I am running RH8 with the Samba-alpha3.23 from the RPMs. I was able to use Kerberos to add machine to a Windows AD domain without any problem and was able to get winbind to function properly. I was able to get group & user listing using wbinfo -g & -u, -t responds with proper information. I have run getent for passwords & groups. Since what appeared to be a successful getent, my winbind daemon will stop/crash (wbinfo -p fails) after running for about 2 minutes. Please see winbind log below. I have sanitized some of the values related to the actual name of the KDC, our AD FQDN, and trusted domains. ***AD Domain User Account*** is the same account in both entries. Any help would be appreciated. got principal=KDC@DOMAIN [2003/04/16 16:16:47, 3] libads/ldap.c:ads_do_paged_search(500) ldap_search_ext_s((distinguishedName=***AD Domain User Account***)) -> Can't contact LDAP server [2003/04/16 16:16:47, 3] libads/ldap_utils.c:ads_do_search_retry(60) Reopening ads connection to realm 'DOMAIN' after error Can't contact LDAP server [2003/04/16 16:16:47, 5] libads/ldap.c:ads_try_connect(53) ads_try_connect: trying ldap server 'KDC' port 389 [2003/04/16 16:16:47, 3] libads/ldap.c:ads_connect(267) Connected to LDAP server ***KDC-IP*** [2003/04/16 16:16:47, 3] libads/ldap.c:ads_server_info(1917) got ldap server name KDC@DOMAIN, using bind path: ***LDAP SEARCH BASE*** [2003/04/16 16:16:47, 4] libads/ldap.c:ads_server_info(1923) time offset is -22 seconds [2003/04/16 16:16:47, 4] libads/sasl.c:ads_sasl_bind(412) Found SASL mechanism GSS-SPNEGO [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 48018 1 2 2 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 113554 1 2 2 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 113554 1 2 2 3 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 3 6 1 4 1 311 2 2 10 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(190) got principal=KDC@DOMAIN [2003/04/16 16:16:47, 3] libads/ldap.c:ads_do_paged_search(500) ldap_search_ext_s((distinguishedName=***AD Domain User Account***)) -> Can't contact LDAP server [2003/04/16 16:16:47, 3] libads/ldap_utils.c:ads_do_search_retry(60) Reopening ads connection to realm 'DOMAIN' after error Can't contact LDAP server [2003/04/16 16:16:47, 5] libads/ldap.c:ads_try_connect(53) ads_try_connect: trying ldap server 'KDC' port 389 [2003/04/16 16:16:47, 3] libads/ldap.c:ads_connect(267) Connected to LDAP server ***KDC-IP*** [2003/04/16 16:16:47, 3] libads/ldap.c:ads_server_info(1917) got ldap server name KDC@DOMAIN, using bind path: ***LDAP SEARCH BASE*** [2003/04/16 16:16:47, 4] libads/ldap.c:ads_server_info(1923) time offset is -22 seconds [2003/04/16 16:16:47, 4] libads/sasl.c:ads_sasl_bind(412) Found SASL mechanism GSS-SPNEGO [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 48018 1 2 2 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 113554 1 2 2 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 2 840 113554 1 2 2 3 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(183) got OID=1 3 6 1 4 1 311 2 2 10 [2003/04/16 16:16:47, 3] libads/sasl.c:ads_sasl_spnego_bind(190) got principal=KDC@DOMAIN [2003/04/16 16:16:47, 1] libads/ldap_utils.c:ads_do_search_retry(76) ads reopen failed after error Success winbindd: ../../../libraries/libldap/getvalues.c:36: ldap_get_values: Assertion `entry != ((void *)0)' failed. [2003/04/16 16:20:05, 1] nsswitch/winbindd.c:main(918) winbindd version 3.0alpha23 started. Copyright The Samba Team 2000-2001 [2003/04/16 16:20:06, 1] nsswitch/winbindd_util.c:rescan_trusted_domains(168) scanning trusted domain list [2003/04/16 16:20:06, 0] nsswitch/winbindd_idmap.c:winbindd_idmap_init(435) winbindd_idmap_init: Unable to open idmap database [2003/04/16 16:23:30, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Pre-W2K Domain Name*** [2003/04/16 16:23:30, 1] libsmb/clikrb5.c:krb5_mk_req2(267) krb5_cc_get_principal failed (No credentials cache found) [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:rescan_trusted_domains(168) scanning trusted domain list [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trusted NT4 Domain1*** S-1-5-21-1649697308-930030979-1844936127 [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trusted NT4 Domain2*** S-1-5-21-1417498601-1066937757-1235820382 [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trust NT4 Domain3*** S-1-5-21-942099442-772538512-7473742 [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trusted NT4 Domain4 *** S-1-5-21-2142334411-1495472810-1800150966 [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trusted W2K Domain1*** S-1-5-21-4083647202-336882308-1182290677 [2003/04/16 16:23:40, 1] nsswitch/winbindd_util.c:add_trusted_domain(140) Added domain ***Trusted NT4 Domain 5*** S-1-5-21-1611677848-116330326-623647154 [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Users !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Server Operators !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Replicator !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Pre-Windows 2000 Compatible Access !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Guests !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Account Operators !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Print Operators !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Administrators !? [2003/04/16 16:26:02, 1] nsswitch/winbindd_ads.c:enum_dom_groups(254) No rid for Backup Operators !? [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:15, 1] libads/ads_utils.c:ads_atype_map(132) hmm, need to map account type 0x20000000 [2003/04/16 16:26:16, 1] libads/ldap_utils.c:ads_do_search_retry(76) ads reopen failed after error Success winbindd: ../../../libraries/libldap/getvalues.c:36: ldap_get_values: Assertion `entry != ((void *)0)' failed. WILLIAM M. SHADE US Army Garrison - Redstone Directorate of Information Management Redstone Arsenal, AL 35898