<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't join RedHat IDM Domain in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Can-t-join-RedHat-IDM-Domain/m-p/137137#M24852</link>
    <description>&lt;P&gt;I have exactly the same symptoms - looking at the logs in the KDC server I can see that my admin user (i.e. the user I am using to create the principle and retrieve the keytab) is problematic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/var/log/kadmind.log&lt;/P&gt;&lt;P&gt;Unauthorized request: kadm5_get_principal, nfs/blah@REALM, client=myadminuser@REALM, service=kadmin/admin@REALM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue appears to relate to the privs that a normal user vs an admin user has.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the best option if possible is to create the principal and keytab file using ipa commands on a linux box and to temporarily put it on a webserver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively you may be able to configure IPA to add the relevant privs to your account so it can do that with password auth.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2018 16:15:38 GMT</pubDate>
    <dc:creator>ac123</dc:creator>
    <dc:date>2018-01-08T16:15:38Z</dc:date>
    <item>
      <title>Can't join RedHat IDM Domain</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Can-t-join-RedHat-IDM-Domain/m-p/124415#M22325</link>
      <description>&lt;P&gt;OnCommand 9.0, trying to join an NFS SVM to the RedHat 7.2 IDM Domain and it's failing saying the SPN already exists, which it absolutely doesn't. &amp;nbsp;Just brought up this IDM domain so nothing is joined to it yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried renaming the SVM and joining it with a new name, still get the same SPN already exists failure. &amp;nbsp;We can't do autoFS of user home directories without it joined to the domain supposedly. &amp;nbsp;Any ideas? &amp;nbsp;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;la-6pna01::vserver nfs&amp;gt; kerberos-config modify -vserver la-6pnasvmnfs03 -lif la-6pnasvmnfs02_nfs_lif1 -kerberos enabled -spn nfs/la-6pnasvmnfs03.internal-idm.domain.com@INTERNAL-IDM.DOMAIN.COM -admin-username mdadmin&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;Error: NFS Kerberos bind SPN procedure failed&lt;BR /&gt;[ 0 ms] Creating account in Unix KDC&lt;BR /&gt;[ 43] Successfully connected to ip 10.85.128.8, port 749 using&lt;BR /&gt;TCP&lt;BR /&gt;**[ 52] FAILURE: Unexpected state: Error 1142 at&lt;BR /&gt;** file:src/utils/secd_kadmin_utils.cpp&lt;BR /&gt;** func:createVifKrbAccountUsingKadmin line:219&lt;BR /&gt;**[ 52] FAILURE: spn already exists. Failed to reuse spn&lt;BR /&gt;** 'nfs/la-6pnasvmnfs03.internal-idm.domain.com@INTER&lt;BR /&gt;** NAL-IDM.DOMAIN.COM' using admin spn&lt;BR /&gt;** 'mdadmin@INTERNAL-IDM.DOMAIN.COM', error: Unknown&lt;BR /&gt;** code 0&lt;BR /&gt;[ 53] Uncaptured failure while creating account&lt;/P&gt;&lt;P&gt;Error: command failed: Failed to enable NFS Kerberos on LIF&lt;BR /&gt;"la-6pnasvmnfs02_nfs_lif1". Failed to bind service principal name on LIF&lt;BR /&gt;"la-6pnasvmnfs02_nfs_lif1". cifs smb kadmin error.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 19:42:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Can-t-join-RedHat-IDM-Domain/m-p/124415#M22325</guid>
      <dc:creator>MDiOrio</dc:creator>
      <dc:date>2016-10-19T19:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join RedHat IDM Domain</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Can-t-join-RedHat-IDM-Domain/m-p/137137#M24852</link>
      <description>&lt;P&gt;I have exactly the same symptoms - looking at the logs in the KDC server I can see that my admin user (i.e. the user I am using to create the principle and retrieve the keytab) is problematic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/var/log/kadmind.log&lt;/P&gt;&lt;P&gt;Unauthorized request: kadm5_get_principal, nfs/blah@REALM, client=myadminuser@REALM, service=kadmin/admin@REALM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue appears to relate to the privs that a normal user vs an admin user has.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the best option if possible is to create the principal and keytab file using ipa commands on a linux box and to temporarily put it on a webserver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively you may be able to configure IPA to add the relevant privs to your account so it can do that with password auth.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 16:15:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Can-t-join-RedHat-IDM-Domain/m-p/137137#M24852</guid>
      <dc:creator>ac123</dc:creator>
      <dc:date>2018-01-08T16:15:38Z</dc:date>
    </item>
  </channel>
</rss>

