Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-1281: How to adjoin when there are conflicting / duplicate SPNs in the forest

Centrify DirectAudit ,   Centrify DirectControl ,   Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:07 AM

Applies to: All versions of Centrify DirectControl on all platforms.

Problem:

adjoin fails with the following message:
  • One or more of the following SPNs already associated with other account in the forest

Cause:

This can happen if there is an enterprise application, such as SAP, using the http SPN, which causes a conflict when adjoin is run.


Solution:

Remove "http" from adclient.krb5.service.principals in /etc/centrifydc/centrifydc.conf.
The entry should now read:
  • adclient.krb5.service.principals: ftp cifs nfs

Save the configuration and then run adjoin again.



See also:

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.