<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[Форум Рутокен &mdash; Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
		<link>https://forum.rutoken.ru/topic/3937/</link>
		<atom:link href="https://forum.rutoken.ru/feed/rss/topic/3937/" rel="self" type="application/rss+xml" />
		<description><![CDATA[Недавние сообщения в теме «Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows».]]></description>
		<lastBuildDate>Fri, 30 Jun 2023 10:19:21 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/21033/#p21033</link>
			<description><![CDATA[<p>Здравствуйте, <strong>marat.israfilov</strong>, <br />По носителю Jacarta вам необходимо обращаться в техническую поддержку компании &quot;Аладдин Р.Д.&quot;.</p>]]></description>
			<author><![CDATA[null@example.com (Фатеева Светлана)]]></author>
			<pubDate>Fri, 30 Jun 2023 10:19:21 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/21033/#p21033</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/21032/#p21032</link>
			<description><![CDATA[<p><strong>savel_97</strong>, добрый день, столкнулся с такой же проблемой, только при использовании токенов Jacarta. Подскажите, пожалуйста, смогли ли Вы решить проблему?<br />Есть некоторые предположения на этот счёт, перекопал кучу зарубежных форумов, но решения пока нет.<br />в логе /var/log/sssd/sssd_pam.log видно что демон читает токен, видит отпечаток сертификата, но видимо он его не устраивает &quot;Cert found [CERT] doesn&#039;t match matching rules and is ignored.<br />Далее говорится, что так как try_cert_auth (флаг для sssd) установлен, но подходящего серта нет, запрос завершается. Скорее всего поэтому p11_child лог говорит что Login NOT required, а в krb5_child логе ошибка Prompter interface isn&#039;t used for password prompts by SSSD.<br />Я сертификаты для KDC и для пользователя в домене SAMBA выпускал через OPENSSL.<br />Открыт к обсуждению вопроса и совместному поиску решения.</p>]]></description>
			<author><![CDATA[null@example.com (marat.israfilov)]]></author>
			<pubDate>Fri, 30 Jun 2023 09:57:19 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/21032/#p21032</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20718/#p20718</link>
			<description><![CDATA[<p><strong>savel_97</strong>, добрый день.<br />Нет, для подобной интеграции необходимы устройства семейства Рутокен ЭЦП.</p>]]></description>
			<author><![CDATA[null@example.com (Аверченко Кирилл)]]></author>
			<pubDate>Fri, 02 Jun 2023 08:51:39 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20718/#p20718</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20716/#p20716</link>
			<description><![CDATA[<p>Подскажите пожалуйста, используя Рутокен S, возможно ли настроить 2ФА на линукс системах в домене Windows?</p>]]></description>
			<author><![CDATA[null@example.com (savel_97)]]></author>
			<pubDate>Fri, 02 Jun 2023 08:17:15 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20716/#p20716</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20641/#p20641</link>
			<description><![CDATA[<p>Понял, благодарю</p>]]></description>
			<author><![CDATA[null@example.com (savel_97)]]></author>
			<pubDate>Tue, 23 May 2023 10:42:49 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20641/#p20641</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20640/#p20640</link>
			<description><![CDATA[<p><strong>savel_97</strong>, Рутокен Лайт не подойдет для 2фа в любом Linux. <br />Необходимо использовать Рутокены ЭЦП 2.0/3.0</p>]]></description>
			<author><![CDATA[null@example.com (Аверченко Кирилл)]]></author>
			<pubDate>Tue, 23 May 2023 09:58:53 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20640/#p20640</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20639/#p20639</link>
			<description><![CDATA[<p>К сожалению нет возможности проверить РуТокен ЭЦП так как есть в наличии только РуТокен lite. Необходимо иметь именно РуТокен ЭЦП для 2ФА? РедОС я как тест использовал, еще буду пытаться настроить 2ФА на АЛЬт ОС и Astra Linux</p>]]></description>
