用户密码已过期,在 freeipa web 中过期后重置。用户收到channel 0: open failed: administratively prohibited: open failed
stdio forwarding failed
错误,无法进入主机。我已经尝试unlock
从门户网站访问用户,我已经在sss_cache
. 除了密码没有任何改变。我无法绕过这个错误。
这是安全日志
Feb 26 09:15:36 xxxx-mng-bh-01 sshd[8665]: pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=a.b.c.d user=serverfault
Feb 26 09:15:36 xxxx-mng-bh-01 sshd[8665]: pam_sss(sshd:auth): received for user serverfault: 12 (Authentication token is no longer valid; new one required)
Feb 26 09:15:36 xxxx-mng-bh-01 sshd[8665]: Accepted password for serverfault from a.b.c.d port 63562 ssh2
Feb 26 09:15:37 xxxx-mng-bh-01 sshd[8665]: pam_unix(sshd:session): session opened for user serverfault by (uid=0)
Feb 26 09:15:37 xxxx-mng-bh-01 sshd[8665]: pam_unix(sshd:session): session closed for user serverfault
此消息 (
administratively prohibited
) 由 OpenSSH 发出。有两种情况可以从服务器端发出:sshd_config
(PermitOpen
选项)sshd_config
配置中不允许或禁用 tcp 转发(AllowTcpForwarding
例如选项)无论如何,它与 FreeIPA 和密码过期无关。