Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7505: Unable to join zone against a Read-Only Domain Controller that exists in AWS

Centrify DirectControl ,  

23 September,16 at 08:49 PM

Applies to:

Centrify DirectControl on All Platforms


Problem:

When attempting to join a machine to a zone against a Read-Only Domain Controller (RODC) that exists in Amazon AWS/EC2, it fails.  If joined against a local on-premise RODC, it works just fine.

You may see log entries similar to the following within /var/log/centrifydc.log while ‘addebug’ is set to “on”:

Aug 31 14:19:40 computer.centrify.com adjoin[26093]: INFO base.join User cannot set the computer password: Cannot contact any KDC for requested realm
Aug 31 14:19:41 computer.centrify.com adjoin[26093]: INFO base.join Computer cannot change its own password: Cannot contact any KDC for requested realm
Aug 31 14:19:41 computer.centrify.com adjoin[26093]: INFO cli.adjoin Join to domain 'centrify.com', zone '' failed.
Aug 31 14:19:41 computer.centrify.com adjoin[26093]: INFO lrpc.session process authentication request failed: ipc socket connect: No such file or directory


Cause:

The join operation logic results in the host being looked for by the AWS instance’s CNAME, rather than the actual computer name.


Workaround:

Add the -D <DNSHostName> or --dnsname <DNSHostName> option to your adjoin command. Where DNSHostName is the DNS name for the computer being joined to the zone.

 For example:
adjoin -S -s RODC.centrify.com -D computer.centrify.com

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.