			<author><![CDATA[null@example.com (savel_97)]]></author>
			<pubDate>Tue, 23 May 2023 09:14:41 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20639/#p20639</guid>
		</item>
		<item>
			<title><![CDATA[Re: Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20638/#p20638</link>
			<description><![CDATA[<p><strong>savel_97</strong>, добрый день.<br />Есть возможность проверить работу на Рутокен ЭЦП?<br />Рутокен Лайт не полностью поддерживается библиотекой rtpkcs11ecp, с помощью которой работает 2фа в Linux.<br />Полная инструкция по настройке Рутокен ЭЦП в RedOS доступна по ссылке <a href="https://dev.rutoken.ru/pages/viewpage.action?pageId=124125237">https://dev.rutoken.ru/pages/viewpage.a … =124125237</a></p>]]></description>
			<author><![CDATA[null@example.com (Аверченко Кирилл)]]></author>
			<pubDate>Tue, 23 May 2023 09:06:35 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20638/#p20638</guid>
		</item>
		<item>
			<title><![CDATA[Настройка 2ФА на рабочих станциях РедОС 7.3.2 в домене Windows]]></title>
			<link>https://forum.rutoken.ru/post/20637/#p20637</link>
			<description><![CDATA[<p>Здравствуйте!<br />Использую РуТокен lite. Клиентская машине РедОС 7.3.2, сервер Active Directory MS.<br />Настраивал все согласно инструкциям <a href="https://dev.rutoken.ru/pages/viewpage.action?pageId=72450654,">https://dev.rutoken.ru/pages/viewpage.a … =72450654,</a> <a href="https://dev.rutoken.ru/pages/viewpage.action?pageId=57149225.">https://dev.rutoken.ru/pages/viewpage.a … =57149225.</a><br />При попытке аутентификации после запроса пин-кода в домен sssd завершает работу с ошибкой 7 &quot;Сбой при проверке подлинности&quot;<br />Согласно логам p11_child обнаруживает рутокен и записанные на нём сертификаты.<br />Ошибка возникает в krb5_child.<br />Попытка отключить предварительную проверку подлинности kerberos к решению проблемы не привела.<br />Прилагаю логи с конфигурационными файлами и логами sssd</p><p><strong>krb5.conf</strong><br />includedir /etc/krb5.conf.d/</p><p>[logging]<br />&nbsp; &nbsp; default = FILE:/var/log/krb5libs.log<br />&nbsp; &nbsp; kdc = FILE:/var/log/krb5kdc.log<br />&nbsp; &nbsp; admin_server = FILE:/var/log/kadmind.log</p><p>[libdefaults]<br />&nbsp; &nbsp; #pkinit_eku_checking = none<br />&nbsp; &nbsp; pkinit_eku_checking = kpServerAuth<br />&nbsp; &nbsp; default_realm = DC.TEST<br />&nbsp; &nbsp; pkinit_identities = /usr/lib64/librtpkcs11ecp.so<br />&nbsp; &nbsp; canonicalize = True<br />&nbsp; &nbsp; <br />pkinit_kdc_hostname = WIN-QIUURAQ5IN8.dc.test<br />&nbsp; &nbsp; dns_lookup_realm = false&nbsp; # Отключить поиск kerberos-имени домена через DNS<br />&nbsp; &nbsp; dns_lookup_kdc = true&nbsp; # Включить поиск kerberos-настроек домена через DNS<br />&nbsp; &nbsp; ticket_lifetime = 24h<br />&nbsp; &nbsp; renew_lifetime = 7d<br />&nbsp; &nbsp; forwardable = true<br />&nbsp; &nbsp; rdns = false<br />&nbsp; &nbsp; pkinit_anchors = FILE:/etc/sssd/pki/sssd_auth_ca_db.pem<br />&nbsp; &nbsp; spake_preauth_groups = edwards25519<br />&nbsp; &nbsp; default_ccache_name = FILE:/tmp/krb5cc_%{uid}<br />&nbsp; &nbsp; default_realm = DC.TEST</p><p>&nbsp; &nbsp; canonicalize = True</p><p>&nbsp; &nbsp; default_tgs_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 RC4-HMAC DES-CBC-CRC DES3-CBC-SHA1 DES-CBC-MD5<br />&nbsp; &nbsp; default_tkt_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 RC4-HMAC DES-CBC-CRC DES3-CBC-SHA1 DES-CBC-MD5<br />&nbsp; &nbsp; preferred_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 RC4-HMAC DES-CBC-CRC DES3-CBC-SHA1 DES-CBC-MD5</p><p>[realms]<br />DC.TEST = {<br />&nbsp; &nbsp; kdc = WIN-QIUURAQ5IN8.dc.test # Primary Domain Controller<br />&nbsp; &nbsp; <br />&nbsp; &nbsp; admin_server = WIN-QIUURAQ5IN8.dc.test # Primary Domain Controller<br />&nbsp; &nbsp; default_domain = dc.test # Domain name<br />}</p><p>[domain_realm]<br />.dc.test = DC.TEST<br />dc.test = DC.TEST</p><br /><p><strong>sssd.conf</strong><br />[sssd]<br />domains = dc.test<br />config_file_version = 2<br />services = nss, pam<br />debug_level = 10</p><p>[domain/dc.test]<br />krb5_auth_timeout = 120<br />ad_domain = dc.test<br />ad_server = WIN-QIUURAQ5IN8.dc.test<br />krb5_realm = DC.TEST<br />case_sensitive = False<br />realmd_tags = manages-system joined-with-samba</p><p># Кэширование аутентификационных данных, необходимо при недоступности домена<br />cache_credentials = True</p><p>pkinit_kdc_hostname = WIN-QIUURAQ5IN8.dc.test<br />pkinit_eku_checking = none</p><p>id_provider = ad<br />access_provider = ad<br />krb5_store_password_if_offline = True<br />default_shell = /bin/bash<br />ldap_id_mapping = True<br />ad_gpo_access_control = disabled</p><p># Включает/Отключает режим полных имён пользователей при входе<br />use_fully_qualified_names = False</p><p># Определение домашнего каталога для доменных пользователей<br />fallback_homedir = /home/%u@%d</p><p># Параметр access_provider = simple Определяет список доступа на основе имен пользователей или групп.<br />#access_provider = simple<br />#simple_allow_users = user1@example.com, user2@example.com<br />#simple_allow_groups = group@example.com</p><p># Включает/Отключает перечисление всех записей домена, операция(id или getent) может занимать длительное время при enumerate = False<br />enumerate = False</p><p># Параметр ignore_group_members может ускорить авторизацию в домене если домен имеет большое количество пользователей, групп и вложенных OU<br /># Если установлено значение TRUE, то атрибут членства в группе не запрашивается с сервера ldap и не обрабатывается вызовов поиска группы.<br /># ignore_group_members = True</p><p># Поиск ссылок может привести к снижению производительности в средах, которые их интенсивно используют.<br /># true - не рекомендуется для больших инфраструктур. Отключаем этот поиск.<br />ldap_referrals = false</p><p># Включает/Отключает динамические обновления DNS, если в статусе sssd ошибка &quot;TSIG error with server: tsig verify failure&quot;, то установите dyndns_update = false<br />dyndns_update = true<br />dyndns_refresh_interval = 43200<br />dyndns_update_ptr = true<br />dyndns_ttl = 3600</p><p>krb5_lifetime = 24h # Срок действия билета истекает каждые 24ч и его можно непрерывно продлевать в течение 7 дней<br />krb5_renewable_lifetime = 7d # Самопродление тикета, значение определяет максимальное время жизни тикета<br />krb5_renew_interval = 60s # Определяет интервал необходимость обновления билета. По истечении половины срока действия билета билет продлевается автоматически.</p><p>[nss]<br /># Сколько секунд nss_sss должен кэшировать перечисления (запросы информации обо всех пользователях) Default: 120<br />#entry_cache_timeout = 15<br /># Задает время в секундах, в течение которого список поддоменов будет считаться действительным. Default: 60<br />#get_domains_timeout = 10<br />debug_level=10</p><br /><p>[pam]<br />pam_p11_allowed_services = +cinnamon-screensaver, +mate-screensaver, +lightdm<br />p11_child_timeout = 120<br />pam_cert_auth = True<br />debug_level=10</p><p>#[certmap/dc.test/nt_principal]<br />#maprule = (|(userPrincipalName={subject_nt_principal})(samAccountName={subject_nt_principal.short_name}))</p><br /><p><strong>krb5_child.log</strong><br />(2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_get_init_creds_password] (0x0020): [RID#67] 1932: [-1765328174][Pre-authentication failed: Cannot read password]<br />********************** PREVIOUS MESSAGE WAS TRIGGERED BY THE FOLLOWING BACKTRACE:<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [main] (0x0400): [RID#67] krb5_child started.