Bug 2028207
| Summary: | realm join fail without info using --membership-software=samba | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Chino Soliard <csoliard> |
| Component: | samba | Assignee: | Andreas Schneider <asn> |
| Status: | CLOSED DUPLICATE | QA Contact: | sssd-qe <sssd-qe> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.5 | CC: | aboscatt, asn, aymeric.marchal, cilmar, dkarpele, gdeschner, jarrpa, sbose |
| Target Milestone: | rc | Flags: | pm-rhel:
mirror+
|
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-01-26 10:24:48 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
Hi, there should be a coredump of the net command, please ask the customer for the coredump or at least for output of 'coredumpctl dump' (assuming the crash of the net command is the latest). For the latter it would be good to install Samba's debuginfo packages. bye, Sumit Sumit, I've the following from journalctl: Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Loaded settings from: /usr/lib/realmd/realmd-defaults.conf /usr/lib/realmd/realmd-distro.conf Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: holding daemon: startup Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: starting service Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: connected to bus Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: released daemon: startup Dec 21 15:07:32 pmstweb01l-hu dbus-daemon[1010]: [system] Successfully activated service 'org.freedesktop.realmd' Dec 21 15:07:32 pmstweb01l-hu systemd[1]: Started Realm and Domain Configuration. Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: claimed name on bus: org.freedesktop.realmd Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: client using service: :1.32 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: holding daemon: :1.32 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Using 'r234.6292' operation for method 'Discover' invocation on 'org.freedesktop.realmd.Provider' interface Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Registered cancellable for operation 'r234.6292' Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Resolving: _ldap._tcp.tribalgroup.net Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Resolving: _ldap._tcp.tribalgroup.net Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.11 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.11 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Error resolving “ldap-dr.tribalgroup.net”: Name or service not known Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Error resolving “AUS-CLD-DC2.tribalgroup.net”: Name or service not known Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.203.50.10 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.203.50.10 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.10 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.10 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Searching for (objectClass=*) Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Got defaultNamingContext: DC=tribalgroup,DC=net Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Sending TCP Netlogon request Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Searching for (objectClass=*) Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Searching for (objectClass=*) Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: Received TCP Netlogon response Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Successfully discovered: tribalgroup.net Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: * Successfully discovered: tribalgroup.net Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: client gone away: :1.32 Dec 21 15:07:32 pmstweb01l-hu realmd[6295]: released daemon: :1.32 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: client using service: :1.34 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: holding daemon: :1.34 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Using 'r245.6300' operation for method 'Discover' invocation on 'org.freedesktop.realmd.Provider' interface Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Registered cancellable for operation 'r245.6300' Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Resolving: _ldap._tcp.tribalgroup.net Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Resolving: _ldap._tcp.tribalgroup.net Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.215.0.20 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.215.0.20 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.11 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.202.50.11 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.203.50.10 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Performing LDAP DSE lookup on: 10.203.50.10 Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Searching for (objectClass=*) Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Searching for (objectClass=*) Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Got defaultNamingContext: DC=tribalgroup,DC=net Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Sending TCP Netlogon request Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Got defaultNamingContext: DC=tribalgroup,DC=net Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Sending TCP Netlogon request Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: Received TCP Netlogon response Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Successfully discovered: tribalgroup.net Dec 21 15:07:43 pmstweb01l-hu realmd[6295]: * Successfully discovered: tribalgroup.net Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: Using 'r245.6300' operation for method 'Join' invocation on 'org.freedesktop.realmd.KerberosMembership' interface Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: Registered cancellable for operation 'r245.6300' Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: holding daemon: current-invocation Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.X3AYE1 -U sv_pdldap -k ads join tribalgroup.net createcomputer=Member_Servers/Hessle/Linux Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.X3AYE1 -U sv_pdldap -k ads join tribalgroup.net createcomputer=Member_Servers/Hessle/Linux Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: process started: 6303 Dec 21 15:07:50 pmstweb01l-hu kernel: net[6303]: segfault at 0 ip 00007f4ce397ff04 sp 00007ffd20c32ae8 error 4 in libsamba-util.so.0.0.1[7f4ce395c000+71000] Dec 21 15:07:50 pmstweb01l-hu kernel: Code: 32 ff ff ff 48 8d 3d d8 23 00 00 31 c0 e8 84 85 fe ff e9 1f ff ff ff e8 da 85 fe ff 66 2e 0f 1f 84 00 00 00 00 00 f3 0f 1e fa <f3> 0f 6f 06 0f 11 47 08 f3 0f 6f 4e 10 0f b7 06 0f 11 4f 18 f3 0f Dec 21 15:07:50 pmstweb01l-hu systemd[1]: Created slice system-systemd\x2dcoredump.slice. Dec 21 15:07:50 pmstweb01l-hu systemd[1]: Started Process Core Dump (PID 6305/UID 0). Dec 21 15:07:50 pmstweb01l-hu systemd-coredump[6306]: Resource limits disable core dumping for process 6303 (net). Dec 21 15:07:50 pmstweb01l-hu systemd-coredump[6306]: Process 6303 (net) of user 0 dumped core. Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: process exited: 6303 Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: Enter sv_pdldap's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: Enter sv_pdldap's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: released daemon: current-invocation Dec 21 15:07:50 pmstweb01l-hu systemd[1]: systemd-coredump: Succeeded. Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: client gone away: :1.34 Dec 21 15:07:50 pmstweb01l-hu realmd[6295]: released daemon: :1.34 Dec 21 15:08:51 pmstweb01l-hu realmd[6295]: quitting realmd service after timeout Dec 21 15:08:51 pmstweb01l-hu realmd[6295]: stopping service Dec 21 15:08:51 pmstweb01l-hu systemd[1]: realmd.service: Succeeded. Is that helpful? Hi,
please try to add a systemd config snippet /usr/lib/systemd/system/realmd.service.d/core_limit.conf which contains:
[Service]
LimitCORE=infinity
and call
systemctl daemon-reload
systemctl stop realmd.service
The next time realmd is called there should be no core dump limit anymore.
