Hide Forgot
Description of problem: kinit as admin, and then access UI. But Internal server error is thrown. Checked about:config: network.negotiate-auth.delegation-uris; status-default; type:string; value is not set Rob took a look, and suspects the web server isn't getting the browser's TGT and in raising that error it is running into another one. The second error is trying to report the user whose TGT we didn't get and since we don't have the TGT <boom> Also checked /var/log/krb5kdc.log, but didn't see any CONSTRAINED DELEGATION. Only ISSUE We should report the right error even if the client doesn't send us a TGT. Version-Release number of selected component (if applicable): ipa-server-2.2.0-101.20120209T0933zgit52cf9d9.el6.x86_64 How reproducible: Steps to Reproduce: 1. kinit as admin 2. access ui from browser Actual results: internal server error Expected results: Be able to access UI successfully Additional info:
Created attachment 560964 [details] error_log
Upstream ticket: https://fedorahosted.org/freeipa/ticket/2371
The problem is the server is trying to raise a CCacheError but failing because there is no principal in context to report.
Fixed upstream: master: https://fedorahosted.org/freeipa/changeset/95b85f6384637e6c5c79a8567de3583e7d3af046 ipa-2-2: https://fedorahosted.org/freeipa/changeset/c941ecf6319bf6445d58b08405c1813019e5f0af
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: No documentation needed.
Verified using ipa-server-2.2.0-11.el6.x86_64
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0819.html