Project

General

Profile

Bug #18495

[regression] Not Able to Join Domain

Added by Fabio Rodrigues almost 4 years ago. Updated about 3 years ago.

Status:
Closed: Cannot reproduce
Priority:
Important
Assignee:
Erin Clark
Category:
OS
Target version:
Seen in:
Severity:
New
Reason for Closing:
Reason for Blocked:
Needs QA:
Yes
Needs Doc:
Yes
Needs Merging:
Yes
Needs Automation:
No
Support Suite Ticket:
n/a
Hardware Configuration:
ChangeLog Required:
No

Description

Hello,

I'm unable to join domain on FreeNAS 9.10.1-U2. If I try the same steps on version 9.10.1, it works fine.

In the debug.log there are some errors like:
INSUFF_ACCESS_RIGHTS
AD_join_domain: Failed

I'm using the same account to join the domain in both versions.

Thanks.

History

#1 Avatar?id=14398&size=24x24 Updated by Kris Moore almost 4 years ago

  • Subject changed from Not Able to Join Domain to [regression] Not Able to Join Domain
  • Assignee set to Erin Clark
  • Priority changed from No priority to Important
  • Target version set to 9.10.2

Over to Erin for investigation. If you could post your debug file, that would come in handy as well.

#2 Updated by Fabio Rodrigues almost 4 years ago

  • File debug.log added

Hello Erin,
Here is the debug.log.
Thanks!

#3 Updated by Erin Clark almost 4 years ago

I need the full debug dump, could you go to system > advanced and click save debug then post it here (also mark the ticket private if you don't want it to be exposed to the internet)

#4 Updated by Erin Clark almost 4 years ago

  • Status changed from Unscreened to Screened

#5 Updated by Fabio Rodrigues almost 4 years ago

  • Private changed from No to Yes

#6 Updated by Fabio Rodrigues almost 4 years ago

Hello Erin,
Is there any specific log from the debug dump that you need? Sorry, but I can't send everything for security reasons.
When I try to join the domain I get a message in green in the user interface with this message: "The service failed to restart". I'm not sure, but I think it is related to SMB.
Thanks.

#7 Updated by Fabio Rodrigues almost 4 years ago

I already tried to manually create the AD object and join the domain. Same error.
What I also noticed is that in the server that I'm able to join the domain, the service is CIFS not SMB.

#8 Updated by Fabio Rodrigues almost 4 years ago

I also see errors like that in the log.winbindd file:

[2016/10/25 09:04:06.615890, 0] ../source3/libsmb/cliconnect.c:1895(cli_session_setup_spnego_send)
Kinit for to access failed: Client not found in Kerberos database

[2016/10/24 17:53:22.602483, 0] ../source3/libsmb/cliconnect.c:1895(cli_session_setup_spnego_send)
Kinit for to access failed: Clients credentials have been revoked

#9 Updated by Erin Clark almost 4 years ago

what happens if you delete the kerberos realm then try rebinding? could you post the messages log and the logs from /var/log/smb4?

#10 Updated by Fabio Rodrigues almost 4 years ago

Same error.
I reinstalled 9.10.1 and it works.
9.10.1-U1 also works but I can't create the AD object before trying to join the domain.
9.10.1-U2 is still not working.

#11 Updated by Fabio Rodrigues almost 4 years ago

Erin,
Do you know how powerful the user that we use to add freenas to the domain needs to be?
I'm asking because I was able to add the server to the domain but I had to give more permissions than expected for the account. The account has more permissions than other accounts that we use to add other computers to the domain.
What if I give this permissions to the user, add the server to the domain, and remove the extra permissions. Do you know if that will crash FreeNAS?

#12 Updated by Erin Clark almost 4 years ago

From experience it does seem to need full privileges for binding, however if you are going to try that I would suggest you try binding it, remove extra permissions then see if it stays bound after a reboot.

#13 Updated by Erin Clark almost 4 years ago

Did you ever have any luck with this?

#14 Avatar?id=14398&size=24x24 Updated by Kris Moore almost 4 years ago

  • Status changed from Screened to Closed: Cannot reproduce

Timing out after 4 weeks. If still an issue, please re-open or update ticket.

#15 Updated by Dru Lavigne about 3 years ago

  • File deleted (debug.log)

#16 Updated by Dru Lavigne about 3 years ago

  • Target version changed from 9.10.2 to N/A
  • Private changed from Yes to No

Also available in: Atom PDF