Bug 15727 - net ad join fails with "Failed to join domain: failed to create kerberos keytab"
Summary: net ad join fails with "Failed to join domain: failed to create kerberos keytab"
Status: RESOLVED FIXED
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Tools (show other bugs)
Version: 4.21.0
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Jule Anger
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-09-27 11:12 UTC by Noel Power
Modified: 2025-06-05 15:41 UTC (History)
2 users (show)

See Also:


Attachments
4.22 patch (7.99 KB, patch)
2025-03-10 13:33 UTC, Pavel Filipenský
asn: review+
Details
4.21 patch (7.99 KB, patch)
2025-03-10 13:34 UTC, Pavel Filipenský
asn: review+
Details
4.22 patch (1.40 KB, patch)
2025-04-23 19:25 UTC, Pavel Filipenský
metze: review+
Details
4.21 patch (1.40 KB, patch)
2025-04-23 19:26 UTC, Pavel Filipenský
metze: review+
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Noel Power 2024-09-27 11:12:16 UTC

    
Comment 1 Noel Power 2024-10-18 09:11:16 UTC
on a to be joined system (with no pre-existing /etc/krb5.keytab)

joining to windows AD now fails (where previously it would succeed)


KRB5_CONFIG=/tmp/YaST2-22963-aVzKaP/krb5.conf net ads join  -s /tmp/YaST2-22963-aVzKaP/smb.conf 

e.g.

pw2kt_process_add_info: Failed to parse principal: RestrictedKrbHost/TW2024
Failed to join domain: failed to create kerberos keytab

where krb5.conf & smb.conf are minimal config (provided as part of yast2 to provision a windows client)


krb5.conf

[realms]
	SOMETESTDOMAIN1.MY.COM = {
	kdc = SomeWinDC.sometestdomain1.my.com
	}
Comment 2 Noel Power 2024-10-18 09:13:15 UTC
but... it appears adding section



[libdefaults]
	default_realm = SOMETESTDOMAIN1.MY.COM


to krb5.conf fixes the problem.
Comment 3 Rowland Penny 2024-10-19 08:33:16 UTC
(In reply to Noel Power from comment #2)

I can remember testing (quite a few years ago) just what was required in /etc/krb5.conf and it turned out it was just that, you do not need the '[realms]' part.

Also, since when did yast run on a Windows machine ?
Comment 4 Samba QA Contact 2025-03-09 00:26:04 UTC
This bug was referenced in samba master:

cf34645050df64d6b8c4fa45394c3feebe691e79
c72554260c950d0ef7652955a59f0f68a026f4f2
Comment 5 Samba QA Contact 2025-03-10 11:10:16 UTC
This bug was referenced in samba master:

5cadaf91bc96cd2a8e0f6bcbd8a212e86b714180
Comment 6 Pavel Filipenský 2025-03-10 13:33:32 UTC
Created attachment 18598 [details]
4.22 patch
Comment 7 Pavel Filipenský 2025-03-10 13:34:01 UTC
Created attachment 18599 [details]
4.21 patch
Comment 8 Pavel Filipenský 2025-03-13 09:04:19 UTC
Jule, please integrate the 4.21 and 4.22 patches.
Comment 9 Jule Anger 2025-03-13 15:28:12 UTC
Pushed to autobuild-v4-{22,21}-test.
Comment 10 Samba QA Contact 2025-03-13 16:59:30 UTC
This bug was referenced in samba v4-21-test:

c0e3cabdb70fe8950813dc083b159cbe72571996
92253a4708b0b0b529df9aa1c97242babce2165c
d7ac6062d61b7d620860dd7e97691edf1c2acd36
Comment 11 Samba QA Contact 2025-03-13 17:07:22 UTC
This bug was referenced in samba v4-22-test:

3849e7abe6d7b1724ae6ab285e25c22086525d3f
83c60df6e8dd604c4954e1b444b8d2332dbff62b
f8f85cf8533824e0c3fae7e4cac363c692f249c5
Comment 12 Jule Anger 2025-03-20 09:53:59 UTC
Closing out bug report.

Thanks!
Comment 13 Samba QA Contact 2025-03-31 14:49:53 UTC
This bug was referenced in samba v4-21-stable (Release samba-4.21.5):

c0e3cabdb70fe8950813dc083b159cbe72571996
92253a4708b0b0b529df9aa1c97242babce2165c
d7ac6062d61b7d620860dd7e97691edf1c2acd36
Comment 14 Samba QA Contact 2025-04-17 17:15:01 UTC
This bug was referenced in samba v4-22-stable (Release samba-4.22.1):

3849e7abe6d7b1724ae6ab285e25c22086525d3f
83c60df6e8dd604c4954e1b444b8d2332dbff62b
f8f85cf8533824e0c3fae7e4cac363c692f249c5
Comment 15 Samba QA Contact 2025-04-23 12:15:03 UTC
This bug was referenced in samba master:

b5bd36dfd7dfd9a09a3f9378330df3be9db4551f
Comment 16 Pavel Filipenský 2025-04-23 19:25:48 UTC
Created attachment 18636 [details]
4.22 patch
Comment 17 Pavel Filipenský 2025-04-23 19:26:49 UTC
Created attachment 18637 [details]
4.21 patch
Comment 18 Pavel Filipenský 2025-04-28 07:09:27 UTC
Jule, please integrate the 4.21 and 4.22 patches.
Comment 19 Jule Anger 2025-04-30 12:23:35 UTC
Pushed to autobuild-v4-{22,21}-test.
Comment 20 Samba QA Contact 2025-04-30 16:43:03 UTC
This bug was referenced in samba v4-21-test:

8743dd673afaea23683ce5f82a33b67909b4de73
Comment 21 Samba QA Contact 2025-05-08 12:55:04 UTC
This bug was referenced in samba v4-22-test:

c9064d2372bff87bbf79c1ee05588a5d71f067c0
Comment 22 Jule Anger 2025-05-08 13:00:00 UTC
Closing out bug report.

Thanks!
Comment 23 Samba QA Contact 2025-06-03 06:50:16 UTC
This bug was referenced in samba v4-21-stable (Release samba-4.21.6):

8743dd673afaea23683ce5f82a33b67909b4de73
Comment 24 Samba QA Contact 2025-06-05 15:41:29 UTC
This bug was referenced in samba v4-22-stable (Release samba-4.22.2):

c9064d2372bff87bbf79c1ee05588a5d71f067c0