Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-3550: Oracle service account not working as expected after server is joined to domain

Centrify DirectControl ,  

12 April,16 at 11:08 AM

Applies to:  All versions of Centrify DirectControl on all supported platforms
 
Problem:
After installing Centrify DirectControl on an Oracle server and joining it to a domain, local accounts such as the Oracle service account are no longer working properly.  
 
The following error may be seen when trying to run sqlplus:
 
ERROR:
ORA-01031: insufficient privileges
 
Cause:
A possible cause is the Oracle account is a member of the local group 'dba', which is also provisioned as an AD-enabled group and conflicts with the local dba group.   
 
Resolution:
  1. Enable the following parameter in /etc/centrifydc/centrifydc.conf:

    adclient.local.group.merge: true 

     
  2. Save the changes and either run adreload or restart adclient using: /usr/share/centrifydc/bin/centrifydc restart.
     
  3. Retry the previous commands or query the group for example using:

    getent group dba 

    The oracle account should now show up as a member. 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.