I think this is working in jammy (22.04):

realm 0.17 (to be uploaded)
samba 4.13.14

My client vm:
root@j1:~# hostname -f
j1.internal.example.fake

Server is AD 2016:

join:
root@j1:~# realm join -v --automatic-id-mapping=no --membership-software=samba 
--client-software=winbind internal.example.fake
 * Resolving: _ldap._tcp.internal.example.fake
 * Performing LDAP DSE lookup on: 10.0.16.5
 * Successfully discovered: internal.example.fake
 * Unconditionally checking packages
 * Resolving required packages
 * Installing necessary packages: libnss-winbind samba-common-bin 
libpam-winbind winbind
 * LANG=C LOGNAME=root KRB5CCNAME=/var/cache/realmd/realm-ad-kerberos-B0AOF1 
/usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7B1DF1 -k ads join 
internal.example.fake
Using short domain name -- INTEXAMPLE
Joined 'J1' to dns domain 'internal.example.fake'
 * LANG=C LOGNAME=root KRB5CCNAME=/var/cache/realmd/realm-ad-kerberos-B0AOF1 
/usr/bin/net -s /var/cache/realmd/realmd-smb-conf.7B1DF1 -k ads keytab create
 ! Failed to update Kerberos configuration, not fatal, please check manually: 
Setting attribute standard::type not supported
 * /usr/sbin/update-rc.d winbind enable
 * /usr/sbin/service winbind restart
 * Successfully enrolled machine in realm


keytab (notice the host key has the "internal" domain component):
root@j1:~# klist -ekt
Keytab name: FILE:/etc/krb5.keytab
KVNO Timestamp         Principal
---- ----------------- --------------------------------------------------------
   1 01/10/22 14:56:04 
restrictedkrbhost/[email protected] 
(aes256-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 restrictedkrbhost/[email protected] 
(aes256-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 
restrictedkrbhost/[email protected] 
(aes128-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 restrictedkrbhost/[email protected] 
(aes128-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 
restrictedkrbhost/[email protected] 
(DEPRECATED:arcfour-hmac) 
   1 01/10/22 14:56:04 restrictedkrbhost/[email protected] 
(DEPRECATED:arcfour-hmac) 
   1 01/10/22 14:56:04 host/[email protected] 
(aes256-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 host/[email protected] 
(aes256-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 host/[email protected] 
(aes128-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 host/[email protected] 
(aes128-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 host/[email protected] 
(DEPRECATED:arcfour-hmac) 
   1 01/10/22 14:56:04 host/[email protected] 
(DEPRECATED:arcfour-hmac) 
   1 01/10/22 14:56:04 [email protected] (aes256-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 [email protected] (aes128-cts-hmac-sha1-96) 
   1 01/10/22 14:56:04 [email protected] (DEPRECATED:arcfour-hmac)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1905000

Title:
  realm join DOMAIN (samba) sets wrong krb5.keytab (missing subdomain)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/realmd/+bug/1905000/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to