Bug 1840752
| Summary: | No longer able to delete computer from AD using adcli | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | sdaniele3 |
| Component: | adcli | Assignee: | Sumit Bose <sbose> |
| Status: | CLOSED ERRATA | QA Contact: | sssd-qe <sssd-qe> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.8 | CC: | dlavu, pkulkarn, rakkumar, ralston, samoss, sgadekar, sgoveas, tscherf |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | sync-to-jira | ||
| Fixed In Version: | adcli-0.8.1-15.el7 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-09-29 20:20:55 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
sdaniele3
2020-05-27 14:39:02 UTC
Hi, thanks for the ticket and the detailed analysis. I can reproduce the issue and you are right that the failure of adcli_enroll_load() should not be fatal here. The call was added to determine the NetBIOS name of the host from the keytab, but this is only needed in cases where the NetBIOS name is different from the short hostname, so a fatal error is not justified. I will prepare a fix. bye, Sumit Upstream: - 40d3be22f6e518e4354aa7c3d0278291fcbed32f Verified against adcli-0.8.1-15.el7.x86_64 [root@test ~]# klist Ticket cache: KEYRING:persistent:0:0 Default principal: Administrator Valid starting Expires Service principal 06/17/2020 21:19:10 06/18/2020 07:19:10 krbtgt/T2SITE12R79.COM renew until 06/24/2020 21:19:08 [root@test ~]# adcli delete-computer --verbose --domain=t2site12r79.com --login-ccache test * Found realm in keytab: T2SITE12R79.COM * Found computer name in keytab: TEST * Found service principal in keytab: host/TEST * Found service principal in keytab: host/test.t2site12r79.com * Found host qualified name in keytab: test.t2site12r79.com * Found service principal in keytab: RestrictedKrbHost/TEST * Found service principal in keytab: RestrictedKrbHost/test.t2site12r79.com * Found service principal in keytab: nfs/test.t2site12r79.com * Found service principal in keytab: nfs/TEST * Using domain name: t2site12r79.com * Calculated computer account name from fqdn: TEST * Using domain realm: t2site12r79.com * Discovering domain controllers: _ldap._tcp.t2site12r79.com * Sending NetLogon ping to domain controller: secad580.t2site12r79.com * Received NetLogon info from: secad580.t2site12r79.com * Wrote out krb5.conf snippet to /tmp/adcli-krb5-6HuI0y/krb5.d/adcli-krb5-conf-gpVWBH * Using GSS-SPNEGO for SASL bind * Looked up short domain name: T2SITE12R79 * Looked up domain SID: S-1-5-21-462758026-4081404078-1474916236 * Using fully qualified name: test.t2site12r79.com * Using domain name: t2site12r79.com * Using computer account name: TEST * Using domain realm: t2site12r79.com * Not setting fully qualified name * Enrolling computer name: test * Found computer account for test$ at: CN=TEST,OU=Linux,OU=Servers,DC=t2site12r79,DC=com * Deleted computer account at: CN=TEST,OU=Linux,OU=Servers,DC=t2site12r79,DC=com Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (adcli bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:3985 |