT_READ) = 0 mprotect(0x7fa9fba3f000, 4096, PROT_READ) = 0 mprotect(0x7fa9fba4f000, 4096, PROT_READ) = 0 mprotect(0x7fa9fba66000, 8192, PROT_READ) = 0 mprotect(0x7fa9fbcc5000, 4096, PROT_READ) = 0 mprotect(0x7fa9fbd90000, 57344, PROT_READ) = 0 mprotect(0x7fa9fbabc000, 8192, PROT_READ) = 0 mprotect(0x7fa9fbae0000, 4096, PROT_READ) = 0 mprotect(0x7fa9fbdb4000, 4096, PROT_READ) = 0 mprotect(0x7fa9fbdd2000, 8192, PROT_READ) = 0 mprotect(0x5577d9698000, 4096, PROT_READ) = 0 mprotect(0x7fa9fbe1b000, 8192, PROT_READ) = 0 prlimit64(0, RLIMIT_STACK, NULL, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0 munmap(0x7fa9fbdd7000, 73907) = 0 statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0 statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0 getrandom("\x08\x5a\x2a\x9a\x6c\x55\xa1\xdf", 8, GRND_NONBLOCK) = 8 brk(NULL) = 0x5577d97a9000 brk(0x5577d97ca000) = 0x5577d97ca000 access("/etc/selinux/config", F_OK) = 0 openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=224366320, ...}, AT_EMPTY_PATH) = 0 mmap(NULL, 224366320, PROT_READ, MAP_PRIVATE, 14, 0) = 0x7fa9ede00000 close(14) = 0 ioctl(0, TCGETS, {c_iflag=BRKINT|ICRNL|IXON|IXANY|IMAXBEL|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD|HUPCL, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 ioctl(1, TCGETS, {c_iflag=BRKINT|ICRNL|IXON|IXANY|IMAXBEL|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD|HUPCL, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 ioctl(2, TCGETS, {c_iflag=BRKINT|ICRNL|IXON|IXANY|IMAXBEL|IUTF8, c_oflag=NL0|CR0|TAB0|BS0|VT0|FF0|OPOST|ONLCR, c_cflag=B38400|CS8|CREAD|HUPCL, c_lflag=ISIG|ICANON|ECHO|ECHOE|ECHOK|IEXTEN|ECHOCTL|ECHOKE, ...}) = 0 futex(0x7fa9fba50288, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7fa9fba500d0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7fa9fbd9ec70, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7fa9fbd9efe0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 newfstatat(AT_FDCWD, "/etc/krb5.conf", {st_mode=S_IFREG|0644, st_size=1163, ...}, 0) = 0 openat(AT_FDCWD, "/etc/krb5.conf", O_RDONLY) = 14 fcntl(14, F_SETFD, FD_CLOEXEC) = 0 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=1163, ...}, AT_EMPTY_PATH) = 0 read(14, "includedir /etc/krb5.conf.d/\n\n# "..., 4096) = 1163 openat(AT_FDCWD, "/etc/krb5.conf.d/", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 17 newfstatat(17, "", {st_mode=S_IFDIR|0755, st_size=106, ...}, AT_EMPTY_PATH) = 0 getdents64(17, 0x5577d97ac2b0 /* 5 entries */, 32768) = 168 getdents64(17, 0x5577d97ac2b0 /* 0 entries */, 32768) = 0 close(17) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//crypto-policies", O_RDONLY) = 17 newfstatat(17, "", {st_mode=S_IFREG|0644, st_size=179, ...}, AT_EMPTY_PATH) = 0 read(17, "[libdefaults]\npermitted_enctypes"..., 4096) = 179 read(17, "", 4096) = 0 close(17) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//enable_sssd_conf_dir", O_RDONLY) = 17 newfstatat(17, "", {st_mode=S_IFREG|0644, st_size=252, ...}, AT_EMPTY_PATH) = 0 read(17, "# This file should normally be i"..., 4096) = 252 openat(AT_FDCWD, "/var/lib/sss/pubconf/krb5.include.d/", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 18 newfstatat(18, "", {st_mode=S_IFDIR|0755, st_size=0, ...}, AT_EMPTY_PATH) = 0 getdents64(18, 0x5577d97b4400 /* 2 entries */, 32768) = 48 getdents64(18, 0x5577d97b4400 /* 0 entries */, 32768) = 0 close(18) = 0 read(17, "", 4096) = 0 close(17) = 0 openat(AT_FDCWD, "/etc/krb5.conf.d//kcm_default_ccache", O_RDONLY) = 17 newfstatat(17, "", {st_mode=S_IFREG|0644, st_size=474, ...