I think this is working in jammy (22.04): realm 0.17 (to be uploaded) samba 4.13.14
My client vm: root@j1:~# hostname -f j1.internal.example.fake Server is AD 2016: join: root@j1:~# realm join -v --automatic-id-mapping=no --membership-software=samba --client-software=winbind internal.example.fake * Resolving: _ldap._tcp.internal.example.fake * Performing LDAP DSE lookup on: 10.0.16.5 * Successfully discovered: internal.example.fake * Unconditionally checking packages * Resolving required packages * Installing necessary packages: libnss-winbind samba-common-bin libpam-winbind winbind * LANG=C LOGNAME=root KRB5CCNAME=/var/cache/realmd/realm-ad-kerberos-B0AOF1 /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7B1DF1 -k ads join internal.example.fake Using short domain name -- INTEXAMPLE Joined 'J1' to dns domain 'internal.example.fake' * LANG=C LOGNAME=root KRB5CCNAME=/var/cache/realmd/realm-ad-kerberos-B0AOF1 /usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7B1DF1 -k ads keytab create ! Failed to update Kerberos configuration, not fatal, please check manually: Setting attribute standard::type not supported * /usr/sbin/update-rc.d winbind enable * /usr/sbin/service winbind restart * Successfully enrolled machine in realm keytab (notice the host key has the "internal" domain component): root@j1:~# klist -ekt Keytab name: FILE:/etc/krb5.keytab KVNO Timestamp Principal ---- ----------------- -------------------------------------------------------- 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (aes256-cts-hmac-sha1-96) 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (aes256-cts-hmac-sha1-96) 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (aes128-cts-hmac-sha1-96) 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (aes128-cts-hmac-sha1-96) 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (DEPRECATED:arcfour-hmac) 1 01/10/22 14:56:04 restrictedkrbhost/[email protected] (DEPRECATED:arcfour-hmac) 1 01/10/22 14:56:04 host/[email protected] (aes256-cts-hmac-sha1-96) 1 01/10/22 14:56:04 host/[email protected] (aes256-cts-hmac-sha1-96) 1 01/10/22 14:56:04 host/[email protected] (aes128-cts-hmac-sha1-96) 1 01/10/22 14:56:04 host/[email protected] (aes128-cts-hmac-sha1-96) 1 01/10/22 14:56:04 host/[email protected] (DEPRECATED:arcfour-hmac) 1 01/10/22 14:56:04 host/[email protected] (DEPRECATED:arcfour-hmac) 1 01/10/22 14:56:04 [email protected] (aes256-cts-hmac-sha1-96) 1 01/10/22 14:56:04 [email protected] (aes128-cts-hmac-sha1-96) 1 01/10/22 14:56:04 [email protected] (DEPRECATED:arcfour-hmac) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1905000 Title: realm join DOMAIN (samba) sets wrong krb5.keytab (missing subdomain) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/realmd/+bug/1905000/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
