[Freeipa-users] ipa trust-add using password

Troels Hansen th at casalogic.dk
Fri Sep 16 08:42:32 UTC 2016


Hi, we are having some issues creating a IPA-AD trust, using password, and not shared secret, because of the error where name routing not getting created on AD if using shared secret. 

We have a AD domain tree with a top level domain and a domain below that where the users are located. We try to join the top level domain as a trust exists between those tow domains. 

Everything worked in our test setup, where we joined using a shared secret. 

We try to join our AD using this command: 
ipa trust-add <ROOT REALM> --type=ad --admin <DOMAIN MASTER USER> @<REALM> --password 

However, we receive one of these two error messages: 

ipa: ERROR: CIFS server communication error: code "- 1073741712 ", 
message "Invalid workstation" (both may be "None") 

ipa: ERROR: AD domain controller complains about communication 
sequence. It may mean unsynchronized time on both sides, for example 

I think the first message was caused by some login restrictions on the user used to join, as it seems we don't receive that error massage anymore, and we receive the second error every time we try to join. 

We have tried pointing it to a specific server with the "--server" option, but that didn't change anything. 


-- 


Med venlig hilsen 

Troels Hansen 

Systemkonsulent 

Casalogic A/S 


T (+45) 70 20 10 63 

M (+45) 22 43 71 57 

Red Hat, SUSE, VMware, Citrix, Novell, Yellowfin BI, EnterpriseDB, Sophos og meget mere. 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20160916/77f10ca2/attachment.htm>


More information about the Freeipa-users mailing list