| Summary: | net ads join generated host keytab contains dysfunctional principals | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Marko Myllynen <myllynen> |
| Component: | samba | Assignee: | Guenther Deschner <gdeschner> |
| Status: | CLOSED DUPLICATE | QA Contact: | qe-baseos-daemons |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 6.2 | CC: | dpal, gdeschner, ondrejv, prc, sbose |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-11-24 09:22:46 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Marko Myllynen
2011-10-26 10:06:57 UTC
I believe that the "Client not found in Kerberos database" message means that there is no UPN defined in AD by that name. Locate the "client-123" computer object in AD and set its "userPrincipalName" attribute to "host/CLIENT-123.COM". You can go back to your linux box and verify that "kinit -k host/CLIENT-123" works now. Note that I can also confirm that the workaround you mentioned works for me, too. (In reply to comment #2) > I believe that the "Client not found in Kerberos database" message means that > there is no UPN defined in AD by that name. Correct, indeed a better test is to use kvno: # kvno 'host/client-123.ad.example.com.COM' kvno: Server not found in Kerberos database while getting credentials for host/client-123.ad.example.com.COM # kvno 'host/CLIENT-123.COM' host/CLIENT-123.COM: kvno = 2 # kvno 'CLIENT-123$@AD.EXAMPLE.COM' CLIENT-123$@AD.EXAMPLE.COM: kvno = 2 Since RHEL 6.2 External Beta has begun, and this bug remains unresolved, it has been rejected as it is not proposed as exception or blocker. Red Hat invites you to ask your support representative to propose this request, if appropriate and relevant, in the next release of Red Hat Enterprise Linux. This is caused by the issues related to bug 748831 - when the join completes normally all the principals are as expected. Closing this one, further discussion can go to bug 748831. Thanks. *** This bug has been marked as a duplicate of bug 748831 *** |