Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Add to Domain error

This thread has been viewed 6 times
  • 1.  Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 10:51 AM

    Anyone know the reason for this clearpass error message and the fix?

     

    Adding host to AD domain...
    INFO - Fetched REALM 'XXXX.LOCAL' from domain FQDN 'XXXX.local'
    INFO - Fetched the NETBIOS name 'XXXX'
    INFO - Creating domain directories for 'XXXX'
    Enter srynearson's password:
    [2013/09/20 07:21:22, 0] libads/kerberos.c:333(ads_kinit_password)
    kerberos_kinit_password srynearson@XXXX.LOCAL failed: KDC has no support for e
    ncryption type
    Failed to join domain: failed to connect to AD: KDC has no support for encryptio
    n type
    INFO - Restoring smb configuration
    INFO - Restoring krb5 configuration file
    INFO - Deleting domain directories for 'XXXX'
    ERROR - ClearPass1 failed to join the domain XXXX.LOCAL with domain controller a
    s XXXX.local
    Join domain failed



  • 2.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 10:54 AM
    Are your clocks in sync? (AD DC + CPPM)


  • 3.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 11:13 AM

    The time on clearpass is correct wit hcurrent time. I will give you Kudos if customer comes back with incorrect time on domain controller lol



  • 4.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 11:19 AM

    Domain controller time is also correct. 

     

     

    I believe it has something to do with: 

    KDC has no support for encryption type



  • 5.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 11:26 AM

    Is the user account that is being used to join the domain set to use DES encryption?

     

    des-ad.png



  • 6.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 01:20 PM

    No. Should it?



  • 7.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 01:26 PM

    No, it shouldn't. That error is usually tied to an encryption failure between the client and AD. What is the forest functional level?

     

    You might have to open a TAC case.



  • 8.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 01:32 PM

    I changed the password so it no longer hast the "$" character and now it gives me this error message:

     

     

    Adding host to AD domain...
    INFO - Fetched REALM 'xxxx.LOCAL' from domain FQDN 'xxxx.local'
    INFO - Fetched the NETBIOS name 'xxxx_NT'
    INFO - Creating domain directories for 'xxxx_NT'
    Enter srynearson's password:
    [2013/09/20 10:22:52, 0] libads/sasl.c:819(ads_sasl_spnego_bind)
    kinit succeeded but ads_sasl_spnego_krb5_bind failed: Unspecified GSS failure.
    Minor code may provide more information : Server not found in Kerberos database
    Failed to join domain: failed to connect to AD: Unspecified GSS failure. Minor
    code may provide more information : Server not found in Kerberos database
    INFO - Restoring smb configuration
    INFO - Restoring krb5 configuration file
    INFO - Deleting domain directories for 'xxxx_NT'
    ERROR - ClearPass1 failed to join the domain xxxx.LOCAL with domain controller a
    s xxxx.local
    Join domain failed



  • 9.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 01:35 PM

    "Server not found in Kerberos database" usually points to a DNS issue.


    Does OCDE.local resolve in DNS?



  • 10.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 20, 2013 01:37 PM

    Yes.



  • 11.  RE: Clearpass Add to Domain error

    Posted May 08, 2014 03:32 PM

    did this ever get resolved? I'm having the same issue



  • 12.  RE: Clearpass Add to Domain error

    Posted Sep 09, 2014 10:12 AM

    Running into the same issue and wondering if there were any updates?

     

    J



  • 13.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 09, 2014 10:14 AM
    Try using a fully qualified username for the join (ex: domainadmin@airheads.int)


  • 14.  RE: Clearpass Add to Domain error

    Posted Sep 09, 2014 10:19 AM

    We're still receiving the same error.

     

    kinit succeeded but ads_sasl_spnego_krb5_bind failed: Unspecified GSS
    failure. Minor code may provide more information : Server not found in Kerberos database

     

    J



  • 15.  RE: Clearpass Add to Domain error

    EMPLOYEE
    Posted Sep 09, 2014 11:18 PM


  • 16.  RE: Clearpass Add to Domain error

    Posted Sep 10, 2014 07:29 AM

    We solved this issue by using a singler domain server, instead of using the domain FQDN when joining the domain.  The reverse looking was changing when using the domain FQDN causing the failure.  After joining the domain it seems that Clearpass then uses the domain FQDN, instead of the singler domain server, so domain failover is still in place.

     

    Thanks again for all the help with this issue,

    J



  • 17.  RE: Clearpass Add to Domain error

    Posted Aug 27, 2015 04:07 AM

    @on entering the domasin details and recieving the kerberos error as previuos users have i pointed the join to a specific DC but not ising the @ but with domainname.domain.co.uk used a specific admin account with no odd characters and hey presto no errors DNS resolved and domain added.


    @jemerson7 wrote:

    We solved this issue by using a singler domain server, instead of using the domain FQDN when joining the domain.  The reverse looking was changing when using the domain FQDN causing the failure.  After joining the domain it seems that Clearpass then uses the domain FQDN, instead of the singler domain server, so domain failover is still in place.

     

    Thanks again for all the help with this issue,

    J