Unable to login FreeIPA user on windows 11 professional OS

322 Views Asked by At

We have configured a FreeIPA server for user authentication and created user accounts. FreeIPA users were able to log in successfully on Windows 11 Home edition, but issues with logging in on Windows 11 Professional edition. The specific error received on Windows 11 Professional edition is: ''The Security database on the server does not have a computer account for this workstation trust relationship.'' However, the configuration steps followed for both Windows 11 Home and Professional editions are the same. Can anyone suggest a solution to address this problem?

FreeIPA users were able to log in successfully on Windows 11 Home edition, but issues with logging in on Windows 11 Professional edition. The specific error received on Windows 11 Professional edition is: ''The Security database on the server does not have a computer account for this workstation trust relationship.''

2

There are 2 best solutions below

0
abbra On

FreeIPA does not support using Windows systems as domain clients. This is not supported and will not be supported.

I guess what you have with Home edition on Windows is a fallback to Kerberos which is not supposed to happen in home (non-domain) environment and is something that Microsoft does not really test according to my inquiries.

Windows 11 Professional edition ties Kerberos authentication to domain enrollment and since you have not enrolled (and cannot do that) Windows system to FreeIPA, it does not work. As I said, it is not supported and will not be support. The fact that Windows 11 Home edition succeeds with a login is a luck, not a real working solution.

0
Rune Jørgensen On

actually you can join any windows machine to a domain/realm via console and the ksetup program

ksetup /setrealm "FREEIPA domain" ksetup /MapUser * * ksetup /addkpasswd "FREEIPA domain" "FQDN of the freeipa server" ksetup /SetComputerPassword [pw set for the host in freeipa] ksetup /setdomain "FREEIPA domain" ksetup /AddKdc "FREEIPA domain"

make sure DNS has SRV records for the KDC in freeipa