Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-10202: Adclient goes disconnected mode after successful upgrade from 5.0.2 to 5.4.1

Authentication Service ,  

24 April,18 at 02:06 PM

Problem:

After successfully upgrading from version 5.0.2 to 5.4.1, Adclient goes into "disconnected" mode.

Causes:

After upgrading adclient to 5.4.1, when adclient is binding to a Window Domain Controller 2003 (DFL 2003), it will fail the Machine password verification after retrieving the service ticket with the new machine password; therefore the keyversionnumber from "/etc/krb5/krb5.keytab" is out of sync after the upgrade.

Running "adkeytab -C -m" does not allow the machine password to be reset. 

====================================================

[root@vanrh6-2 ~]# adkeytab -C -m
Error: Computer failed to change its own password
Adjust the privilege settings for 'vanrh6-2' or retry with a more privileged principal.
Failed: Change Password: Default Key Tab  

========================================================
   

         
Solution:

1.)When upgrading from 5.0.2 to 5.4.x or above, please make sure adclient is binding to a DC which is Window Server 2008 or above in order to prevent adclient going into "disconnected" mode.

2.)If upgrading the Domain Controller to Window Server 2008 or above is not an available option, it is recommended to upgrade the adclient to a version that is no later than Suite 2013.2 (5.1.2).


Note: 
Below Platform support has been terminated in Suite 2015.1(5.2.3):
-Windows Server 2003
-Windows Server 2003 R2

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.