HTH
bye,
Sumit
*** This bug has been marked as a duplicate of bug 2035528 *** |
Description of problem: In RHEL8.5, when following the following KCS: How to configure a Samba server with SSSD in RHEL with Winbind handling AD Join [*] https://access.redhat.com/solutions/3802321 The command... realm join domain.net --user=administrator --client-software=sssd --membership-software=samba ... fails giving no details. After some test, we can isolate the issue to the following version: - RHEL8.5 - samba.4.14.5-2.el8.x86_64 The same problem is *not* present in: - RHEL8.4 - samba.4.14.5-2.el8.x86_64 As a workaround, the solution is to downgrade to: - samba.4.13.3-4.el8_4.x86_64 And this also downgrade other packages. ________________________________________________________________________ Version-Release number of selected component (if applicable): libipa_hbac x86_64 2.5.2-2.el8_5.1 libsmbclient x86_64 4.14.5-2.el8 libsss_certmap x86_64 2.5.2-2.el8_5.1 libsss_idmap x86_64 2.5.2-2.el8_5.1 libsss_nss_idmap x86_64 2.5.2-2.el8_5.1 libtevent x86_64 0.11.0-0.el8 libwbclient x86_64 4.14.5-2.el8 python3-sssdconfig noarch 2.5.2-2.el8_5.1 samba x86_64 4.14.5-2.el8 samba-client-libs x86_64 4.14.5-2.el8 samba-common noarch 4.14.5-2.el8 samba-common-libs x86_64 4.14.5-2.el8 samba-common-tools x86_64 4.14.5-2.el8 samba-libs x86_64 4.14.5-2.el8 samba-winbind x86_64 4.14.5-2.el8 samba-winbind-modules x86_64 4.14.5-2.el8 sssd x86_64 2.5.2-2.el8_5.1 sssd-ad x86_64 2.5.2-2.el8_5.1 sssd-client x86_64 2.5.2-2.el8_5.1 sssd-common x86_64 2.5.2-2.el8_5.1 sssd-common-pac x86_64 2.5.2-2.el8_5.1 sssd-ipa x86_64 2.5.2-2.el8_5.1 sssd-kcm x86_64 2.5.2-2.el8_5.1 sssd-krb5 x86_64 2.5.2-2.el8_5.1 sssd-krb5-common x86_64 2.5.2-2.el8_5.1 sssd-ldap x86_64 2.5.2-2.el8_5.1 sssd-proxy x86_64 2.5.2-2.el8_5.1 sssd-winbind-idmap x86_64 2.5.2-2.el8_5.1 How reproducible: Following the KCS, after step 2 (installing requried packages). Steps to Reproduce: 1. Yum update; yum install (the required packages -smb,sssd,etc.-) # yum install realmd oddjob oddjob-mkhomedir sssd adcli samba samba-winbind krb5-workstation 2. Attemt a realm join using --membership-software=samba # realm -vvv join domain.net --user=administrator --client-software=sssd --membership-software=samba Actual results: # realm -vvv join domain.net --user=administrator --client-software=sssd --membership-software=samba * Resolving: _ldap._tcp.domain.net * Performing LDAP DSE lookup on: 10.2.10.10 * Performing LDAP DSE lookup on: 10.4.10.10 * Performing LDAP DSE lookup on: 10.5.10.10 * Successfully discovered: domain.net Password for administrador: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.3XH1D1 -U sv_pdldap -k ads join domain.net createcomputer=example_group/example/linux Enter administrador's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 realm: Couldn't join realm: Failed to enroll machine in realm. See diagnostics. Please check https://red.ht/support_rhel_ad to get help for common issues. Expected results: "Successful joined the domain" Additional info: I asked the customer to reproduce the entire process so you have the evidence and the packages version: ___________________________________________________________________________________________________________________________________________________________________________________ [1] Yum update; yum install (the required packages -smb,sssd,etc.-) ___________________________________________________________________________________________________________________________________________________________________________________ [root@hostname ~]# yum install realmd oddjob oddjob-mkhomedir sssd adcli samba samba-winbind krb5-workstation Updating Subscription Management repositories. Last metadata expiration check: 2:21:01 ago on Tue 30 Nov 2021 05:40:19 GMT. Package realmd-0.16.3-23.el8.x86_64 is already installed. Package oddjob-0.34.7-1.el8.x86_64 is already installed. Package oddjob-mkhomedir-0.34.7-1.el8.x86_64 is already installed. Package sssd-2.4.0-9.el8_4.2.x86_64 is already installed. Package adcli-0.8.2-12.el8.x86_64 is already installed. Package samba-4.13.3-4.el8_4.x86_64 is already installed. Package samba-winbind-4.13.3-4.el8_4.x86_64 is already installed. Package krb5-workstation-1.18.2-14.el8.x86_64 is already installed. Dependencies