AD accounts are failing to login on RHEL via winbind with an error "Clock skew too great in KDC reply"
Issue
- AD accounts are failing to login on RHEL via winbind with an error below:
Apr 4 02:30:50 rhel6u10 winbindd[1234]: [2024/04/04 02:30:50.249425, 0] libads/sasl.c:939(ads_sasl_spnego_bind)
Apr 4 02:30:50 rhel6u10 winbindd[1234]: kinit succeeded but ads_sasl_spnego_krb5_bind failed: Unspecified GSS failure. Minor code may provide more information : Clock skew too great in KDC reply
net ads joincommand is failing with clock skew error:
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Unspecified GSS failure. Minor code may provide more information : Clock skew too great in KDC reply
Environment
- Red Hat Enterprise Linux 6.10
- Microsoft Active Directory
- samba/winbind
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.