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [unpack_buffer] (0x1000): [RID#67] total buffer size: [328]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [unpack_buffer] (0x0100): [RID#67] cmd [249 (pre-auth)] uid [374600500] gid [374600513] validate [true] enterprise principal [true] offline [false] UPN [admin@DC.TEST]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [unpack_buffer] (0x0100): [RID#67] ccname: [FILE:/tmp/krb5cc_374600500] old_ccname: [FILE:/tmp/krb5cc_374600500] keytab: [not set]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [check_keytab_name] (0x0400): [RID#67] Missing krb5_keytab option for domain, looking for default one<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [check_keytab_name] (0x0400): [RID#67] krb5_kt_default_name() returned: FILE:/etc/krb5.keytab<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [check_keytab_name] (0x0400): [RID#67] krb5_child will default to: /etc/krb5.keytab<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [check_use_fast] (0x0100): [RID#67] Not using FAST.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [switch_creds] (0x0200): [RID#67] Switch user to [0][0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [switch_creds] (0x0200): [RID#67] Already user [0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [main] (0x2000): [RID#67] Running as [0][0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [set_lifetime_options] (0x0100): [RID#67] Renewable lifetime is set to [7d # Самопродление тикета, значение определяет максимальное время жизни тикета]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [set_lifetime_options] (0x0100): [RID#67] Lifetime is set to [24h # Срок действия билета истекает каждые 24ч и его можно непрерывно продлевать в течение 7 дней]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [set_canonicalize_option] (0x0100): [RID#67] Canonicalization is set to [true]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [main] (0x0400): [RID#67] Will perform pre-auth<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [tgt_req_child] (0x1000): [RID#67] Attempting to get a TGT<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [get_and_save_tgt] (0x4000): [RID#67] Found Smartcard credentials, trying pkinit.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [get_pkinit_identity] (0x4000): [RID#67] Got [RuToken][/usr/lib64/librtpkcs11ecp.so].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [get_pkinit_identity] (0x4000): [RID#67] Using pkinit identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:token=RuToken:certid=74652D5275546F6B656E2D37393232653939632D636566392D346135652D613539372D3433316362336161353638395F45:certlabel=te-RuToken-7922e99c-cef9-4a5e-a597-431cb3aa5689_E].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [get_and_save_tgt] (0x0400): [RID#67] Attempting kinit for realm [DC.TEST]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_responder] (0x4000): [RID#67] Got question [pkinit].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [answer_pkinit] (0x4000): [RID#67] [0] Identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:slotid=1:token=RuToken] flags [0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [answer_pkinit] (0x4000): [RID#67] Setting pkinit_prompting.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x4000): [RID#67] sss_krb5_prompter name [(null)] banner [(null)] num_prompts [1] EINVAL.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x4000): [RID#67] Prompt [0][RuToken&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PIN].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x0200): [RID#67] Prompter interface isn&#039;t used for password prompts by SSSD.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x4000): [RID#67] sss_krb5_prompter name [(null)] banner [(null)] num_prompts [1] EINVAL.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x4000): [RID#67] Prompt [0][Password for admin\@DC.TEST@DC.TEST].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_prompter] (0x0200): [RID#67] Prompter interface isn&#039;t used for password prompts by SSSD.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:12): [krb5_child[11266]] [sss_krb5_get_init_creds_password] (0x0020): [RID#67] 1932: [-1765328174][Pre-authentication failed: Cannot read password]<br />********************** BACKTRACE DUMP ENDS HERE *********************************</p><p>(2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_get_init_creds_password] (0x0020): [RID#68] 1932: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />********************** PREVIOUS MESSAGE WAS TRIGGERED BY THE FOLLOWING BACKTRACE:<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [main] (0x0400): [RID#68] krb5_child started.