resolved. ==================================================================================================================================================================================== Package Architecture Version Repository Size ==================================================================================================================================================================================== Upgrading: libipa_hbac x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 115 k libsmbclient x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 147 k libsss_certmap x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 155 k libsss_idmap x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 120 k libsss_nss_idmap x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 127 k libtevent x86_64 0.11.0-0.el8 rhel-8-for-x86_64-baseos-rpms 50 k libwbclient x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 121 k python3-sssdconfig noarch 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 142 k samba x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 847 k samba-client-libs x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 5.4 M samba-common noarch 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 220 k samba-common-libs x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 173 k samba-common-tools x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 499 k samba-libs x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 169 k samba-winbind x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 556 k samba-winbind-modules x86_64 4.14.5-2.el8 rhel-8-for-x86_64-baseos-rpms 129 k sssd x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 107 k sssd-ad x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 270 k sssd-client x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 205 k sssd-common x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 1.6 M sssd-common-pac x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 178 k sssd-ipa x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 347 k sssd-kcm x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 254 k sssd-krb5 x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 150 k sssd-krb5-common x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 185 k sssd-ldap x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 208 k sssd-proxy x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 147 k sssd-winbind-idmap x86_64 2.5.2-2.el8_5.1 rhel-8-for-x86_64-baseos-rpms 104 k Transaction Summary ==================================================================================================================================================================================== Upgrade 28 Packages Total download size: 13 M Is this ok [y/N]: y Downloading Packages: (1/28): libtevent-0.11.0-0.el8.x86_64.rpm 164 kB/s | 50 kB 00:00 (2/28): samba-common-tools-4.14.5-2.el8.x86_64.rpm 1.5 MB/s | 499 kB 00:00 ... omitted (26/28): sssd-common-2.5.2-2.el8_5.1.x86_64.rpm 5.7 MB/s | 1.6 MB 00:00 (27/28): libsss_certmap-2.5.2-2.el8_5.1.x86_64.rpm 1.0 MB/s | 155 kB 00:00 (28/28): samba-libs-4.14.5-2.el8.x86_64.rpm 716 kB/s | 169 kB 00:00 ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Total 6.1 MB/s | 13 MB 00:02 Running transaction check Transaction check succeeded. Running transaction test Transaction test succeeded. Running transaction Preparing : 1/1 Running scriptlet: libtevent-0.11.0-0.el8.x86_64 1/1 Upgrading : libtevent-0.11.0-0.el8.x86_64 1/56 ... omitted Running scriptlet: libipa_hbac-2.4.0-9.el8_4.2.x86_64 56/56 Running scriptlet: libwbclient-4.14.5-2.el8.x86_64 56/56 Running scriptlet: sssd-common-2.5.2-2.el8_5.1.x86_64 56/56 Running scriptlet: libipa_hbac-2.4.0-9.el8_4.2.x86_64 56/56 Verifying : libtevent-0.11.0-0.el8.x86_64 1/56 Verifying : libtevent-0.10.2-2.el8.x86_64 2/56 ... omitted Verifying : libsss_certmap-2.5.2-2.el8_5.1.x86_64 55/56 Verifying : libsss_certmap-2.4.0-9.el8_4.2.x86_64 56/56 Installed products updated. Upgraded: libipa_hbac-2.5.2-2.el8_5.1.x86_64 libsmbclient-4.14.5-2.el8.x86_64 libsss_certmap-2.5.2-2.el8_5.1.x86_64 libsss_idmap-2.5.2-2.el8_5.1.x86_64 libsss_nss_idmap-2.5.2-2.el8_5.1.x86_64 libtevent-0.11.0-0.el8.x86_64 libwbclient-4.14.5-2.el8.x86_64 python3-sssdconfig-2.5.2-2.el8_5.1.noarch samba-4.14.5-2.el8.x86_64 