On Fri, Feb 8, 2019 at 10:20 AM Sumit Bose sbose@redhat.com wrote:
I looked at other objects an dit seems none have had the same SPN registered, and I don't know at all how the object is created (other that it is created when I "realm" the server). I will look at it a bit !
There is an issue if realmd uses adcli to join the domain if 'hostname' only returns the short name and not the fully-qualified DNS name. In this case adcli tries to add the same SPN twice which causes an error and as a result no SPN is added.
That would perfectly be it ! Do you think you could include that remark in https://docs.pagure.org/SSSD.sssd/users/ad_provider.html#client-configuratio... ?
Regards,
Jeremy