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [unpack_buffer] (0x1000): [RID#68] total buffer size: [336]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [unpack_buffer] (0x0100): [RID#68] cmd [241 (auth)] uid [374600500] gid [374600513] validate [true] enterprise principal [true] offline [false] UPN [admin@DC.TEST]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [unpack_buffer] (0x0100): [RID#68] ccname: [FILE:/tmp/krb5cc_374600500] old_ccname: [FILE:/tmp/krb5cc_374600500] keytab: [not set]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [check_keytab_name] (0x0400): [RID#68] Missing krb5_keytab option for domain, looking for default one<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [check_keytab_name] (0x0400): [RID#68] krb5_kt_default_name() returned: FILE:/etc/krb5.keytab<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [check_keytab_name] (0x0400): [RID#68] krb5_child will default to: /etc/krb5.keytab<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [check_use_fast] (0x0100): [RID#68] Not using FAST.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [switch_creds] (0x0200): [RID#68] Switch user to [374600500][374600513].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [switch_creds] (0x0200): [RID#68] Switch user to [0][0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [k5c_check_old_ccache] (0x4000): [RID#68] Ccache_file is [FILE:/tmp/krb5cc_374600500] and is not active and TGT is&nbsp; valid.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [k5c_precreate_ccache] (0x4000): [RID#68] Recreating ccache<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [switch_creds] (0x0200): [RID#68] Switch user to [0][0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [switch_creds] (0x0200): [RID#68] Already user [0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [main] (0x2000): [RID#68] Running as [0][0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [set_lifetime_options] (0x0100): [RID#68] Renewable lifetime is set to [7d # Самопродление тикета, значение определяет максимальное время жизни тикета]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [set_lifetime_options] (0x0100): [RID#68] Lifetime is set to [24h # Срок действия билета истекает каждые 24ч и его можно непрерывно продлевать в течение 7 дней]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [set_canonicalize_option] (0x0100): [RID#68] Canonicalization is set to [true]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [main] (0x0400): [RID#68] Will perform auth<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [main] (0x0400): [RID#68] Will perform online auth<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [tgt_req_child] (0x1000): [RID#68] Attempting to get a TGT<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [get_and_save_tgt] (0x4000): [RID#68] Found Smartcard credentials, trying pkinit.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [get_pkinit_identity] (0x4000): [RID#68] Got [RuToken][/usr/lib64/librtpkcs11ecp.so].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [get_pkinit_identity] (0x4000): [RID#68] Using pkinit identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:token=RuToken:certid=74652D5275546F6B656E2D37393232653939632D636566392D346135652D613539372D3433316362336161353638395F45:certlabel=te-RuToken-7922e99c-cef9-4a5e-a597-431cb3aa5689_E].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [get_and_save_tgt] (0x0400): [RID#68] Attempting kinit for realm [DC.TEST]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_responder] (0x4000): [RID#68] Got question [pkinit].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [answer_pkinit] (0x4000): [RID#68] [0] Identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:slotid=1:token=RuToken] flags [0].