Connected Ubuntu to AD, but can't login

Viewed 4424

I am using a Linux box to connect to the school AD. The process has gone well, but I'm unable to login.

realm list

VINCI.IISCORNI.IT
  type: kerberos
  realm-name: VINCI.IISCORNI.IT
  domain-name: vinci.iiscorni.it
  configured: kerberos-member
  server-software: active-directory
  client-software: sssd
  required-package: sssd-tools
  required-package: sssd
  required-package: libnss-sss
  required-package: libpam-sss
  required-package: adcli
  required-package: samba-common-bin
  login-formats: %U@vinci.iiscorni.it
  login-policy: allow-realm-logins
administrator@LAB-INFO-11L:~$ su VINCI\\m.missiroli
su: user VINCI\m.missiroli does not exist
administrator@LAB-INFO-11L:~$ id m.missiroli@vinci.iiscorni.it
id: ‘m.missiroli’: no such user

The box is a fresh Ubuntu 20.04 LTS and the server is Windows 2012.

2 Answers

• Please check whether your GDM application is configured for PAM or not. If not, then run the below command to update it and configure.

sudo pam-auth-update

After running this command, hit ‘yes’ at the command prompt and select all stars and hit ‘enter’ once again. Reboot the system and then check. • Also try logging in with AD name, i.e., UPN or short name via SSH, you should be able to login. Also, check whether you are verified to login to the domain joined ubuntu system by running the below command: -

 sudo su –

• By entering the grub mode by pressing Ctrl+Alt+F3 on the login screen and entering these following commands can also work for you.

  sudo apt-get update
  sudo apt-get dist-upgrade
  sudo dpkg --configure -a

Hope the above methods should work for you. Also, find the below links for more information: -

https://askubuntu.com/questions/1231410/cant-log-in-on-ubuntu-20-04

I normally make a group in AD (whatever.local) called Linus_machinename_Sudoers

sudo nano /etc/security/access.conf

Add the lines

+ : whatever.local\Linus_machinename_Sudoers : ALL

- : ALL : ALL

save and exit then for sudoer access

sudo visudo

Add the following line

%Linus_machinename_Sudoers@whatever.local ALL=(ALL) ALL

save and exit

then putty or ssh in a whatever.local\whoever

to join the domain in the first place

sudo apt update && sudo apt upgrade -y

sudo apt -y install realmd sssd sssd-tools libnss-sss libpam-sss adcli samba-common-bin oddjob oddjob-mkhomedir packagekit openssh-server ssh

Test the domain is contactable

Realm discover whatever.local

If good

sudo realm join whatever.local

Test you have joined

id whatever.local\\whoever

Related