This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG fails to join domain 18.5.5

Hi all

We are having trouble with a test instance of XG 18.5.5 in which we can not get it to join our domain.  We are running some 18.5.1 devices which did not have any issues with joining a domain but 18.5.5 just does not play ball.

We get the following in the NASM logs:

Feb 06 13:45:23.454494Z [nasm] Log level set to INFO
Feb 06 13:45:23.454570Z [nasm] init_nasm: launch in "non-auxiliary" mode [tid=f7584bc0]
Feb 06 13:45:23.454637Z [nasm] protocol initialized successfully
Feb 06 13:45:23.454667Z [nasm] NASM initialized successfully, driving towards endless loop
Feb 06 13:45:23.454724Z [nasm] create_ntlmserver_thread(): AD SSO server thread created successfully (tid=f6981b40)
Feb 06 13:45:23.459009Z [ntlmserver] initialize_fasm(): initialized successfully
Feb 06 13:45:23.460179Z [ntlmserver] initialize_inmemorydb(): /tmp/ntlm_users.db opened successfully.
Feb 06 13:45:23.460214Z [ntlmserver] initialize_local_socket(): initialized successfully
Feb 06 13:45:23.460223Z [ntlmserver] ntlm_server() requesting status of AD channel
Feb 06 13:45:23.462628Z [ntlmserver] client_request_processor(): new local client connected on fd=11, informing channel status to client
Feb 06 13:45:23.462645Z [ntlmserver] inform_channel_status(): sumit DATA to proxy='0 0 0 0 0 0 0 0 5 0 0 0 '
Feb 06 13:45:23.462652Z [ntlmserver] inform_channel_status(): informing channel status to http proxy, channel status=0
Feb 06 13:45:23.918527Z [nasm] is_ad_join_required() AD join required due to detected change in smb.conf
Feb 06 13:45:24.565643Z [nasm] connection closed, verify baby's health :)
dos charset 'CP850' unavailable - using ASCII
kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed for ldap/xxx with user[yyy] realm[zzz]: Invalid credentials

The credentials and server name are correct and test fine in the Authentication Server page.  We have checked the usual things like DNS, Time, Server name and Device name etc and all seem fine. 

The account we are using has all the required permission.

Checked all the logs and used the debug mode but nothing shouts at us.  At a loss at the moment as to why this is happening and need to get this sorted ASAP as we have a load of devices that need upgrading.

Anybody have any ideas what we may be missing or anything else to look at?



This thread was automatically locked due to age.