This article applies to BoKS 6.7 and 7.0.
Resolution / Workaround
Apply hotfix HFBM-0070 (for BoKS Manager 6.7) or HFBM-0085 (for BoKS Manager 7.0), available for download from the HelpSystems Community Portal.
Additionally this contains a correction for adgetdc which could cause it to abort if e.g. DNS lookup of an AD server failed. (A similar problem exists in adjoin and is corrected by hotfix HFBM-0069).
- mapkerberos -l
Now lists three columns: Principal, BoKS user and Account type.
- lsbks -a/-f
Parameter "Has same User Principal Name as:" now lists multiple lines of users if more than two users share the same principal name.
- lsbks -DA
Displays comma-separated list of users with the same principal name.
The redesign involves a small change to the database schema (a key is no longer required to be unique). This means this hotfix MUST be installed on the Master and all Replicas before adsync is executed.
This also means that the kerberos-to-user mapping table (T68) should be empty or at least not contain any duplicate keys (the PRINCIPAL field) before the hotfix is uninstalled.
Still have questions? We can help. Submit a case to Technical Support.