root@phys-adtest:~# realm -v join -U metro-0omentest@TOU.T3.UCDAVIS.EDU * Resolving: * Performing LDAP DSE lookup on: * Performing LDAP DSE lookup on: * Successfully discovered: tou.T3.UCDAVIS.EDU Password for metro-0omentest@TOU.T3.UCDAVIS.EDU: * Unconditionally checking packages * Resolving required packages * LANG=C /usr/sbin/adcli join --verbose --domain tou.T3.UCDAVIS.EDU --domain-realm TOU.T3.UCDAVIS.EDU --domain-controller --login-type user --login-user metro-0omentest@TOU.T3.UCDAVIS.EDU --stdin-password * Using domain name: tou.T3.UCDAVIS.EDU * Calculated computer account name from fqdn: PHYS-ADTEST * Using domain realm: tou.T3.UCDAVIS.EDU * Sending netlogon pings to domain controller: cldap:// * Received NetLogon info from: TOUDC3C.tou.T3.UCDAVIS.EDU * Wrote out krb5.conf snippet to /var/cache/realmd/adcli-krb5-WUUhHu/krb5.d/adcli-krb5-conf-UMQa9O * Authenticated as user: metro-0omentest@TOU.T3.UCDAVIS.EDU * Looked up short domain name: TOU * Using fully qualified name: phys-adtest * Using domain name: tou.T3.UCDAVIS.EDU * Using computer account name: PHYS-ADTEST * Using domain realm: tou.T3.UCDAVIS.EDU * Calculated computer account name from fqdn: PHYS-ADTEST * Generated 120 character computer password * Using keytab: FILE:/etc/krb5.keytab * Found computer account for PHYS-ADTEST$ at: CN=phys-adtest,OU=METRO-OU-AdminPCS,OU=METRO-OU-Computers,OU=METRO,OU=DEPARTMENTS,DC=tou,DC=T3,DC=UCDAVIS,DC=EDU * Set computer password * Retrieved kvno '3' for computer account in directory: CN=phys-adtest,OU=METRO-OU-AdminPCS,OU=METRO-OU-Computers,OU=METRO,OU=DEPARTMENTS,DC=tou,DC=T3,DC=UCDAVIS,DC=EDU * Modifying computer account: dNSHostName * Modifying computer account: userAccountControl * Modifying computer account: operatingSystem, operatingSystemVersion, operatingSystemServicePack * Modifying computer account: userPrincipalName ! Couldn't set service principals on computer account CN=phys-adtest,OU=METRO-OU-AdminPCS,OU=METRO-OU-Computers,OU=METRO,OU=DEPARTMENTS,DC=tou,DC=T3,DC=UCDAVIS,DC=EDU: 00002083: AtrErr: DSID-03151785, #1: 0: 00002083: DSID-03151785, problem 1006 (ATT_OR_VALUE_EXISTS), data 0, Att 90303 (servicePrincipalName) * Discovered which keytab salt to use * Added the entries to the keytab: PHYS-ADTEST$@TOU.T3.UCDAVIS.EDU: FILE:/etc/krb5.keytab * Added the entries to the keytab: host/PHYS-ADTEST@TOU.T3.UCDAVIS.EDU: FILE:/etc/krb5.keytab * Added the entries to the keytab: host/phys-adtest@TOU.T3.UCDAVIS.EDU: FILE:/etc/krb5.keytab * Added the entries to the keytab: RestrictedKrbHost/PHYS-ADTEST@TOU.T3.UCDAVIS.EDU: FILE:/etc/krb5.keytab * Added the entries to the keytab: RestrictedKrbHost/phys-adtest@TOU.T3.UCDAVIS.EDU: FILE:/etc/krb5.keytab * /usr/sbin/update-rc.d sssd enable update-rc.d: error: cannot find a LSB script for sssd * /usr/sbin/service sssd restart * Successfully enrolled machine in realm