SSSD Login Fails After Patch

I recently updated a Fedora 22 workstation and SSSD logins began to fail.

Logs look good until sss_send_pac fails. Oddly the principal user is getting the domain added twice. For example:


I'm not sure what debuggin steps to take at this point. Joining the realm and performing ldapsearch commands are all successful.

Authentication is provided by an Active Directory system on a larger Windows-based network.

When I step up logging output in sssd.conf to level 10 I can review the krb5_child.log. I find the following failure in the log:

(Thu Dec 3 09:22:36 2015) [[sssd[krb5_child[2158]]]] [sss_send_pac] (0x0040): sss_pac_make_request failed [-1][2]

(Thu Dec 3 09:22:36 2015) [[sssd[krb5_child[2158]]]] [validate_tgt] (0x0040): sss_send_pac failed, group membership for user with principal [jgiotta\@magic.local@magic.local] might not be correct.

When this occurs I believe login fails, but terminal only says "System error" at login. At this moment, I'm essentially locked out of my profile and can only access via root.

