adcli fails with "Couldn't add keytab entries: Cryptosystem internal error"

Solution Verified - Updated -

Issue

  • When attempting to join the AD domain, receive the below errors:
! Couldn't authenticate with keytab while discovering which salt to use.
realmd: ! Couldn't add keytab entries: FILE:/etc/krb5.keytab: Cryptosystem internal error
  • Cannot join AD on a RHEL 8.0 FIPS-enabled machine.

Environment

  • Red Hat Enterprise Linux 8.0
  • FIPS Enabled

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content