Active Directory SSSD keytab generation before starting sssd
Bug #1586967 reported by
Christian Schmitt
This bug affects 7 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu Server Guide |
Confirmed
|
Undecided
|
Andreas Hasenack |
Bug Description
Actually for configuring SSSD on Ubuntu (https:/
The step sudo kinit Administrator and net ads join -k needs to be done before starting sssd.
summary: |
- Active Directory SSSD missing keytab generation + Active Directory SSSD keytab generation before starting sssd |
description: | updated |
Changed in serverguide: | |
status: | New → Confirmed |
Changed in serverguide: | |
assignee: | nobody → Andreas Hasenack (ahasenack) |
To post a comment you must log in.
I came to report same.
The guide states:
sudo systemctl restart ntp.service
sudo systemctl restart smbd.service nmbd.service
sudo systemctl start sssd.service
but
sssd.service depends on the keytab file which is not present until the machine is joined to AD. A user will see this error message:
Jun 17 11:02:17 hostname sssd[be[24166]: Failed to read keytab [default]: No such file or directory
Jun 17 11:02:17 hostname sssd[24158]: Exiting the SSSD. Could not restart critical service [example.com].
The documentation should be:
sudo systemctl restart ntp.service
sudo systemctl restart smbd.service nmbd.service
sudo kinit Administrator
sudo net ads join -k
sudo systemctl start sssd.service