Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Description of problem:
We started doing regression runs for SSSD on RHEL7.4 and discovered that all of our AD tests failed. Looking into the logs, the client failed to join the domain and is unable to create a keytab.
-- Logs begin at Fri 2017-03-10 12:46:51 EST, end at Fri 2017-03-10 17:53:27 EST. --
Mar 10 17:53:08 test.sssd.com realmd[12360]: * Resolving: _ldap._tcp.sssd.com
Mar 10 17:53:08 test.sssd.com realmd[12360]: * Performing LDAP DSE lookup on: 10.12.0.160
Mar 10 17:53:08 test.sssd.com realmd[12360]: * Performing LDAP DSE lookup on: 2620:52:0:c00:8d03:6469:ac47:1740
Mar 10 17:53:08 test.sssd.com realmd[12360]: * Performing LDAP DSE lookup on: 10.12.0.159
Mar 10 17:53:08 test.sssd.com realmd[12360]: * Successfully discovered: sssd.com
Mar 10 17:53:12 test.sssd.com realmd[12360]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net
Mar 10 17:53:12 test.sssd.com realmd[12360]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.LI91WY -U Administrator ads join sssd
Mar 10 17:53:18 test.sssd.com realmd[12360]: Enter Administrator's password:
Mar 10 17:53:18 test.sssd.com realmd[12360]: Failed to join domain: failed to create kerberos keytab
Mar 10 17:53:18 test.sssd.com realmd[12360]: ! Joining the domain sssd.com failed
When adding the --membership-software=adcli to the realm join command it works.
Version-Release number of selected component (if applicable):
How reproducible:
Always
Steps to Reproduce:
1. Join a linux machine to a windows domain by issuing 'realm join -v $DOMAIN'
2.
3.
Actual results:
No keytab is created, SSSD cannot be started.
Expected results:
Keytab is created, SSSD can be started.
Additional info:
I'm creating the ticket here because realmd has not changed since 7.3 while Samba has a new build in 7.4
Comment 2Andreas Schneider
2017-03-13 10:31:26 UTC
Can you please provide the log level 10 output from the 'net' command?
testparm -s /var/cache/realmd/realmd-smb-conf.LI91
and
/usr/bin/net -s /var/cache/realmd/realmd-smb-conf.LI91WY -U Administrator ads join -d10
The cache file are never generated, so the commands are not returning anything.
[root@vm-idm-006 ~]# realm join sssdad2012r2.com
Password for Administrator:
See: journalctl REALMD_OPERATION=r5684.18103
realm: Couldn't join realm: Joining the domain sssdad2012r2.com failed
[root@vm-idm-006 ~]# ls -ltrh /var/cache/realmd/
total 0
Is there anything else I need to do?
Comment 5Andreas Schneider
2017-03-13 16:49:23 UTC
*** This bug has been marked as a duplicate of bug 1430755 ***