}, AT_EMPTY_PATH) = 0 read(17, "# This file should normally be i"..., 4096) = 474 read(17, "", 4096) = 0 close(17) = 0 read(14, "", 4096) = 0 close(14) = 0 futex(0x7fa9fba50000, FUTEX_WAKE_PRIVATE, 2147483647) = 0 futex(0x7fa9fb5fd500, FUTEX_WAKE_PRIVATE, 2147483647) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDONLY|O_CLOEXEC) = 14 read(14, "", 4095) = 0 close(14) = 0 openat(AT_FDCWD, "/etc/selinux/config", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=1187, ...}, AT_EMPTY_PATH) = 0 read(14, "\n# This file controls the state "..., 4096) = 1187 read(14, "", 4096) = 0 close(14) = 0 futex(0x7fa9fb5fb1a0, FUTEX_WAKE_PRIVATE, 2147483647) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=424715, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs_dist", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=704, ...}, AT_EMPTY_PATH) = 0 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=704, ...}, AT_EMPTY_PATH) = 0 read(14, "/run /var/run\n/run/lock /var/loc"..., 4096) = 704 read(14, "", 4096) = 0 close(14) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 read(14, "", 4096) = 0 close(14) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=424715, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.bin", {st_mode=S_IFREG|0644, st_size=597805, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.bin", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=597805, ...}, AT_EMPTY_PATH) = 0 read(14, "\212\377|\371\5\0\0\0\20\0\0\00010.42 2022-12-11\6\0\0\0"..., 4096) = 4096 lseek(14, 0, SEEK_SET) = 0 mmap(NULL, 597805, PROT_READ, MAP_PRIVATE, 14, 0) = 0x7fa9fb486000 brk(0x5577d9801000) = 0x5577d9801000 brk(0x5577d9822000) = 0x5577d9822000 mmap(NULL, 491520, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9fb40e000 mremap(0x7fa9fb40e000, 491520, 983040, MREMAP_MAYMOVE) = 0x7fa9edd10000 close(14) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs", {st_mode=S_IFREG|0644, st_size=15537, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", {st_mode=S_IFREG|0644, st_size=21309, ...}, 0) = 0 openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=21309, ...}, AT_EMPTY_PATH) = 0 read(14, "\212\377|\371\5\0\0\0\20\0\0\00010.42 2022-12-11\6\0\0\0"..., 4096) = 4096 lseek(14, 0, SEEK_SET) = 0 mmap(NULL, 21309, PROT_READ, MAP_PRIVATE, 14, 0) = 0x7fa9fbde4000 close(14) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local", {st_mode=S_IFREG|0644, st_size=0, ...}, 0) = 0 newfstatat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local.bin", 0x7fff92893ff0, 0) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local", O_RDONLY|O_CLOEXEC) = 14 newfstatat(14, "", {st_mode=S_IFREG|0644, st_size=0, ...}, AT_EMPTY_PATH) = 0 read(14, "", 4096) = 0 lseek(14, 0, SEEK_SET) = 0 read(14, "", 4096) = 0 close(14) = 0 mmap(NULL, 827392, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7fa9edc46000 munmap(0x7fa9edd10000, 983040) = 0 brk(0x5577d9843000) = 0x5577d9843000 brk(0x5577d9867000) = 0x5577d9867000 brk(0x5577d988a000) = 0x5577d988a000 brk(0x5577d98ae000) = 0x5577d98ae000 brk(0x5577d98d2000) = 0x5577d98d2000 brk(0x5577d98f5000) = 0x5577d98f5000 brk(0x5577d9919000) = 0x5577d9919000 brk(0x5577d993d000) = 0x5577d993d000 brk(0x5577d9960000) = 0x5577d9960000 brk(0x5577d9984000) = 0x5577d9984000 brk(0x5577d99a8000) = 0x5577d99a8000 brk(0x5577d99cb000) = 0x5577d99cb000 brk(0x5577d99ef000) = 0x5577d99ef000 brk(0x5577d9a13000) = 0x5577d9a13000 brk(0x5577d9a36000) = 