Good Afternoon,

I'm currently in the process of trying to setup PacketFence in a lab 
environment before deploying a setup to production.

We have installed CentOS 7.9.2009 with PacketFence version 10.3.0 without any 
issues and our LAB DC (DC1) is running windows server 2019 with DNS and DHCP 
roles installed.

However we are now attempting to join PacketFence to our LAB.LOCAL domain, but 
are experiencing the below Error message when attempting a join:

kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed for 
ldap/dc1.lab.local with user[USER.NAME] realm[LAB.LOCAL]: No logon servers are 
currently available to service the logon request. kinit succeeded but 
ads_sasl_spnego_gensec_bind(KRB5) failed for ldap/dc1.lab.local with 
user[PACKETFENCE$] realm[LAB.LOCAL]: No logon servers are currently available 
to service the logon request. DNS update failed: NT_STATUS_INVALID_PARAMETER 
Using short domain name -- LAB Joined 'PACKETFENCE' to dns domain 'LAB.LOCAL' 
No DNS domain configured for packetfence. Unable to perform DNS Update.

I can see that the Server gets a Kerberos ticket from the server and even 
creates a computer account, but the rest of the process just will not complete. 
I have even attempted to run 'net ads info' which returns information:

LDAP Server: 192.168.1.3
LDAP Server Name: DC1.LAB.LOCAL
Realm: LAB.LOCAL
Bind Path: dc=LAB,dc=LOCAL
LDAP Port: 389
Server Time: Thu, 22 Jul 2021 15:28:40 BST
KDC Server: 192.168.1.3
Server time offset: -24
Last machine account password change: Thu, 01 Jan 1970 01:00:00 BST

I've checked timezones on both DC and the PacketFence server to which is all 
matches and the servers can communicate via ping.

Can anyone advise how I can further troubleshoot this issue?

Thanks in Advance
Damien.
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to