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [answer_pkinit] (0x4000): [RID#68] Setting pkinit_prompting.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [pkinit_identity_matches] (0x4000): [RID#68] Found [module_name=/usr/lib64/librtpkcs11ecp.so] in identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:slotid=1:token=RuToken].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [pkinit_identity_matches] (0x4000): [RID#68] Found [token=RuToken] in identity [PKCS11:module_name=/usr/lib64/librtpkcs11ecp.so:slotid=1:token=RuToken].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_prompter] (0x4000): [RID#68] sss_krb5_prompter name [(null)] banner [(null)] num_prompts [1] EINVAL.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_prompter] (0x4000): [RID#68] Prompt [0][Password for admin\@DC.TEST@DC.TEST].<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_prompter] (0x0200): [RID#68] Prompter interface isn&#039;t used for password prompts by SSSD.<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [sss_krb5_get_init_creds_password] (0x0020): [RID#68] 1932: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />********************** BACKTRACE DUMP ENDS HERE *********************************</p><p>(2023-05-22 18:08:15): [krb5_child[11269]] [get_and_save_tgt] (0x0020): [RID#68] 2009: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />(2023-05-22 18:08:15): [krb5_child[11269]] [map_krb5_error] (0x0020): [RID#68] 2138: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />********************** PREVIOUS MESSAGE WAS TRIGGERED BY THE FOLLOWING BACKTRACE:<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [get_and_save_tgt] (0x0020): [RID#68] 2009: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />&nbsp; &nbsp;*&nbsp; (2023-05-22 18:08:15): [krb5_child[11269]] [map_krb5_error] (0x0020): [RID#68] 2138: [-1765328174][Pre-authentication failed: Preauthentication failed]<br />********************** BACKTRACE DUMP ENDS HERE *********************************</p><br /><p>8:15): [pam] [pam_reply] (0x4000): [CID#12] pam_reply initially called with result [7]: Сбой при проверке подлинности. this result might be changed during processing<br />(2023-05-22 18:08:15): [pam] [ldb] (0x10000): [CID#12] Added timed event &quot;ldb_kv_callback&quot;: 0x55cd735280d0</p><p>(2023-05-22 18:08:15): [pam] [ldb] (0x10000): [CID#12] Added timed event &quot;ldb_kv_timeout&quot;: 0x55cd734ef5d0</p><p>(2023-05-22 18:08:15): [pam] [ldb] (0x10000): [CID#12] Running timer event 0x55cd735280d0 &quot;ldb_kv_callback&quot;</p><p>(2023-05-22 18:08:15): [pam] [ldb] (0x10000): [CID#12] Destroying timer event 0x55cd734ef5d0 &quot;ldb_kv_timeout&quot;</p><p>(2023-05-22 18:08:15): [pam] [ldb] (0x10000): [CID#12] Destroying timer event 0x55cd735280d0 &quot;ldb_kv_callback&quot;</p><p>(2023-05-22 18:08:15): [pam] [pam_reply] (0x0200): [CID#12] blen: 24<br />(2023-05-22 18:08:15): [pam] [pam_reply] (0x0200): [CID#12] Returning [7]: Сбой при проверке подлинности to the client<br />(2023-05-22 18:08:15): [pam] [client_recv] (0x0200): [CID#12] Client disconnected!<br />(2023-05-22 18:08:15): [pam] [client_close_fn] (0x2000): [CID#12] Terminated client [0x55cd734fe1d0][24]<br />(2023-05-22 18:08:17): [pam] [pam_initgr_cache_remove] (0x2000): [CID#12] [admin] removed from PAM initgroup cache</p><br /><p><strong>p11_child.log</strong><br />(2023-05-22 18:08:11): [p11_child[11263]] [main] (0x0400): [CID#12] p11_child started.<br />(2023-05-22 18:08:11): [p11_child[11263]] [main] (0x2000): [CID#12] Running in [pre-auth] mode.<br />(2023-05-22 18:08:11): [p11_child[11263]] [main] (0x2000): [CID#12] Running with effective IDs: [0][0].<br />(2023-05-22 18:08:11): [p11_child[11263]] [main] (0x2000): [CID#12] Running with real IDs [0][0].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Module List:<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] common name: [p11-kit-trust].