Bug 1471021 - adcli doesn't update kvno while joining system to AD domain (RODC).
Summary: adcli doesn't update kvno while joining system to AD domain (RODC).
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: adcli
Version: 7.3
Hardware: All
OS: Linux
Target Milestone: rc
: ---
Assignee: Sumit Bose
QA Contact: Petr Čech
Aneta Šteflová Petrová
Depends On:
Blocks: 1420851 1472344 1477926 1490412
TreeView+ depends on / blocked
Reported: 2017-07-14 09:32 UTC by Gaurav Swami
Modified: 2021-09-09 12:26 UTC (History)
6 users (show)

Fixed In Version: adcli-0.8.1-4.el7
Doc Type: Bug Fix
Doc Text:
Kerberos operations depending on KVNO in the keytab file no longer fail when a RODC is used The *adcli* utility did not handle the key version number (KVNO) properly when updating Kerberos keys on a read-only domain controller (RODC). Consequently, some operations, such as validating a Kerberos ticket, failed because no key with a matching KVNO was found in the keytab file. With this update, *adcli* detects if a RODC is used and handles the KVNO accordingly. As a result, the keytab file contains the right KVNO, and all Kerberos operations depending on this behavior work as expected.
Clone Of:
Last Closed: 2018-04-10 18:13:14 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0966 0 None None None 2018-04-10 18:13:30 UTC

Comment 15 errata-xmlrpc 2018-04-10 18:13:14 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.