Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-10143: adcdiag shows "CLDINST" error when multiple DNS servers are set in /etc/resolv.conf

Authentication Service ,  

13 April,18 at 12:02 AM


When running the adcdiag script on a Linux/Unix server the following error is shown:

Check item #7: ErrorExit
        Please re-specify the trusted Identity Platform instance in the zone.
tform instance.
        Trusted Identity Platform instance is configured but no Centrify Connector is serving to this Identity Pla
    INFO: Trusted Identity Platform instance set in zone:
    INFO: Can't discover any Centrify Connectors.
  Description: Verify that trusted Identity Platform instance is specified
Check item #7: CLDINST started

MFA works yet the script is failing, why and how to fix this?


The adcdiag script uses ldap to make a search on the domain for available Centrify connectors. If the first DNS server in /etc/resolv.conf does not know about the domain controllers the query will fail. This is a limitation of ldapsearch - it relies on DNS. 


Add a valid DNS server as the first entry that have records to a Domain Controller.