samba-client-libs-4.14.5-2.el8.x86_64 samba-common-4.14.5-2.el8.noarch samba-common-libs-4.14.5-2.el8.x86_64 samba-common-tools-4.14.5-2.el8.x86_64 samba-libs-4.14.5-2.el8.x86_64 samba-winbind-4.14.5-2.el8.x86_64 samba-winbind-modules-4.14.5-2.el8.x86_64 sssd-2.5.2-2.el8_5.1.x86_64 sssd-ad-2.5.2-2.el8_5.1.x86_64 sssd-client-2.5.2-2.el8_5.1.x86_64 sssd-common-2.5.2-2.el8_5.1.x86_64 sssd-common-pac-2.5.2-2.el8_5.1.x86_64 sssd-ipa-2.5.2-2.el8_5.1.x86_64 sssd-kcm-2.5.2-2.el8_5.1.x86_64 sssd-krb5-2.5.2-2.el8_5.1.x86_64 sssd-krb5-common-2.5.2-2.el8_5.1.x86_64 sssd-ldap-2.5.2-2.el8_5.1.x86_64 sssd-proxy-2.5.2-2.el8_5.1.x86_64 sssd-winbind-idmap-2.5.2-2.el8_5.1.x86_64 Complete! ___________________________________________________________________________________________________________________________________________________________________________________ [2] realm -vvv (this should fail) ___________________________________________________________________________________________________________________________________________________________________________________ [root@hostname ~]# realm -vvv join domain.net --computer-ou="ou=linux,ou=group,ou=example_group,dc=domain,dc=net" --user=administrator --client-software=sssd --membership-software=samba * Resolving: _ldap._tcp.domain.net * Performing LDAP DSE lookup on: 10.2.10.10 * Performing LDAP DSE lookup on: 10.4.10.10 * Performing LDAP DSE lookup on: 10.5.10.10 * Successfully discovered: domain.net Password for administrator: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.3XH1D1 -U administrator -k ads join domain.net createcomputer=example_group/group/linux Enter administrator's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 realm: Couldn't join realm: Failed to enroll machine in realm. See diagnostics. Please check https://red.ht/support_rhel_ad to get help for common issues. ___________________________________________________________________________________________________________________________________________________________________________________ [3] the output for the "journalctl REALMD_OPERATION=**" suggested by previous command. ___________________________________________________________________________________________________________________________________________________________________________________ Nov 30 08:20:58 hostname realmd[655495]: Loaded settings from: /usr/lib/realmd/realmd-defaults.conf /usr/lib/realmd/realmd-distro.conf Nov 30 08:20:58 hostname realmd[655495]: holding daemon: startup Nov 30 08:20:58 hostname realmd[655495]: starting service Nov 30 08:20:58 hostname realmd[655495]: connected to bus Nov 30 08:20:58 hostname realmd[655495]: released daemon: startup Nov 30 08:20:58 hostname realmd[655495]: claimed name on bus: org.freedesktop.realmd Nov 30 08:20:58 hostname realmd[655495]: client using service: :1.47220 Nov 30 08:20:58 hostname realmd[655495]: holding daemon: :1.47220 Nov 30 08:20:58 hostname realmd[655495]: Using 'r983933.655492' operation for method 'Discover' invocation on 'org.freedesktop.realmd.Provider' interface Nov 30 08:20:58 hostname realmd[655495]: Registered cancellable for operation 'r983933.655492' Nov 30 08:20:58 hostname realmd[655495]: * Resolving: _ldap._tcp.domain.net Nov 30 08:20:58 hostname realmd[655495]: * Resolving: _ldap._tcp.domain.net Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.2.10.10 Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.2.10.10 Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.5.10.10 Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.5.10.10 Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.5.10.10 Nov 30 08:20:58 hostname realmd[655495]: * Performing LDAP DSE lookup on: 10.5.10.10 Nov 30 08:20:58 hostname realmd[655495]: Searching for (objectClass=*) Nov 30 08:20:58 hostname realmd[655495]: Got defaultNamingContext: DC=domain,DC=net Nov 30 08:20:58 hostname realmd[655495]: Sending TCP Netlogon request Nov 30 08:20:58 hostname realmd[655495]: Received TCP Netlogon response Nov 30 08:20:58 hostname realmd[655495]: * Successfully discovered: domain.net Nov 30 08:20:58 hostname realmd[655495]: * Successfully discovered: domain.net Nov 30 08:21:06 hostname realmd[655495]: Using 'r983933.655492' operation for method 'Join' invocation on 'org.freedesktop.realmd.KerberosMembership' interface