Microsoft KB5008380 for CVE-2021-42287. Unable to join vm to AD domain.
After having installed the hotfix for CVE-2021-42287 on our Windows 2019 DCs, if "PacRequestorEnforcement" is set to "2" (enabling th "Enforcement phase") we became unable to join OL VM to our AD domain (tested on an OL8 vm fully updated).
I tryed both "realm" or "adcli" with the same results and we get an "authentication error" after the computer account was created in AD (so we are able to create a new computer object but the join procedure fails while setting the computer account password, leaving the VM not joined to AD domain because the password isn't set nor the computer keytab is generated) and with an orphan computer object in AD.