0x5577d9a36000 brk(0x5577d9a5a000) = 0x5577d9a5a000 brk(0x5577d9a7e000) = 0x5577d9a7e000 brk(0x5577d9aa1000) = 0x5577d9aa1000 brk(0x5577d9ac5000) = 0x5577d9ac5000 brk(0x5577d9ae9000) = 0x5577d9ae9000 brk(0x5577d9b0c000) = 0x5577d9b0c000 brk(0x5577d9b30000) = 0x5577d9b30000 brk(0x5577d9b54000) = 0x5577d9b54000 brk(0x5577d9b77000) = 0x5577d9b77000 brk(0x5577d9b9b000) = 0x5577d9b9b000 brk(0x5577d9bbf000) = 0x5577d9bbf000 brk(0x5577d9be2000) = 0x5577d9be2000 brk(0x5577d9c06000) = 0x5577d9c06000 brk(0x5577d9c2a000) = 0x5577d9c2a000 brk(0x5577d9c4d000) = 0x5577d9c4d000 brk(0x5577d9c71000) = 0x5577d9c71000 brk(0x5577d9c95000) = 0x5577d9c95000 brk(0x5577d9cb9000) = 0x5577d9cb9000 brk(0x5577d9cdc000) = 0x5577d9cdc000 brk(0x5577d9d00000) = 0x5577d9d00000 brk(0x5577d9d24000) = 0x5577d9d24000 brk(0x5577d9d47000) = 0x5577d9d47000 brk(0x5577d9d6b000) = 0x5577d9d6b000 brk(0x5577d9d8f000) = 0x5577d9d8f000 brk(0x5577d9db2000) = 0x5577d9db2000 brk(0x5577d9dd6000) = 0x5577d9dd6000 brk(0x5577d9dfa000) = 0x5577d9dfa000 brk(0x5577d9e1d000) = 0x5577d9e1d000 brk(0x5577d9e41000) = 0x5577d9e41000 brk(0x5577d9e65000) = 0x5577d9e65000 brk(0x5577d9e88000) = 0x5577d9e88000 brk(0x5577d9eac000) = 0x5577d9eac000 brk(0x5577d9ed0000) = 0x5577d9ed0000 brk(0x5577d9ef3000) = 0x5577d9ef3000 brk(0x5577d9f17000) = 0x5577d9f17000 brk(0x5577d9f3b000) = 0x5577d9f3b000 brk(0x5577d9f5e000) = 0x5577d9f5e000 brk(0x5577d9f82000) = 0x5577d9f82000 brk(0x5577d9fa6000) = 0x5577d9fa6000 brk(0x5577d9fca000) = 0x5577d9fca000 brk(0x5577d9fed000) = 0x5577d9fed000 brk(0x5577da011000) = 0x5577da011000 brk(0x5577da035000) = 0x5577da035000 brk(0x5577da058000) = 0x5577da058000 brk(0x5577da07c000) = 0x5577da07c000 access("/var/run/setrans/.setrans-unix", F_OK) = -1 ENOENT (No such file or directory) futex(0x7fa9fb5fd648, FUTEX_WAKE_PRIVATE, 2147483647) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/current", O_RDONLY|O_CLOEXEC) = 14 read(14, "unconfined_u:unconfined_r:unconf"..., 4095) = 54 close(14) = 0 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 14 write(14, "unconfined_u:object_r:device_t:s"..., 34) = 34 close(14) = 0 openat(AT_FDCWD, "/dev/stderr", O_WRONLY|O_CREAT|O_APPEND, 0600) = 14 openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 17 write(17, NULL, 0) = 0 close(17) = 0 munmap(0x7fa9edc46000, 827392) = 0 munmap(0x7fa9fbde4000, 21309) = 0 munmap(0x7fa9fb486000, 597805) = 0 socket(AF_UNIX, SOCK_STREAM, 0) = 17 connect(17, {sa_family=AF_UNIX, sun_path="/var/run/.heim_org.h5l.kcm-socket"}, 110) = -1 ECONNREFUSED (Connection refused) close(17) = 0 openat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 17 newfstatat(17, "", {st_mode=S_IFREG|0644, st_size=2998, ...}, AT_EMPTY_PATH) = 0 read(17, "# Locale name alias data base.\n#"..., 4096) = 2998 read(17, "", 4096) = 0 close(17) = 0 openat(AT_FDCWD, "/usr/share/locale/en_IN.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en_IN/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory) write(2, "kinit: Connection refused ", 26kinit: Connection refused ) = 26 write(2, "while getting default ccache", 28while getting default ccache) = 28 write(2, "\n", 1 ) = 1 close(14) = 0 exit_group(1) = ? +++ exited with 1 +++
