Dear Community,
I’m having trouble with reaching the KDC server on an Openvpn setup: local UCS-Master (with Samba4), vserver UCS-Slave (without Samba).
The system diagnostic page is showing me two errors
- The KDC isn’t reachable under tcp/udp master.domain.name:88
- Checking Kerberos DNS Updates: Fehler traten auf bei der Ausführung von
kinit
odernsupdate
.
kinit
für den Principal slave-host$ mit der Password Datei /etc/machine.secret ist fehlgeschlagen.
I have tried to fix this by following a renewal todo for /etc/machine.secret
but that went wrong and so I did a rejoin running univention-join
. When I run this command from the UCS-slave I get an initial fail and a success on the second try. After I rejoin the system I have to adjust some network settings as the system will join with my.public.ip.adr. My network looks like
root@slave-host:~# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether MAC brd ff:ff:ff:ff:ff:ff
inet my.public.ip.adr brd my.public.ip.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80:some::thing/64 scope link
valid_lft forever preferred_lft forever
3: eth0.vlannr@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether MAC brd ff:ff:ff:ff:ff:ff
inet my.local.ip.adr/31 brd my.local.ip.adr scope global eth0.vlannr
valid_lft forever preferred_lft forever
inet6 fe80:some::thing/64 scope link
valid_lft forever preferred_lft forever
4: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 100
link/none
inet my.openvpn.ip.adr peer master.openvpn.ip.adr/32 scope global tun0
valid_lft forever preferred_lft forever
inet6 fe80::f4a1:4e6c:599c:12c4/64 scope link flags 800
valid_lft forever preferred_lft forever
5: docker0: ....
On the UCS-Master I don’t have any issues when running the system diagnostics.
I can search ldap, I can ping the master, samba4 is running on the master:
root@slave-host:~# nmap master.domain.name -p 88
Starting Nmap 6.47 ( http://nmap.org ) at 2018-02-19 15:17 CET
Nmap scan report for master.domain.name (master.local.ip.adr)
Host is up (0.029s latency).
PORT STATE SERVICE
88/tcp open kerberos-sec
Nmap done: 1 IP address (1 host up) scanned in 0.58 seconds
Kind regards,
Bernd