Hi there,
I have finally gotten around to prepping a sandbox to do a dry run of an AD takeover of a Server 2003 Small Biz edition and I have hit a wall before I even begin. I cannot get the ucs host to join the domain, and the error I get doesn’t make a whole lot of sense to me, so here is my log and some comments.
Win2003 host: DENALI
ip: 192.168.10.1 (not my choice)
domain: allforkids.local
UCS host: ucs
ip: 192.168.10.10
Expected steps: Install UCS, choose member of AD, select top option (backup AD), join to AD, test and make sure I can login to the domain, proceed with the installation and execution of AD takeover.
What I get is a failure to join. What I don’t quite get is where it is failing. When I run through the wizard at initial install, and choose the domain, it kicks me back asking to set the ip info because the DHCP server is NOT giving the DC as the DNS server, so I set a static IP (which I need to do anyway and don’t know if I can change it later) and DNS and then it finds the domain controller just fine on the second pass. So now it lets me put in the Domain Admin user/pass and proceeds with the install but fails in joining and lets me go to the UCS console and try again.
So… is the join process trying to ssh into UCS (self) and then process the join? The username and password help prompts say the domain administrator user/pass and the Domain Controller Master which I assume must be the DENALI host. I don’t think it is expecting to be able to ssh into DENALI, it has no sshd.
I am at a loss. I have this in hyper-v and have a checkpoint at the point where you join the domain, so I can roll back to that configuration step (after disk format) as many times as I need. Any help would be much appreciated… it must be something dumb I just can’t see, something super obvious.
root@ucs:/var/log/univention# cat join.log
Sat Jun 11 20:01:18 AKDT 2016: starting /usr/share/univention-join/univention-join -dcaccount Administrator -dcpwd /tmp/tmp.trsKOWRhID
ssh: connect to host ucs.allforkids.local port 22: Connection refused
Sat Jun 11 20:01:18 AKDT 2016: finish /usr/share/univention-join/univention-join
Sat Jun 11 20:08:02 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount Administrator -dcpwd /tmp/tmpGjiVbw
Warning: Permanently added 'ucs.allforkids.local,192.168.10.10' (ECDSA) to the list of known hosts.
Permission denied (publickey,gssapi-keyex,gssapi-with-mic,keyboard-interactive).
Sat Jun 11 20:08:07 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:21 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount root -dcpwd /tmp/tmpSXSIfr
running version check
OK: UCS version on ucs.allforkids.local is higher or equal (4.10) to the local version (4.10).
Stopping ldap server(s): slapd ...done.
Starting ldap server(s): slapd ...done.
Sat Jun 11 20:08:29 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:46 AKDT 2016: starting /usr/sbin/univention-join -dcname denali.allforkids.local -dcaccount administrator -dcpwd /tmp/tmpVGUzSM
ssh: connect to host denali.allforkids.local port 22: Connection refused
Sat Jun 11 20:08:46 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:56 AKDT 2016: starting /usr/sbin/univention-join -dcname denali.allforkids.local -dcaccount administrator -dcpwd /tmp/tmpalRX9m
ssh: connect to host denali.allforkids.local port 22: Connection refused
Sat Jun 11 20:08:56 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:18:14 AKDT 2016: starting /usr/sbin/univention-join
Sat Jun 11 20:18:24 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:26:24 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount root -dcpwd /tmp/tmpF6_sMn
running version check
OK: UCS version on ucs.allforkids.local is higher or equal (4.10) to the local version (4.10).
Stopping ldap server(s): slapd ...done.
Starting ldap server(s): slapd ...done.
Sat Jun 11 20:26:31 AKDT 2016: finish /usr/sbin/univention-join
root@ucs:/var/log/univention# cat join.log
Sat Jun 11 20:01:18 AKDT 2016: starting /usr/share/univention-join/univention-join -dcaccount Administrator -dcpwd /tmp/tmp.trsKOWRhID
ssh: connect to host ucs.allforkids.local port 22: Connection refused
Sat Jun 11 20:01:18 AKDT 2016: finish /usr/share/univention-join/univention-join
Sat Jun 11 20:08:02 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount Administrator -dcpwd /tmp/tmpGjiVbw
Warning: Permanently added 'ucs.allforkids.local,192.168.10.10' (ECDSA) to the list of known hosts.
Permission denied (publickey,gssapi-keyex,gssapi-with-mic,keyboard-interactive).
Sat Jun 11 20:08:07 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:21 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount root -dcpwd /tmp/tmpSXSIfr
running version check
OK: UCS version on ucs.allforkids.local is higher or equal (4.10) to the local version (4.10).
Stopping ldap server(s): slapd ...done.
Starting ldap server(s): slapd ...done.
Sat Jun 11 20:08:29 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:46 AKDT 2016: starting /usr/sbin/univention-join -dcname denali.allforkids.local -dcaccount administrator -dcpwd /tmp/tmpVGUzSM
ssh: connect to host denali.allforkids.local port 22: Connection refused
Sat Jun 11 20:08:46 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:08:56 AKDT 2016: starting /usr/sbin/univention-join -dcname denali.allforkids.local -dcaccount administrator -dcpwd /tmp/tmpalRX9m
ssh: connect to host denali.allforkids.local port 22: Connection refused
Sat Jun 11 20:08:56 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:18:14 AKDT 2016: starting /usr/sbin/univention-join
Sat Jun 11 20:18:24 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:26:24 AKDT 2016: starting /usr/sbin/univention-join -dcname ucs.allforkids.local -dcaccount root -dcpwd /tmp/tmpF6_sMn
running version check
OK: UCS version on ucs.allforkids.local is higher or equal (4.10) to the local version (4.10).
Stopping ldap server(s): slapd ...done.
Starting ldap server(s): slapd ...done.
Sat Jun 11 20:26:31 AKDT 2016: finish /usr/sbin/univention-join
Sat Jun 11 20:27:41 AKDT 2016: starting /usr/sbin/univention-join -dcname denali.allforkids.local -dcaccount administrator -dcpwd /tmp/tmpi0vnQk
ssh: connect to host denali.allforkids.local port 22: Connection refused
Sat Jun 11 20:27:41 AKDT 2016: finish /usr/sbin/univention-join