Quantcast
Channel: All Centrify Express posts
Viewing all articles
Browse latest Browse all 1833

Re: is not a zone user?

$
0
0

Robertson,

 

i'm running in Auto Zone Mode Express

# adinfo --zone
Auto Zone

 

The same user that I receive the msg  "No passwd entry for user"  when I  "su" the user, can login on another PC without problem. So, there is no problem on the Samba AD. And in this PC that I receive this error msg, I can login with others users.

This problem happens in 4 PC, some users can login in one PC and in another can't, for exemple:

user1 can login on pc1 but can't login on pc2

user2 can't login on pc1 but can login on pc2

 

# adinfo -g
adinfo (CentrifyDC 5.5.1-400)
Host Diagnostics
  uname: Linux efi-cli-03 4.9.0-8-amd64 #1 SMP Debian 4.9.110-3+deb9u5 (2018-09-30) x86_64
  OS: Debian
  Version: 9.0
  Number of CPUs: 4
IP Diagnostics
  Local host name: cli-03
  Local IP Address: 172.16.3.61
    Not found in DNS!Make sure it is in Reverse Lookup Zone.
  FQDN host name:cli-03.domain.lan
Domain Diagnostics
  Domain: domain.lan
  Subnet site: Default-First-Site-Name
    DNS query for: _ldap._tcp.domain.lan
    Found SRV records:
      srv-ad.domain.lan:389
  Testing Active Directory connectivity:
    Domain Controller: srv-ad.domain.lan
      ldap:      389/tcp - good
      ldap:      389/udp - good
      smb:       445/tcp - good
      kdc:        88/tcp - good
      kpasswd:   464/tcp - good
      ntp:       123/udp - good
  Domain Controller: srv-ad.domain.lan:389
    Domain controller type: Windows 2008 R2
    Domain Name:            DOMAIN.LAN
    isGlobalCatalogReady:   TRUE
    domainFunctionality:           4 = (DS_BEHAVIOR_WIN2008_R2)
    forestFunctionality:           4 = (DS_BEHAVIOR_WIN2008_R2)
    domainControllerFunctionality: 4 = (DS_BEHAVIOR_WIN2008_R2)
  Forest Name: EFILTROS.LAN
    DNS query for: _gc._tcp.DOMAIN.LAN
  Testing Active Directory connectivity:
    Global Catalog: srv-ad.domain.lan
      gc:       3268/tcp - good
  Domain Controller: srv-ad.domain.lan:3268
    Domain controller type: Windows 2008 R2
    Domain Name:            DOMAIN.LAN
    isGlobalCatalogReady:   TRUE
    domainFunctionality:           4 = (DS_BEHAVIOR_WIN2008_R2)
    forestFunctionality:           4 = (DS_BEHAVIOR_WIN2008_R2)
    domainControllerFunctionality: 4 = (DS_BEHAVIOR_WIN2008_R2)
  Forest Name: DOMAIN.LAN
Retrieving zone data from domain.lan
  Could not get domain RIDs from adclient: Bad data
Computer Account Diagnostics
  Joined as: cli-03.domain.lan
  Trusted for Delegation: false
  Use DES Key Only: false
  Key Version: 2
  Service Principal Names: cifs/cli-03
                           cifs/cli-03.domain.lan
                           ftp/cli-03
                           ftp/cli-03.domain.lan
                           host/cli-03
                           host/cli-03.domain.lan
Supported Encryption Type(s): DES-CBC-CRC
                              DES-CBC-MD5
                              RC4-HMAC
                              AES128-CTS-HMAC-SHA1-96
                              AES256-CTS-HMAC-SHA1-96
Operating System Version: 6.1:9.0

System Diagnostic
  Failed to get sysinfo from adclient.

Centrify DirectControl Status
  Running in connected mode
Licensed Features: Disabled

adinfo

This user I get the error msg "No passwd entry for user", but he can retrieve info from AD

 

# adinfo -u user1
Active Directory password:
Local host name: efi-cli-03
Joined to domain: efiltros.lan
Joined as: efi-cli-03.efiltros.lan
Pre-win2K name: efi-cli-03
Current DC: efi-srv-ad.efiltros.lan
Preferred site: Default-First-Site-Name
Zone: Auto Zone
Last password set: 2018-09-24 20:28:28 -03
CentrifyDC mode: connected
Licensed Features: Disabled

 

Maybe it's a sync problem. Is there a way to resync the CentridyAD client

 

Tks for your help

 


Viewing all articles
Browse latest Browse all 1833

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>