Kerberos armoring in Microsoft Active Directory 2012 R2 breaks IPA/AD cross-realm trust.
Issue
- Centralized user authentication breaks when Kerberos Armoring service on the Microsot Active Directory 2012 R2 server is enabled.
Environment
- Red Hat Enterprise Linux 7.2 and older.
- IPA Server 4.2.
- Microsoft Active Directory 2012 R2.
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.