[SOLVED] RE: [External] - Re: Issues getting Kerberos to work with realmd and Active Directory

2020-07-30 Thread Wesley Taylor
Thank you all for your responses. Fortunately for me, just running klist and picking the UPN form got me past this issue, but if I run into any issues in the future I will employ those other solutions. I appreciate the help! -Wes Public Content -Original Message- From: Simo Sorce

Re: Issues getting Kerberos to work with realmd and Active Directory

2020-07-30 Thread Simo Sorce
Wesley, when joining hosts to AD a computer account is created and a UPN and SPNs are set on it. Unlike MIT kerberos in AD heavy use of aliases is employed so each host have a "host password/key" that is shared with all the aliases created. Most notably there are the UPN, generally of the form

Re: Issues getting Kerberos to work with realmd and Active Directory

2020-07-30 Thread Greg Hudson
On 7/30/20 1:00 PM, Wesley Taylor wrote: > I am confused because when I run 'adcli update --verbose' it says it updated > the keytab at /etc/krb5.keytab and outputs the same account name (which I am > assuming is the principal for the computer) as adcli testjoin. I am really > scratching my

Issues getting Kerberos to work with realmd and Active Directory

2020-07-30 Thread Wesley Taylor
Hi All, I am trying to get HTCondor with Kerberos authentication (https://htcondor.readthedocs.io/en/stable/admin-manual/security.html?highlight=Kerberos#kerberos-authentication) to work on some linux machines I have which I joined to Windows Active Directory with realmd. HTCondor tries to