IPA Client AD Trust logins fail with Cannot find KDC for realm "AD.REALM" while getting initial credentials
Issue
- Unable to login with AD Trust users on IPA clients
- Succesfully able to resolve SSSD users with
idcommand but login fails during PAM authentication. SSSDkrb5_childlogs errors out with
Cannot find KDC for realm "AD.REALM" while getting initial credentials
- The same error can be reproduced with
# kinit aduser@AD.REALM
Environment
- Red Hat Enterprise Linux 7
- Red Hat Identity Management
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
