-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-9.1.0
-
adcli-0.9.3.1-1.el10
-
None
-
Low
-
rhel-idm-sssd
-
ssg_idm
-
None
-
False
-
False
-
-
No
-
None
-
Pass
-
Automated
-
Bug Fix
-
-
Done
-
Done
-
Done
-
-
Unspecified
-
None
-
57,005
Description of problem:
After successful joining to domain:
adcli join ... adwin.renesas.com
I receive this Kerberos keytab:
[root@slsrvadm-02v ~]# klist -k
Keytab name: FILE:/etc/krb5.keytab
KVNO Principal
---- --------------------------------------------------------------------------
2 slsrvadm-02v2$@ADWIN.RENESAS.COM
2 host/slsrvadm-02v2@ADWIN.RENESAS.COM
2 slsrvadm-02v2$@ADWIN.RENESAS.COM
2 host/slsrvadm-02v2@ADWIN.RENESAS.COM
2 host/slsrvadm-02v.diasemi.com@ADWIN.RENESAS.COM
2 RestrictedKrbHost/slsrvadm-02v2@ADWIN.RENESAS.COM
2 host/slsrvadm-02v.diasemi.com@ADWIN.RENESAS.COM
2 RestrictedKrbHost/slsrvadm-02v2@ADWIN.RENESAS.COM
2 RestrictedKrbHost/slsrvadm-02v.diasemi.com@ADWIN.RENESAS.COM
2 RestrictedKrbHost/slsrvadm-02v.diasemi.com@ADWIN.RENESAS.COM
... however 'adcli testjoin' complains about 'diasemi.com' domain which I did not join:
[root@slsrvadm-02v ~]# adcli testjoin
adcli: couldn't connect to diasemi.com domain: Couldn't get kerberos ticket for machine account: slsrvadm-02v2: Realm not local to KDC
Please check
https://red.ht/support_rhel_ad
to get help for common issues.
and as per the man page, I can't supply domain name to adcli testjoin
- external trackers
- links to
-
RHBA-2025:157535
adcli update