Nov 30 08:21:06 hostname realmd[655495]: Registered cancellable for operation 'r983933.655492' Nov 30 08:21:06 hostname realmd[655495]: holding daemon: current-invocation Nov 30 08:21:06 hostname realmd[655495]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Nov 30 08:21:06 hostname realmd[655495]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Nov 30 08:21:06 hostname realmd[655495]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7EQGD1 -U administrator -k ads join domain.net createcomput> Nov 30 08:21:06 hostname realmd[655495]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7EQGD1 -U administrator -k ads join domain.net createcomput> Nov 30 08:21:06 hostname realmd[655495]: process started: 655499 Nov 30 08:21:06 hostname realmd[655495]: process exited: 655499 Nov 30 08:21:06 hostname realmd[655495]: Enter administrator's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 Nov 30 08:21:06 hostname realmd[655495]: Enter administrator's password: ! Failed to enroll machine in realm: Process was terminated with signal: 11 Nov 30 08:21:06 hostname realmd[655495]: released daemon: current-invocation Nov 30 08:21:06 hostname realmd[655495]: client gone away: :1.47220 Nov 30 08:21:06 hostname realmd[655495]: released daemon: :1.47220 ___________________________________________________________________________________________________________________________________________________________________________________ [4] Downgrade the packages (yum install samba.4.13.3-4) ___________________________________________________________________________________________________________________________________________________________________________________ [root@hostname ~]# yum install samba-4.13.3-4.el8_4 Updating Subscription Management repositories. Last metadata expiration check: 2:46:50 ago on Tue 30 Nov 2021 05:40:19 GMT. Dependencies resolved. ==================================================================================================================================================================================== Package Architecture Version Repository Size ==================================================================================================================================================================================== Downgrading: libipa_hbac x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 111 k libsmbclient x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 146 k libsss_certmap x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 150 k libsss_idmap x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 116 k libsss_nss_idmap x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 122 k libwbclient x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 120 k python3-sssdconfig noarch 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 137 k samba x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 846 k samba-client-libs x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 5.4 M samba-common noarch 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 218 k samba-common-libs x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 172 k samba-common-tools x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 498 k samba-libs x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 168 k samba-winbind x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 554 k samba-winbind-modules x86_64 4.13.3-4.el8_4 rhel-8-for-x86_64-baseos-rpms 126 k sssd x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 102 k sssd-ad x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 273 k sssd-client x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 197 k sssd-common x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 1.6 M sssd-common-pac x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 177 k sssd-ipa x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 358 k sssd-kcm x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 236 k sssd-krb5 x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 145 k sssd-krb5-common x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 186 k sssd-ldap x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 222 k sssd-proxy x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 145 k sssd-winbind-idmap x86_64 2.4.0-9.el8_4.2 rhel-8-for-x86_64-baseos-rpms 