• Vitaly Lipatov's avatar
    tune_sssd.sh: fix GSSAPI delegation by using full FQDN for SPN · 691c51d9
    Vitaly Lipatov authored
    - Use dnshostname=$(hostname -f) to register correct dNSHostName
      (e.g. host.office.etersoft.ru instead of host.etersoft.ru)
    - Replace deprecated -k with --use-kerberos=required
    - Add idempotency: check testjoin status before joining
    - If already joined, verify keytab has correct FQDN
    - If machine account is broken, leave and rejoin
    
    Note: requires msDS-AllowedDNSSuffixes on DC to include the DNS subdomain
    Co-Authored-By: 's avatarClaude Opus 4.5 <noreply@anthropic.com>
    691c51d9
Name
Last commit
Last update
..
remove_nss_mysql.sh Loading commit data...
tune_sssd.sh Loading commit data...