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] dll name: [/usr/lib64/pkcs11/p11-kit-trust.so].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Description [/etc/pki/ca-trust/source] Manufacturer [PKCS#11 Kit] flags [1] removable [false] token present [true].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Description [/usr/share/pki/ca-trust-source] Manufacturer [PKCS#11 Kit] flags [1] removable [false] token present [true].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] common name: [jcPKCS11].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] dll name: [/usr/lib64/librtpkcs11ecp.so].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Description [SafeNet eToken 5100 [Main Interface] 00 00] Manufacturer [] flags [6] removable [true] token present [false].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Description [Aktiv Rutoken lite 01 00] Manufacturer [] flags [7] removable [true] token present [true].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Token label [RuToken].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Found [RuToken] in slot [Aktiv Rutoken lite 01 00][1] of module [1][/usr/lib64/librtpkcs11ecp.so].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Login NOT required.<br />(2023-05-22 18:08:12): [p11_child[11263]] [read_certs] (0x4000): [CID#12] found cert[{EE76FDC1-C248-4318-B831-DE726CAF1A0D}][/DC=test/DC=dc/CN=dc-WIN-QIUURAQ5IN8-CA]<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_ocsp] (0x0020): [CID#12] No OCSP URL in certificate and no default responder defined, skipping OCSP check.<br />(2023-05-22 18:08:12): [p11_child[11263]] [read_certs] (0x4000): [CID#12] found cert[te-RuToken-7922e99c-cef9-4a5e-a597-431cb3aa5689_E][/DC=test/DC=dc/CN=Users/CN=admin]<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_ocsp] (0x0020): [CID#12] No OCSP URL in certificate and no default responder defined, skipping OCSP check.<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] (null) /usr/lib64/librtpkcs11ecp.so (null) RuToken (null) - no label given- 74652D5275546F6B656E2D37393232653939632D636566392D346135652D613539372D3433316362336161353638395F45.<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] uri: pkcs11:library-description=Rutoken%20ECP%20PKCS%20%2311%20library;library-manufacturer=Aktiv%20Co.;library-version=2.7;slot-description=Aktiv%20Rutoken%20lite%2001%2000;slot-manufacturer=;slot-id=1;model=Rutoken%20lite;manufacturer=Aktiv%20Co.;serial=41937396;token=RuToken;id=%74%65%2D%52%75%54%6F%6B%65%6E%2D%37%39%32%32%65%39%39%63%2D%63%65%66%39%2D%34%61%35%65%2D%61%35%39%37%2D%34%33%31%63%62%33%61%61%35%36%38%39%5F%45;object=te-RuToken-7922e99c-cef9-4a5e-a597-431cb3aa5689_E;type=cert.<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] (null) /usr/lib64/librtpkcs11ecp.so (null) RuToken (null) - no label given- 7B42454642373841412D383941372D344332352D413938432D4643434238344334333636387D.<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] uri: pkcs11:library-description=Rutoken%20ECP%20PKCS%20%2311%20library;library-manufacturer=Aktiv%20Co.;library-version=2.7;slot-description=Aktiv%20Rutoken%20lite%2001%2000;slot-manufacturer=;slot-id=1;model=Rutoken%20lite;manufacturer=Aktiv%20Co.;serial=41937396;token=RuToken;id=%7B%42%45%46%42%37%38%41%41%2D%38%39%41%37%2D%34%43%32%35%2D%41%39%38%43%2D%46%43%43%42%38%34%43%34%33%36%36%38%7D;object=%7BEE76FDC1-C248-4318-B831-DE726CAF1A0D%7D;type=cert.<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Found certificate has key id [74652D5275546F6B656E2D37393232653939632D636566392D346135652D613539372D3433316362336161353638395F45].<br />(2023-05-22 18:08:12): [p11_child[11263]] [do_card] (0x4000): [CID#12] Found certificate has key id [7B42454642373841412D383941372D344332352D413938432D4643434238344334333636387D].</p>]]></description>
			<author><![CDATA[null@example.com (savel_97)]]></author>
			<pubDate>Tue, 23 May 2023 06:22:02 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/20637/#p20637</guid>
		</item>
	</channel>
</rss>