100 k Transaction Summary ==================================================================================================================================================================================== Downgrade 27 Packages Total download size: 13 M Is this ok [y/N]: y Downloading Packages: (1/27): libsmbclient-4.13.3-4.el8_4.x86_64.rpm 621 kB/s | 146 kB 00:00 (2/27): samba-libs-4.13.3-4.el8_4.x86_64.rpm 705 kB/s | 168 kB 00:00 ... omitted (26/27): python3-sssdconfig-2.4.0-9.el8_4.2.noarch.rpm 604 kB/s | 137 kB 00:00 (27/27): sssd-winbind-idmap-2.4.0-9.el8_4.2.x86_64.rpm 496 kB/s | 100 kB 00:00 ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Total 5.7 MB/s | 13 MB 00:02 Running transaction check Transaction check succeeded. Running transaction test Transaction test succeeded. Running transaction Preparing : 1/1 Running scriptlet: libsss_idmap-2.4.0-9.el8_4.2.x86_64 1/1 Downgrading : libsss_idmap-2.4.0-9.el8_4.2.x86_64 1/54 Running scriptlet: libsss_idmap-2.4.0-9.el8_4.2.x86_64 1/54 Running scriptlet: samba-common-4.13.3-4.el8_4.noarch 2/54 Downgrading : samba-common-4.13.3-4.el8_4.noarch 2/54 Running scriptlet: samba-common-4.13.3-4.el8_4.noarch 2/54 ... omitted Running scriptlet: libsss_certmap-2.5.2-2.el8_5.1.x86_64 53/54 Cleanup : libipa_hbac-2.5.2-2.el8_5.1.x86_64 54/54 Running scriptlet: libipa_hbac-2.5.2-2.el8_5.1.x86_64 54/54 Running scriptlet: libwbclient-4.13.3-4.el8_4.x86_64 54/54 Running scriptlet: sssd-common-2.4.0-9.el8_4.2.x86_64 54/54 Running scriptlet: libipa_hbac-2.5.2-2.el8_5.1.x86_64 54/54 Verifying : samba-4.13.3-4.el8_4.x86_64 1/54 Verifying : samba-4.14.5-2.el8.x86_64 2/54 Verifying : samba-libs-4.13.3-4.el8_4.x86_64 3/54 ... omitted Verifying : python3-sssdconfig-2.5.2-2.el8_5.1.noarch 52/54 Verifying : sssd-winbind-idmap-2.4.0-9.el8_4.2.x86_64 53/54 Verifying : sssd-winbind-idmap-2.5.2-2.el8_5.1.x86_64 54/54 Installed products updated. Downgraded: libipa_hbac-2.4.0-9.el8_4.2.x86_64 libsmbclient-4.13.3-4.el8_4.x86_64 libsss_certmap-2.4.0-9.el8_4.2.x86_64 libsss_idmap-2.4.0-9.el8_4.2.x86_64 libsss_nss_idmap-2.4.0-9.el8_4.2.x86_64 libwbclient-4.13.3-4.el8_4.x86_64 python3-sssdconfig-2.4.0-9.el8_4.2.noarch samba-4.13.3-4.el8_4.x86_64 samba-client-libs-4.13.3-4.el8_4.x86_64 samba-common-4.13.3-4.el8_4.noarch samba-common-libs-4.13.3-4.el8_4.x86_64 samba-common-tools-4.13.3-4.el8_4.x86_64 samba-libs-4.13.3-4.el8_4.x86_64 samba-winbind-4.13.3-4.el8_4.x86_64 samba-winbind-modules-4.13.3-4.el8_4.x86_64 sssd-2.4.0-9.el8_4.2.x86_64 sssd-ad-2.4.0-9.el8_4.2.x86_64 sssd-client-2.4.0-9.el8_4.2.x86_64 sssd-common-2.4.0-9.el8_4.2.x86_64 sssd-common-pac-2.4.0-9.el8_4.2.x86_64 sssd-ipa-2.4.0-9.el8_4.2.x86_64 sssd-kcm-2.4.0-9.el8_4.2.x86_64 sssd-krb5-2.4.0-9.el8_4.2.x86_64 sssd-krb5-common-2.4.0-9.el8_4.2.x86_64 sssd-ldap-2.4.0-9.el8_4.2.x86_64 sssd-proxy-2.4.0-9.el8_4.2.x86_64 sssd-winbind-idmap-2.4.0-9.el8_4.2.x86_64 Complete! ___________________________________________________________________________________________________________________________________________________________________________________ [5] realm -vvv (this should work) ___________________________________________________________________________________________________________________________________________________________________________________ [root@hostname ~]# realm -vvv join domain.net --computer-ou="ou=linux,ou=group,ou=example_group,dc=domain,dc=net" --user=administrator --client-software=sssd --membership-software=samba * Resolving: _ldap._tcp.domain.net * Performing LDAP DSE lookup on: 10.5.10.10 * Performing LDAP DSE lookup on: 10.2.10.10 * Performing LDAP DSE lookup on: 10.3.10.10 * Successfully discovered: domain.net Password for administrator: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator -k ads join domain.net createcomputer=example_group/group/linux Enter administrator's password: Using short domain name -- DOMAIN Joined 'hostname' to dns domain 'domain.net' * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator ads keytab create Enter administrator's password: ! Failed to update Kerberos configuration, not fatal, please check manually: Setting attribute standard::type not supported * /usr/bin/systemctl enable sssd.service Created symlink /etc/systemd/system/multi-user.target.wants/sssd.service → /usr/lib/systemd/system/sssd.service. * /usr/bin/systemctl restart sssd.service * /usr/bin/sh -c /usr/bin/authselect select sssd with-mkhomedir --force && /usr/bin/systemctl enable oddjobd.service && /usr/bin/systemctl start oddjobd.service Backup stored at /var/lib/authselect/backups/2021-11-30-08-30-28.Af9X8Y Profile "sssd" was selected. The following nsswitch maps are overwritten by the profile: - passwd - group - netgroup - automount - services Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. - with-mkhomedir is selected, make sure pam_oddjob_mkhomedir module is present and oddjobd service is enabled and active - systemctl enable --now oddjobd.service * Successfully enrolled machine in realm ___________________________________________________________________________________________________________________________________________________________________________________ [6] If available/possible, the output for the "journalctl REALMD_OPERATION=**" suggested by previous command. ___________________________________________________________________________________________________________________________________________________________________________________ Nov 30 08:30:26 hostname realmd[656623]: Using 'r984496.656630' operation for method 'Join' invocation on 'org.freedesktop.realmd.KerberosMembership' interface Nov 30 08:30:26 hostname realmd[656623]: Registered cancellable for operation 'r984496.656630' Nov 30 08:30:26 hostname realmd[656623]: holding daemon: current-invocation Nov 30 08:30:26 hostname realmd[656623]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Nov 30 08:30:26 hostname realmd[656623]: * Required files: /usr/sbin/oddjobd, /usr/libexec/oddjob/mkhomedir, /usr/sbin/sssd, /usr/bin/net Nov 30 08:30:26 hostname realmd[656623]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator -k ads join domain.net createcomput> Nov 30 08:30:26 hostname realmd[656623]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator -k ads join domain.net createcomput> Nov 30 08:30:26 hostname realmd[656623]: process started: 656633 Nov 30 08:30:27 hostname realmd[656623]: Enter administrator's password: Nov 30 08:30:27 hostname realmd[656623]: Enter administrator's password: Nov 30 08:30:27 hostname realmd[656623]: Using short domain name -- DOMAIN Nov 30 08:30:27 hostname realmd[656623]: Using short domain name -- DOMAIN Nov 30 08:30:27 hostname realmd[656623]: Joined 'hostname' to dns domain 'domain.net' Nov 30 08:30:27 hostname realmd[656623]: Joined 'hostname' to dns domain 'domain.net' Nov 30 08:30:27 hostname realmd[656623]: process exited: 656633 Nov 30 08:30:27 hostname realmd[656623]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator ads keytab create Nov 30 08:30:27 hostname realmd[656623]: * LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.YJ0MD1 -U administrator ads keytab create Nov 30 08:30:27 hostname realmd[656623]: process started: 656635 Nov 30 08:30:27 hostname realmd[656623]: Enter administrator's password: Nov 30 08:30:27 hostname realmd[656623]: Enter administrator's password: Nov 30 08:30:27 hostname realmd[656623]: process exited: 656635 Nov 30 08:30:27 hostname realmd[656623]: Couldn't set file attributes: /etc/krb5.conf: Setting attribute standard::type not supported Nov 30 08:30:27 hostname realmd[656623]: Couldn't set file attributes: /etc/krb5.conf: Setting attribute standard::type not supported Nov 30 08:30:27 hostname realmd[656623]: ! Failed to update Kerberos configuration, not fatal, please check manually: Setting attribute standard::type not supported Nov 30 08:30:27 hostname realmd[656623]: ! Failed to update Kerberos configuration, not fatal, please check manually: Setting attribute standard::type not supported Nov 30 08:30:27 hostname realmd[656623]: * /usr/bin/systemctl enable sssd.service Nov 30 08:30:27 hostname realmd[656623]: * /usr/bin/systemctl enable sssd.service Nov 30 08:30:27 hostname realmd[656623]: process started: 656637 Nov 30 08:30:27 hostname systemd[1]: Reloading. Nov 30 08:30:27 hostname realmd[656623]: Created symlink /etc/systemd/system/multi-user.target.wants/sssd.service → /usr/lib/systemd/system/sssd.service. Nov 30 08:30:27 hostname realmd[656623]: Created symlink /etc/systemd/system/multi-user.target.wants/sssd.service → /usr/lib/systemd/system/sssd.service. Nov 30 08:30:28 