(In reply to Buvanesh Kumar from comment #2) > Sure. > > அ ~ kinit > kinit: Connection refused while getting default ccache > > அ ~ sudo kinit > kinit: Connection refused while getting default ccache > //snip > openat(AT_FDCWD, "/var/lib/sss/pubconf/krb5.include.d/", > O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 18 > newfstatat(18, "", {st_mode=S_IFDIR|0755, st_size=0, ...}, AT_EMPTY_PATH) = 0 > getdents64(18, 0x5577d97b4400 /* 2 entries */, 32768) = 48 > getdents64(18, 0x5577d97b4400 /* 0 entries */, 32768) = 0 > close(18) = 0 > read(17, "", 4096) = 0 > close(17) = 0 > openat(AT_FDCWD, "/etc/krb5.conf.d//kcm_default_ccache", O_RDONLY) = 17 The file is owned by the sssd-kcm package but > அ ~ sudo lsof /var/run/.heim_org.h5l.kcm-socket > /run/.heim_org.h5l.kcm-socket > lsof: WARNING: can't stat() fuse.gvfsd-fuse file system /run/user/1000/gvfs > Output information may be incomplete. > lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc > Output information may be incomplete. > But nobody listen on the UNIX socket. sssd-kcm is systemd socket activated service so you should se at least systemd listening on the socket e.g. [root@localhost ]# lsof /var/run/.heim_org.h5l.kcm-socket /run/.heim_org.h5l.kcm-socket COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME systemd 1 root 62u unix 0x00000000f1674ef5 0t0 27704 /run/.heim_org.h5l.kcm-socket type=STREAM (LISTEN) and later when sssd-kcm is running something like [root@localhost ]# lsof /var/run/.heim_org.h5l.kcm-socket /run/.heim_org.h5l.kcm-socket COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME systemd 1 root 62u unix 0x00000000f1674ef5 0t0 27704 /run/.heim_org.h5l.kcm-socket type=STREAM (LISTEN) sssd_kcm 346133 root 3u unix 0x00000000f1674ef5 0t0 27704 /run/.heim_org.h5l.kcm-socket type=STREAM (LISTEN) Is looks like the sssd-kcm.socket is disabled on your system even though it should be enabled by default e.g. [root@localhost ]# systemctl status sssd-kcm.{socket,service} ● sssd-kcm.socket - SSSD Kerberos Cache Manager responder socket Loaded: loaded (/usr/lib/systemd/system/sssd-kcm.socket; enabled; vendor preset: enabled) Active: active (listening) since Tue 2023-07-18 11:57:37 CEST; 1 week 5 days ago Triggers: ● sssd-kcm.service Docs: man:sssd-kcm(8) Listen: /run/.heim_org.h5l.kcm-socket (Stream) CGroup: /system.slice/sssd-kcm.socket Jul 18 11:57:37 localhost.localdomain systemd[1]: Listening on SSSD Kerberos Cache Manager responder socket. ○ sssd-kcm.service - SSSD Kerberos Cache Manager Loaded: loaded (/usr/lib/systemd/system/sssd-kcm.service; indirect; vendor preset: disabled) Active: inactive (dead) since Mon 2023-07-31 11:37:21 CEST; 18s ago TriggeredBy: ● sssd-kcm.socket Docs: man:sssd-kcm(5) Process: 346132 ExecStartPre=/usr/sbin/sssd --genconf-section=kcm (code=exited, status=0/SUCCESS) Process: 346133 ExecStart=/usr/libexec/sssd/sssd_kcm --uid 0 --gid 0 ${DEBUG_LOGGER} (code=exited, status=0/SUCCESS) Main PID: 346133 (code=exited, status=0/SUCCESS) Jul 31 11:31:50 localhost.localdomain systemd[1]: Starting SSSD Kerberos Cache Manager... Jul 31 11:31:51 localhost.localdomain systemd[1]: Started SSSD Kerberos Cache Manager. Jul 31 11:31:51 localhost.localdomain sssd_kcm[346133]: Starting up Jul 31 11:37:21 localhost.localdomain systemd[1]: Stopping SSSD Kerberos Cache Manager... Jul 31 11:37:21 localhost.localdomain systemd[1]: sssd-kcm.service: Deactivated successfully. Jul 31 11:37:21 localhost.localdomain systemd[1]: Stopped SSSD Kerberos Cache Manager. I would recommend to check status of related systemd units `systemctl status sssd-kcm.{socket,service}`
