Bug 1258488
Summary: | Join to AD with adcli and defined computer-ou fails | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Patrik Kis <pkis> |
Component: | realmd | Assignee: | Sumit Bose <sbose> |
Status: | CLOSED ERRATA | QA Contact: | Patrik Kis <pkis> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 7.2 | CC: | ebenes, ovasik, peljasz, pkis, sbose, stefw |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | realmd-0.16.1-6.el7 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-11-04 07:46:26 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Patrik Kis
2015-08-31 13:28:33 UTC
NOTE, that in realmd-0.16.1-3.el7 adcli become the default membership software so this issue might be more visible. Changing the target release to RHEL-7.2, but leave the decision to fix/postpone to devel as the issue is not that critical and have a en easy workaround (--membership-software=samba). The adcli command line is incorrect. The adcli documentation states: -O, --domain-ou=OU=xxx The full distinguished name of the OU in which to create the computer account. If not specified then the computer account will be created in a default location. In other words, an argument like OU=TestOU is an incomplete OU. If you are driving adcli directly, please specify the full OU, like this: OU=TestOU,DC=example,DC=com So workaround for this is to specify a full DN to the realm client --computer-ou command. So I think this is a realmd bug. It should perform the qualification automatically before handing it off to adcli. Fixed upstream here: http://cgit.freedesktop.org/realmd/realmd/commit/?id=3db35ad73ec57c8af499a0dcef96ffd4da914236 it would be nice to have it fixed, more than half a year later and admins still bog down there. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2511.html |