Symptoms:
Administration > Single Sign On > Configuration > Active Directory Domain > Leave AD, the node fails to leave the domain.ldm client exception: Error trying to leave AD, error code [1321],user [domainusername] /opt/likewise/bin/domainjoin-cli leave fails with error: Error: ERROR_MEMBER_NOT_IN_GROUP /opt/likewise/bin/domainjoin-cli query give below output:Error: LW_ERROR_KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN [code 0x0000a309]Client not found in Kerberos database
Below steps will make changes in Likewise registry, Hence please make sure to take a snapshot of the appliance. Please refer the KB for more details regarding offline snapshot for vcenters in ELM: VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice
/opt/likewise/bin/lwregshellcd HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoinls[\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin\]+ "Default" REG_SZ "<domain-name>"[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin\<domain-name>] 4. Delete all entries using the delete_ commands (replace domain-name with the previous output)
lsdelete_tree <domain-name>delete_value Default5. Restart the likewise service:
/opt/likewise/bin/lwsm restart lwreg 6. Confirm with domainjoin-cli query command that the PSC/vCenter node no longer references the Active Directory Domain:
/opt/likewise/bin/domainjoin-cli queryName = vcenterDomain =