Bug 45699 - Join as AD member not possible during system setup
Join as AD member not possible during system setup
Status: RESOLVED WONTFIX
Product: UCS
Classification: Unclassified
Component: System setup
UCS 4.2
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-10 15:39 CET by Nico Gulden
Modified: 2020-07-03 20:54 CEST (History)
3 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 6: Setup Problem: Issue for the setup process
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 3: A User would likely not purchase the product
User Pain: 0.206
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2017101921000607, 2017102421000348, 2017102621000282
Bug group (optional): External feedback
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nico Gulden univentionstaff 2017-11-10 15:39:10 CET
I have received several user feedbacks that complain about not working AD joins during first UCS system during the system setup.

See the following Ticket#2017101921000607.
Comment 1 Erik Damrose univentionstaff 2017-11-10 15:42:19 CET
NEEDMOREINFO: why did the join fail
/var/log/univention/setup.log would be helpful
Comment 2 Florian Best univentionstaff 2017-11-10 15:44:45 CET
(In reply to Nico Gulden from comment #0)
> I have received several user feedbacks that complain about not working AD
Where are the others?
> joins during first UCS system during the system setup.
Where did you get the information that it was the first UCS system?
The ticket contains "AD join war im initialen Setup nicht möglich.". This is not necessarily the first UCS system.
> 
> See the following Ticket#2017101921000607.
Comment 3 Nico Gulden univentionstaff 2017-11-10 16:09:25 CET
Unfortunately, the tickets don't have more information and details.

* Ticket#2017102421000348
* Ticket#2017102621000282
Comment 4 mathias.muehlbacher 2017-11-10 19:42:25 CET
Hi there,

I have given the origin feedback at the installation process of UCS.
As I am running a VSphere server I have downloaded the VM image.
Two things I have tried:
1) AD join direct at the setup process
2) Created a separate "UCS domain" (sorry - can't remember the correct name of it) and tried to join AD afterwards.

Both things were not successful.

To be honest: I have deleted the VM from my host so I am no longer able to provide any log files.


I usually have Linux -> Windows Server 2012R2 problems with Samba as I have disabled SMB2 on my Windows Server.
Therefore I need to enable SMB2 on my Linux VMs.

If needed I can download the UCS VM image again and try to do the join again and provide all requested *.log files.


Kind regards,
Mathias Mühlbacher
Comment 5 Florian Best univentionstaff 2017-11-14 15:42:56 CET
(In reply to mathias.muehlbacher from comment #4)
Hi Matthias Mühlbacher,

thank you for reporting back here.

We are currently facing two different problems:

1. The univention-ad-connector debian packages cannot be installed during the setup. This would be Bug #42020 with the error message "univention-ad-connector: Failed to install".

2. After joining a UCS (DC Master) into an Active Directory on the Active Directory side a DNS service (SRV) record _domaincontroller_master._tcp.$domainname which points to the UCS System is created. If this entry exists but that UCS System is not online anymore joining a seconds UCS system will fail. This is Bug #43745 and a fix will be released soon. The error message would contain something like "The connection to the server could not be done" / "ping to ... failed".

Can you remember if it were one of these two errors?
Comment 6 mathias.muehlbacher 2017-11-14 20:01:39 CET
Hello Florian Best,

I have downloaded UCS core from your website: UCS-VMware-ESX-Demo-Image.ova
I left the settings untouched and put the UCS virtual machine in the same VLAN as my Active Directory server.

As this is also my main DNS server + DHCP I do not need to specify anything special and can click on next (eq. Weiter as I us the German language version) until Domain settings (Domäneneinstellungen).

I have selected joing existing MS AD domain.
Entered my credentials + password (cross checked if the keyboard layout is okay for characters to suite the German keyboard layout).

Error message: "Verbindungsaufbau abgelehnt. Bitte überprüfen Sie das Passwort".

So it was none of the mentioned bugs/errors.

Kind regards,
Mathias
Comment 7 Nico Gulden univentionstaff 2017-11-16 14:28:39 CET
Remark from Ticket#2017102621000282:

"Ich hatte vor, den UCS Server während der Installation bereits in die Active Directory Domain zu integrieren, das funktionierte allerdings nicht, da der Installer
versuchte, per ssh auf den Windows Domain Controller zuzugreifen, was natürlich nicht funktionieren konnte. Das könnte besser dokumentiert sein."
Comment 8 mathias.muehlbacher 2017-11-16 15:49:07 CET
Okay if the join uses SSH then it won't work.
But how about the join after you have created a separate UCS within the setup process?

The error message was also "Verbindungsaufbau abgelehnt. Bitte überprüfen Sie das Passwort." when I have created a separate UCS domain and wanted to join my AD domain.
Comment 9 Florian Best univentionstaff 2017-11-27 19:04:22 CET
(In reply to Nico Gulden from comment #7)
> Remark from Ticket#2017102621000282:
> 
> "Ich hatte vor, den UCS Server während der Installation bereits in die
> Active Directory Domain zu integrieren, das funktionierte allerdings nicht,
> da der Installer
> versuchte, per ssh auf den Windows Domain Controller zuzugreifen, was
> natürlich nicht funktionieren konnte. Das könnte besser dokumentiert sein."

(In reply to mathias.muehlbacher from comment #8)
> Okay if the join uses SSH then it won't work.
> But how about the join after you have created a separate UCS within the
> setup process?
> 
> The error message was also "Verbindungsaufbau abgelehnt. Bitte überprüfen
> Sie das Passwort." when I have created a separate UCS domain and wanted to
> join my AD domain.

During Bug #42910 I fixed an error that the wrong IP address was used for an SSH connection. I think these problems are caused by this. We should wait for the new UCS 4.2-3 Images which contain these fixes. They will be released this week.
Comment 10 Ingo Steuwer univentionstaff 2020-07-03 20:54:03 CEST
This issue has been filed against UCS 4.2.

UCS 4.2 is out of maintenance and many UCS components have changed in later releases. Thus, this issue is now being closed.

If this issue still occurs in newer UCS versions, please use "Clone this bug" or reopen it and update the UCS version. In this case please provide detailed information on how this issue is affecting you.