![SSSD를 통해 Windows AD 계정을 사용하여 서버에 로그인할 때 가끔 발생하는 문제](https://linux55.com/image/182428/SSSD%EB%A5%BC%20%ED%86%B5%ED%95%B4%20Windows%20AD%20%EA%B3%84%EC%A0%95%EC%9D%84%20%EC%82%AC%EC%9A%A9%ED%95%98%EC%97%AC%20%EC%84%9C%EB%B2%84%EC%97%90%20%EB%A1%9C%EA%B7%B8%EC%9D%B8%ED%95%A0%20%EB%95%8C%20%EA%B0%80%EB%81%94%20%EB%B0%9C%EC%83%9D%ED%95%98%EB%8A%94%20%EB%AC%B8%EC%A0%9C.png)
서버에 연결된 Windows AD 계정을 사용하여 Windows 원격 데스크톱 관리자를 통해 CentOS7 데스크톱 GUI에 로그인을 시도한 결과 SSSD
...
myuser로 로그인을 시도해
ssh
도 작동하지 않는다는 메시지가 터미널에 표시됩니다...
debug2: we sent a password packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
Permission denied, please try again.
내가 해야 할 일은 ssh
루트로 로그인하고 cd
myuser의 /home 디렉토리로 이동하는 것뿐입니다. 그럼 sssd
상태를 보니 ..
[root@airflowetl ~]# systemctl status sssd
● sssd.service - System Security Services Daemon
Loaded: loaded (/usr/lib/systemd/system/sssd.service; enabled; vendor preset: disabled)
Active: active (running) since Wed 2020-01-22 16:52:28 HST; 9 months 0 days ago
Main PID: 122026 (sssd)
CGroup: /system.slice/sssd.service
├─122026 /usr/sbin/sssd -i --logger=files
├─122027 /usr/libexec/sssd/sssd_be --domain co.local --uid 0 --gid 0 --logger=files
├─122028 /usr/libexec/sssd/sssd_nss --uid 0 --gid 0 --logger=files
└─122029 /usr/libexec/sssd/sssd_pam --uid 0 --gid 0 --logger=files
Oct 22 18:16:52 airflowetl.co.local [sssd[krb5_child[119918]]][119918]: KDC has no support for encryption type
Oct 22 18:16:52 airflowetl.co.local [sssd[krb5_child[119918]]][119918]: KDC has no support for encryption type
Oct 22 18:17:05 airflowetl.co.local [sssd[krb5_child[120064]]][120064]: KDC has no support for encryption type
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 1
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 1
Oct 22 18:17:22 airflowetl.co.local sssd[be[co.local]][122027]: GSSAPI Error: Unspecified GSS failure. Minor code may provid...ype)
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 1
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 1
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 1
Oct 22 18:17:22 airflowetl.co.local sssd_be[122027]: GSSAPI client step 2
Hint: Some lines were ellipsized, use -l to show in full.
내 /etc/sssd.conf
파일은 다음과 같습니다...
[root@airflowetl sssd]# cat sssd.conf
[sssd]
domains = co.local
config_file_version = 2
services = nss, pam
[domain/co.local]
ad_domain = co.local
krb5_realm = CO.LOCAL
auth_provider = ad
access_provider = ad
chpass_provider = ad
realmd_tags = manages-system joined-with-samba
cache_credentials = True
id_provider = ad
krb5_store_password_if_offline = True
default_shell = /bin/bash
ldap_id_mapping = False
ldap_user_uid_number = uidNumber
ldap_user_gid_number = gidNumber
ldap_group_gid_number = gidNumber
use_fully_qualified_names = False
fallback_homedir = /home/%u
access_provider = ad
default_domain_suffix = co.local
더 많은 경험을 가진 사람이 여기서 무슨 일이 일어나고 있는지 알고 있습니까? 디버깅 제안 사항이 있습니까(가끔 발생하고 관련 내용을 모르기 때문에 테스트하기 어렵습니다)?