VMware Cloud Community
Aarif_Khan
Contributor
Contributor
Jump to solution

Unable to join ESXi host in domain (using RODC)

Dear Friends,

I'm trying to join one of our ESXi 6.7 host to domain but getting error "Errors in Active Directory operations", I went thr' couple of KB articles available and tried all of them, but still getting the error. All required ports are opened -

Note: I am using RODC for domain joining; I have created an host object in primary DC and after sometime object replicated in RODC. 

Please assist. Thanks in advance.

Logs: 

20190419083242:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX1

20190419083342:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX2

20190419083442:ERROR:lsass: Failed to run provider specific request (request code = 8, provider = 'lsa-activedirectory-provider') -> error = 40286, symbol = LW_ERROR_LDAP_SERVER_DOWN, client pid = XXXX3

20190419083542:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX4

20190419085316:INFO:lsass: Joining domain example.com
20190419085316:INFO:netlogon: Looking for a DC in domain 'example.com', site '<null>' with flags 10
20190419085316:INFO:netlogon: Filtering list of 3 servers with list of 0 black listed servers
20190419085331:ERROR:lsass: Failed to find DC for domain example.com

0 Kudos
1 Solution

Accepted Solutions
msripada
Virtuoso
Virtuoso
Jump to solution

ESXi host and vCenter uses likewise binary to join to AD.

vCenter joining to writable AD does not make any difference to ESXi host adding to RODC (Still unsupported)

ESXi host is an object like VCSA so it cannot be written or updated on RODC when you are trying to join. 

When you are joining ESXi host to AD, it creates object and updates the object properties. Both of these cannot happen in RODC hence its unsupported.

thanks,

MS

View solution in original post

0 Kudos
6 Replies
fabio1975
Commander
Commander
Jump to solution

Ciao 

If I remember correctly you can't join a DC RODC (read only domain controller)

For windows OS:

You have to provision the Computer account in AD on one of your writable DC's.
Once it replicates the computer account to the RODC. And try offline join.

 

but for Windows OS it works ... for ESXi I've never tried ... you should join a "normal" DOMAIN Controller.

 

Fabio

Visit vmvirtual.blog
If you're satisfied give me a kudos

0 Kudos
msripada
Virtuoso
Virtuoso
Jump to solution

https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.vcsa.doc/GUID-08EA2F92-78A7-4EFF-88...

Important:Joining vCenter Server to an Active Directory domain with a read-only domain controller (RODC) is not supported. You can join vCenter Server only to an Active Directory domain with a writable domain controller.
0 Kudos
Aarif_Khan
Contributor
Contributor
Jump to solution

Yes, I can't use RODC for domain join purpose, therefore I have created computer object at primary DC (Writable).

0 Kudos
Aarif_Khan
Contributor
Contributor
Jump to solution

vCenter Server is already integrated to domain controller, here I am trying to join ESXi node to domain using RODC (which has ESXi objected replicated from primary DC).

0 Kudos
msripada
Virtuoso
Virtuoso
Jump to solution

ESXi host and vCenter uses likewise binary to join to AD.

vCenter joining to writable AD does not make any difference to ESXi host adding to RODC (Still unsupported)

ESXi host is an object like VCSA so it cannot be written or updated on RODC when you are trying to join. 

When you are joining ESXi host to AD, it creates object and updates the object properties. Both of these cannot happen in RODC hence its unsupported.

thanks,

MS

0 Kudos
Aarif_Khan
Contributor
Contributor
Jump to solution

Thank you so much for your support. Below KB article also confirm the same;

Configuring the ESXi host with Active Directory authentication (2075361) (vmware.com) 

0 Kudos