hostname realmd[656623]: process exited: 656637 Nov 30 08:30:28 hostname realmd[656623]: * /usr/bin/systemctl restart sssd.service Nov 30 08:30:28 hostname realmd[656623]: * /usr/bin/systemctl restart sssd.service Nov 30 08:30:28 hostname realmd[656623]: process started: 656655 Nov 30 08:30:28 hostname systemd[1]: Starting System Security Services Daemon... Nov 30 08:30:28 hostname sssd[sssd][656656]: Starting up Nov 30 08:30:28 hostname sssd[be[domain.net]][656658]: Starting up Nov 30 08:30:28 hostname sssd[be[implicit_files]][656657]: Starting up Nov 30 08:30:28 hostname sssd[nss][656659]: Starting up Nov 30 08:30:28 hostname sssd[pam][656660]: Starting up Nov 30 08:30:28 hostname systemd[1]: Started System Security Services Daemon. Nov 30 08:30:28 hostname realmd[656623]: process exited: 656655 Nov 30 08:30:28 hostname realmd[656623]: * /usr/bin/sh -c /usr/bin/authselect select sssd with-mkhomedir --force && /usr/bin/systemctl enable oddjobd.service && /usr/bin/sys> Nov 30 08:30:28 hostname realmd[656623]: * /usr/bin/sh -c /usr/bin/authselect select sssd with-mkhomedir --force && /usr/bin/systemctl enable oddjobd.service && /usr/bin/sys> Nov 30 08:30:28 hostname systemd[1]: Reached target User and Group Name Lookups. Nov 30 08:30:28 hostname realmd[656623]: process started: 656662 Nov 30 08:30:28 hostname realmd[656623]: Backup stored at /var/lib/authselect/backups/2021-11-30-08-30-28.Af9X8Y Nov 30 08:30:28 hostname realmd[656623]: Backup stored at /var/lib/authselect/backups/2021-11-30-08-30-28.Af9X8Y Nov 30 08:30:28 hostname realmd[656623]: Profile "sssd" was selected. Nov 30 08:30:28 hostname realmd[656623]: Profile "sssd" was selected. Nov 30 08:30:28 hostname realmd[656623]: The following nsswitch maps are overwritten by the profile: Nov 30 08:30:28 hostname realmd[656623]: The following nsswitch maps are overwritten by the profile: Nov 30 08:30:28 hostname realmd[656623]: - passwd Nov 30 08:30:28 hostname realmd[656623]: - passwd Nov 30 08:30:28 hostname realmd[656623]: - group Nov 30 08:30:28 hostname realmd[656623]: - group Nov 30 08:30:28 hostname realmd[656623]: - netgroup Nov 30 08:30:28 hostname realmd[656623]: - netgroup Nov 30 08:30:28 hostname realmd[656623]: - automount Nov 30 08:30:28 hostname realmd[656623]: - automount Nov 30 08:30:28 hostname realmd[656623]: - services Nov 30 08:30:28 hostname realmd[656623]: - services Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname realmd[656623]: Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. Nov 30 08:30:28 hostname realmd[656623]: Make sure that SSSD service is configured and enabled. See SSSD documentation for more information. Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname realmd[656623]: - with-mkhomedir is selected, make sure pam_oddjob_mkhomedir module Nov 30 08:30:28 hostname realmd[656623]: - with-mkhomedir is selected, make sure pam_oddjob_mkhomedir module Nov 30 08:30:28 hostname realmd[656623]: is present and oddjobd service is enabled and active Nov 30 08:30:28 hostname realmd[656623]: is present and oddjobd service is enabled and active Nov 30 08:30:28 hostname realmd[656623]: - systemctl enable --now oddjobd.service Nov 30 08:30:28 hostname realmd[656623]: - systemctl enable --now oddjobd.service Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname realmd[656623]: Nov 30 08:30:28 hostname systemd[1]: Reloading. Nov 30 08:30:28 hostname realmd[656623]: process exited: 656662 Nov 30 08:30:28 hostname realmd[656623]: * Successfully enrolled machine in realm Nov 30 08:30:28 hostname realmd[656623]: * Successfully enrolled machine in realm Nov 30 08:30:28 hostname realmd[656623]: released daemon: current-invocation Nov 30 08:30:28 hostname realmd[656623]: client gone away: :1.47234 Nov 30 08:30:28 hostname realmd[656623]: released daemon: :1.47234 Nov 30 08:30:38 hostname sssd[656656]: ; TSIG error with server: tsig verify failure Nov 30 08:30:38 hostname sssd[656656]: update failed: REFUSED Nov 30 08:30:38 hostname sssd[656656]: ; TSIG error with server: tsig verify failure Nov 30 08:30:38 hostname sssd[656656]: update failed: REFUSED Nov 30 08:31:28 hostname realmd[656623]: quitting realmd service after timeout Nov 30 08:31:28 hostname realmd[656623]: stopping service Nov 30 08:31:28 hostname systemd[1]: realmd.service: Succeeded.