# FreeIPA Web UI login fails after upgrade to rocky 8

**URL:** <https://forums.rockylinux.org/t/freeipa-web-ui-login-fails-after-upgrade-to-rocky-8/18653>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-8\
**Created:** [June 4, 2025, 1:16pm UTC](https://forums.rockylinux.org/t/freeipa-web-ui-login-fails-after-upgrade-to-rocky-8/18653 "2025-06-04T13:16:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbran](https://avatars.discourse-cdn.com/v4/letter/j/85e7bf/32.png) [@jbran](https://forums.rockylinux.org/u/jbran)\
**Post date:** [June 4, 2025, 1:16pm UTC](https://forums.rockylinux.org/t/freeipa-web-ui-login-fails-after-upgrade-to-rocky-8/18653/1 "2025-06-04T13:16:37Z")

</div>

I’m trying to upgrade an old Centos 7 based FreeIPA setup to run on Rocky Linux 8

The server is installed with the command " ipa-replica-install --principal admin --admin-password ‘xxx’ --setup-dns --setup-ca --setup-kra --forwarder=10.18.38.9" and I didnt notice any errors

All seem to be working fine in the backend as far as I can see (lkinit etc)

But when I try to login to the Web UI the login failes with  
Your session has expired. Please log in again.

Looking at /var/log/httpd/error\_log I can see a the following error when trying to login in

```auto
[Wed Jun 04 15:11:49.072233 2025] [wsgi:error] [pid 2305:tid 139625594136320] [remote 172.17.0.3:44693] ipa: INFO: [jsonserver_i18n_messages] UNKNOWN: i18n_messages(version='2.251'): SUCCESS
[Wed Jun 04 15:11:49.145416 2025] [wsgi:error] [pid 2306:tid 139625594136320] [remote 172.17.0.3:44695] ipa: INFO: 401 Unauthorized: Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Credential cache is empty)
[Wed Jun 04 15:11:49.281768 2025] [wsgi:error] [pid 2306:tid 139625594136320] [remote 172.17.0.3:44695] ipa: INFO: 401 Unauthorized: Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Credential cache is empty)

```

and in /var/log/krb5kdc.log

```auto
Jun 04 15:56:33 ipa02.opr.ngc.dk krb5kdc[2233](info): TGS_REQ (6 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19), aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17), camellia256-cts-cmac(26), camellia128-cts-cmac(25)}) 172.18.38.11: S4U2PROXY_EVIDENCE_TKT_WITHOUT_PAC: authtime 1749045392, etypes {rep=UNSUPPORTED:(0)} HTTP/ipa02.opr.ngc.dk@HPC.NGC.DK for ldap/ipa02.opr.ngc.dk@HPC.NGC.DK, KDC policy rejects request
Jun 04 15:56:33 ipa02.opr.ngc.dk krb5kdc[2233](info): ... CONSTRAINED-DELEGATION s4u-client=<unknown>
Jun 04 15:56:33 ipa02.opr.ngc.dk krb5kdc[2233](info): closing down fd 11

```

edit . ok so I think I have identied the issue on

> **[RHEL-8.9 IdM update, web UI and CLI 401 Unauthorized with KDC...](https://access.redhat.com/solutions/7052125)**
>
> After updating to RHEL-8.9 with IPA packages from 4.9.12-9 to 4.9.12-11+( no errors ), a Kerberos kinit works correctly, but any ipa command line of WebUI access is denied, with an HTTP error 401: /var/log/httpd/error\_log ...ipa: INFO: 401...

which indicated that tis is a uproblem with SIDs and the sollution should be to generate the SIDs with “ipa config-mod --enable-sid --add-sids” buth this command is not valid on my rocky 8.10 server

```auto
# ipa config-mod --enable-sid --add-sids
Usage: ipa [global-options] config-mod [options]

ipa: error: no such option: --enable-sid

```

```auto
# cat /etc/redhat-release
Rocky Linux release 8.10 (Green Obsidian)

# ipa --version
VERSION: 4.9.13, API_VERSION: 2.251

```

Do anyone have an idea how to fix this ?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [June 4, 2025, 4:13pm UTC](https://forums.rockylinux.org/t/freeipa-web-ui-login-fails-after-upgrade-to-rocky-8/18653/2 "2025-06-04T16:13:15Z")

</div>

Did you finish the migration and drop the CentOS 7 system(s)? If you have not, you really need to finish the migration before continuing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [August 3, 2025, 4:14pm UTC](https://forums.rockylinux.org/t/freeipa-web-ui-login-fails-after-upgrade-to-rocky-8/18653/3 "2025-08-03T16:14:06Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
