FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
JBarrera
Staff
Staff
Article Id 282224
Description This article describes how to fix the FortiAuthenticator error 'Miscellaneous failure (see text): Clock skew too great'.
Scope FortiAuthenticator.
Solution

See this knowledge base article for troubleshooting steps with other possible domain name issues whe....

 

If similar logs to the following example are seen during debugging, it means there is a mismatch between the DC and FortiAuthenticator. For best results, use the same NTP source on both systems.

 

Example:

 

2023-10-31T17:15:08.371209-06:00 Fac winad_mon[1497]: * ADS join for LDAP 1 (pid 2027) exited.
2023-10-31T17:15:08.371216-06:00 Fac winad_mon[1497]: Failed to join Windows AD network: FORTILAB.COM
2023-10-31T17:15:08.371399-06:00 Fac netadsjoin[srvid:1]: gse_get_client_auth_token: gss_init_sec_context failed with [ Miscellaneous failure (see text): Clock skew too great](2529638949)
2023-10-31T17:15:08.371405-06:00 Fac netadsjoin[srvid:1]: kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed for ldap/win-3ro721d4qht.fortilab.com with user[administrator] realm[FORTILAB.COM]: Logon failure
2023-10-31T17:15:08.371409-06:00 Fac netadsjoin[srvid:1]: Desired enctyption type is 28
2023-10-31T17:15:08.371412-06:00 Fac netadsjoin[srvid:1]: Failed to join domain: failed to connect to AD: Logon failure

 

Change the timezone on the FortiAuthenticator and validate the log:


2023-10-31T18:56:08.788667-06:00 Fac winad_mon[1497]: Rejoin request for LDAP 1. Reason: winbind error [0], radius error [0], ping auth error [1]
2023-10-31T18:56:40.812668-06:00 Fac winad_mon[1497]: * try ads join for server 1
2023-10-31T18:56:42.194339-06:00 Fac netadsjoin[srvid:1]: Desired enctyption type is 28
2023-10-31T18:56:42.194346-06:00 Fac netadsjoin[srvid:1]: Using short domain name -- FORTILAB
2023-10-31T18:56:42.194349-06:00 Fac netadsjoin[srvid:1]: Joined 'FAC' to dns domain 'fortilab.com'
2023-10-31T18:56:42.195934-06:00 Fac winad_mon[1497]: ** CHILD signal **
2023-10-31T18:56:42.195943-06:00 Fac winad_mon[1497]: * ADS join for LDAP 1 (pid 6509) exited.
2023-10-31T18:56:42.195946-06:00 Fac winad_mon[1497]: Joined Windows AD network: FORTILAB.COM

Contributors