Symptoms:
Administration > Single Sign On > Configuration > Active Directory Domain > Leave AD, the node fails to leave the domain.ldm client exception: Error trying to leave AD, error code [1321],user [domainusername] /opt/likewise/bin/domainjoin-cli leave fails with error: Error: ERROR_MEMBER_NOT_IN_GROUP /opt/likewise/bin/domainjoin-cli query give below output:Error: LW_ERROR_KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN [code 0x0000a309]Client not found in Kerberos database
VMware vCenter Server 6.x
VMware vCenter Server 7.x
VMware vCenter Server 8.x
Below steps will make changes in Likewise registry, Hence please make sure to take a snapshot of the appliance. Please refer the KB for more details regarding offline snapshot for vcenters in ELM: VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice
/opt/likewise/bin/lwregshellcd HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoinls[\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin\]+ "Default" REG_SZ "<domain-name>"[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory\DomainJoin\<domain-name>] 4. Delete all entries using the delete_ commands (replace domain-name with the previous output)
lsdelete_tree <domain-name>delete_value Default5. Restart the likewise service:
/opt/likewise/bin/lwsm restart lwreg 6. Confirm with domainjoin-cli query command that the PSC/vCenter node no longer references the Active Directory Domain:
/opt/likewise/bin/domainjoin-cli queryName = vcenterDomain =