FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
JBarrera
Staff
Staff
Article Id 282224

Description 

 

This article describes how to fix the FortiAuthenticator error 'Miscellaneous failure (see text): Clock skew too great' and common errors 

 

Scope

 

FortiAuthenticator

 

Solution

 

For troubleshooting steps with other possible domain name issues when joining an AD network, see Troubleshooting Tip: FortiAuthenticator error: Failed to join Windows AD network: Domain Name.

 

If similar logs to the following example are seen during debugging, it means there is a mismatch between the DC and FortiAuthenticator. For best results, use the same NTP source on both systems.

 

Example:

 

2023-10-31T17:15:08.371209-06:00 Fac winad_mon[1497]: * ADS join for LDAP 1 (pid 2027) exited.
2023-10-31T17:15:08.371216-06:00 Fac winad_mon[1497]: Failed to join Windows AD network: FORTILAB.COM
2023-10-31T17:15:08.371399-06:00 Fac netadsjoin[srvid:1]: gse_get_client_auth_token: gss_init_sec_context failed with [ Miscellaneous failure (see text): Clock skew too great](2529638949)
2023-10-31T17:15:08.371405-06:00 Fac netadsjoin[srvid:1]: kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed for ldap/win-3ro721d4qht.fortilab.com with user[administrator] realm[FORTILAB.COM]: Logon failure
2023-10-31T17:15:08.371409-06:00 Fac netadsjoin[srvid:1]: Desired enctyption type is 28
2023-10-31T17:15:08.371412-06:00 Fac netadsjoin[srvid:1]: Failed to join domain: failed to connect to AD: Logon failure

 

  • Change the timezone on the FortiAuthenticator and validate the log:

 

   2023-10-31T18:56:08.788667-06:00 Fac winad_mon[1497]: Rejoin request for LDAP 1. Reason: winbind error [0],radius     error [0], ping auth error [1]
   2023-10-31T18:56:40.812668-06:00 Fac winad_mon[1497]: * try ads join for server 1
   2023-10-31T18:56:42.194339-06:00 Fac netadsjoin[srvid:1]: Desired enctyption type is 28
   2023-10-31T18:56:42.194346-06:00 Fac netadsjoin[srvid:1]: Using short domain name -- FORTILAB
   2023-10-31T18:56:42.194349-06:00 Fac netadsjoin[srvid:1]: Joined 'FAC' to dns domain 'fortilab.com'
   2023-10-31T18:56:42.195934-06:00 Fac winad_mon[1497]: ** CHILD signal **
   2023-10-31T18:56:42.195943-06:00 Fac winad_mon[1497]: * ADS join for LDAP 1 (pid 6509) exited.
   2023-10-31T18:56:42.195946-06:00 Fac winad_mon[1497]: Joined Windows AD network: FORTILAB.COM

 

  • Another common error that may occur is when the FortiAuthenticator is not able to find the domain controller to attempt to rejoin:

 

     2024-10-28T09:04:31.374142+01:00  FortiAuthenticator winad_mon[1412]: Wbinfo ping failed for LDAP 1, rc 233

   2024-10-28T09:04:31.374156+01:00  FortiAuthenticator winad_mon[1412]: Rejoin request for LDAP 1. Reason: winbind     error [0], radius error [0], ping auth error [1]

   2024-10-28T09:04:31.374163+01:00 FortiAuthenticator winad_mon[1412]: * try ads join for server 1

   2024-10-28T09:04:31.452345+01:00 FortiAuthenticator winad_mon[20706]: Try to join domain using preferred dc         "fortilab.com"

 

  1. Ensure the server is reachable and no ports are being blocked.
  2. Check if there are no DNS failure.
  3. Increase the LDAP Server Response Timeout to 20 seconds from the default value of 5.