LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 06-24-2019, 02:34 PM   #1
quqonlik
LQ Newbie
 
Registered: Jun 2019
Posts: 6

Rep: Reputation: Disabled
Active directory issue with CentOS 7


Can someone suggest anything? I cloned the server from existing one which we use LDAP and AD authentication but cloned server is not syncing with AD anymore. I tried to rejoin it but after rejoining my exsiting username no longer exist. Also I see the following:

SSSD status active but:
sssd[be[adserver.com]][15170]: Backend is offline


sssd_pam log:

[sssd[pam]] [sss_dp_get_reply] (0x0010): The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Offline]


SSSD conf file:

[sssd]
domains = adserver.com
config_file_version = 2
services = nss, pam

[domain/adserver.com]
ad_domain = adserver.com.com
krb5_realm = ADSERVER.COM
realmd_tags = manages-system joined-with-samba
cache_credentials = True
id_provider = ad
krb5_store_password_if_offline = True
default_shell = /bin/bash
ldap_sasl_authid = test-b8-devsub$
ldap_id_mapping = True
use_fully_qualified_names = False
fallback_homedir = /home/%u
access_provider = ad
[pam]


Any suggestion or resolution appreciated!

Thank you,

Last edited by quqonlik; 06-24-2019 at 04:08 PM.
 
Old 06-25-2019, 06:20 AM   #2
dc.901
Senior Member
 
Registered: Aug 2018
Location: Atlanta, GA - USA
Distribution: CentOS/RHEL, openSuSE/SLES, Ubuntu
Posts: 1,005

Rep: Reputation: 370Reputation: 370Reputation: 370Reputation: 370
Quote:
Originally Posted by quqonlik View Post
Can someone suggest anything? I cloned the server from existing one which we use LDAP and AD authentication but cloned server is not syncing with AD anymore.
So, after cloning the machine, did you rename the clone? Or, do you have now two machines with same name?
If the clone was renamed, does the AD Object exists? If you do not know ask your AD admin.

Quote:
Originally Posted by quqonlik View Post
I tried to rejoin it but after rejoining my exsiting username no longer exist.
How exactly did you do that? Can you show which commands you ran?

What is the OS? Did you check syslog, and event logs on your AD server?
 
Old 06-25-2019, 08:34 AM   #3
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Moderator Response

Moved: This thread is more suitable in <CentOS> and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 06-25-2019, 09:48 AM   #4
quqonlik
LQ Newbie
 
Registered: Jun 2019
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by dc.901 View Post
So, after cloning the machine, did you rename the clone? Or, do you have now two machines with same name?
If the clone was renamed, does the AD Object exists? If you do not know ask your AD admin.
Quote:
Originally Posted by dc.901 View Post

Yes, I renamed hostname and all config parameters. The clone was done through vmware. I checked Active Directory server and I do see joined host "test-b8-devsub"

How exactly did you do that? Can you show which commands you ran?

realm join -v --computer-name=ADSERVER.COM --user=me_admin adserver.com

Output:

Using short domain name -- ADSERVER.COM
Joined 'test-b8-devsub' to dns domain 'adserver.com'
No DNS domain configured for ddil-t8-devsub. Unable to perform DNS Update.
* LANG=C LOGNAME=root /usr/bin/net -s /var/cache/realmd/realmd-smb-conf -U me_admin ads keytab create
Enter me_admin's password:
* /usr/bin/systemctl enable sssd.service
Created symlink from /etc/systemd/system/multi-user.target.wants/sssd.service to /usr/lib/systemd/system/sssd.service.
* /usr/bin/systemctl restart sssd.service
* /usr/bin/sh -c /usr/sbin/authconfig --update --enablesssd --enablesssdauth --enablemkhomedir --nostart && /usr/bin/systemctl enable oddjobd.service && /usr/bin/systemctl start oddjobd.service
* Successfully enrolled machine in realm



What is the OS? Did you check syslog, and event logs on your AD server?


Cloned server is CentOS 7. I haven't check the logs from AD side yet. I tried to rejoining the host it joins fines but tells no userexists when I tried to switch to my ad admin existing user.
 
Old 06-25-2019, 10:09 AM   #5
quqonlik
LQ Newbie
 
Registered: Jun 2019
Posts: 6

Original Poster
Rep: Reputation: Disabled
I found the root cause. Selinux and firewalld were causing the connecting between AD and Linux host. Turning them off fixed the issue.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to join ubnutu system with active directory also login into active directory user mani25288 Linux - Server 2 07-10-2017 09:56 AM
LXer: Setting Up An Active/Active Samba CTDB Cluster Using GFS & DRBD (CentOS 5.5) LXer Syndicated Linux News 0 12-03-2010 10:00 AM
Username & Password Sync Fedora Directory and Microsoft Active Directory karnac01 Fedora 4 07-19-2010 12:51 AM
Fedora Directory Server sync Active Directory paul_mat Linux - Networking 8 03-08-2007 10:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 10:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration