Bug 1471021 - adcli doesn't update kvno while joining system to AD domain (RODC).
adcli doesn't update kvno while joining system to AD domain (RODC).
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: adcli (Show other bugs)
All Linux
medium Severity medium
: rc
: ---
Assigned To: Sumit Bose
Petr Čech
Aneta Šteflová Petrová
Depends On:
Blocks: 1420851 1472344 1477926 1490412
  Show dependency treegraph
Reported: 2017-07-14 05:32 EDT by Gaurav Swami
Modified: 2018-01-16 04:01 EST (History)
6 users (show)

See Also:
Fixed In Version: adcli-0.8.1-4.el7
Doc Type: Bug Fix
Doc Text:
Kerberos operations depending on KVNO in the keytab file no longer fail when a RODC is used The *adcli* utility did not handle the key version number (KVNO) properly when updating Kerberos keys on a read-only domain controller (RODC). Consequently, some operations, such as validating a Kerberos ticket, failed because no key with a matching KVNO was found in the keytab file. With this update, *adcli* detects if a RODC is used and handles the KVNO accordingly. As a result, the keytab file contains the right KVNO, and all Kerberos operations depending on this behavior work as expected.
Story Points: ---
Clone Of:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)

Note You need to log in before you can comment on or make changes to this bug.