The issue is due to the fact that I copied krb5.conf file from one laptop to an another, and missed to fix the SELinux labelling afterwards. In short note, I had to run `$ sudo restorecon -Rv /etc/` to fix the labelling. Longer version: The service status for sssd-kcm.socket (note: it is sssd-kcm.socket, not sssd-kcm or sssd-kcm.service) showed as failed, as soon as I start executing kinit: அ ~ sudo systemctl status sssd-kcm.socket ● sssd-kcm.socket - SSSD Kerberos Cache Manager responder socket Loaded: loaded (/usr/lib/systemd/system/sssd-kcm.socket; enabled; preset: enabled) Active: active (listening) since Mon 2023-07-31 12:01:27 CEST; 3s ago Triggers: ● sssd-kcm.service Docs: man:sssd-kcm(8) Listen: /run/.heim_org.h5l.kcm-socket (Stream) CGroup: /system.slice/sssd-kcm.socket அ ~ kinit kinit: Connection reset by peer while getting default ccache அ ~ sudo systemctl status sssd-kcm.socket × sssd-kcm.socket - SSSD Kerberos Cache Manager responder socket Loaded: loaded (/usr/lib/systemd/system/sssd-kcm.socket; enabled; preset: enabled) Active: failed (Result: service-start-limit-hit) since Mon 2023-07-31 12:02:31 CEST; 1s ago Duration: 1min 3.645s Triggers: ● sssd-kcm.service Docs: man:sssd-kcm(8) Listen: /run/.heim_org.h5l.kcm-socket (Stream) Jul 31 12:01:27 fedora systemd[1]: Listening on sssd-kcm.socket - SSSD Kerberos Cache Manager responder socket. Jul 31 12:02:31 fedora systemd[1]: sssd-kcm.socket: Failed with result 'service-start-limit-hit'. I was missing files related to sssd-* packages, I have reinstalled sssd-kcm to fix it. அ ~ rpm --verify sssd-common sssd-kcm missing /etc/sssd missing /etc/sssd/conf.d missing /etc/sssd/pki .......T. /usr/lib/systemd/system/sssd.service .M....... /var/log/sssd அ ~ sudo dnf reinstall sssd-kcm அ ~ rpm --verify sssd-kcm < no output, that means we are good > I tried kinit again, and I still saw the same issue. I have inspected the SELinux warnings and found inappropriate labelling. அ ~ sudo ausearch -m avc -ts recent ---- time->Mon Jul 31 11:58:56 2023 type=AVC msg=audit(1690797536.716:793): avc: denied { read } for pid=20207 comm="sssd_kcm" name="krb5.conf" dev="nvme0n1p8" ino=278998 scontext=system_u:system_r:sssd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 ---- time->Mon Jul 31 11:58:56 2023 type=AVC msg=audit(1690797536.824:796): avc: denied { read } for pid=20210 comm="sssd_kcm" name="krb5.conf" dev="nvme0n1p8" ino=278998 scontext=system_u:system_r:sssd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 ---- time->Mon Jul 31 11:58:56 2023 type=AVC msg=audit(1690797536.933:799): avc: denied { read } for pid=20212 comm="sssd_kcm" name="krb5.conf" dev="nvme0n1p8" ino=278998 scontext=system_u:system_r:sssd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 ---- time->Mon Jul 31 11:58:57 2023 type=AVC msg=audit(1690797537.028:802): avc: denied { read } for pid=20215 comm="sssd_kcm" name="krb5.conf" dev="nvme0n1p8" ino=278998 scontext=system_u:system_r:sssd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 ---- time->Mon Jul 31 11:58:57 2023 type=AVC msg=audit(1690797537.142:805): avc: denied { read } for pid=20217 comm="sssd_kcm" name="krb5.conf" dev="nvme0n1p8" ino=278998 scontext=system_u:system_r:sssd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file permissive=0 அ ~ ls -lZ /etc/krb5.conf -rw-r--r--. 1 bsivasub bsivasub unconfined_u:object_r:user_home_t:s0 1163 Jul 26 03:33 /etc/krb5.conf Fixed the SELinux labelling using $ sudo restorecon -Rv /etc/ I have also fixed the file permissions for /etc/krb5.conf file by using $ rpm --restore krb5-libs Finally, I was able to do kinit without an issue. Thanks a lot to Lukas for the help and guidance :).