This used to work ... root at workhorse:/var/log/samba# wbinfo -t checking the trust secret via RPC calls failed error code was NT_STATUS_ACCESS_DENIED (0xc0000022) Could not check secret root at workhorse:/var/log/samba# net ads info LDAP server: 10.0.0.60 LDAP server name: dim-win2300.DaCrib.local Realm: DACRIB.LOCAL Bind Path: dc=DACRIB,dc=LOCAL LDAP port: 389 Server time: Sat, 24 Apr 2010 16:20:52 EDT KDC server: 10.0.0.60 Server time offset: 0 log.smbd: [2010/04/24 16:08:15, 0] libads/kerberos.c:332(ads_kinit_password) kerberos_kinit_password WORKHORSE$@DACRIB.LOCAL failed: Preauthentication failed log.winbindd: [2010/04/24 16:08:16, 0] libsmb/cliconnect.c:996(cli_session_setup_spnego) Kinit failed: Preauthentication failed [2010/04/24 16:08:17, 1] winbindd/winbindd_util.c:303(trustdom_recv) Could not receive trustdoms [2010/04/24 16:08:25, 0] libads/kerberos.c:332(ads_kinit_password) kerberos_kinit_password WORKHORSE$@DACRIB.LOCAL failed: Preauthentication failed [2010/04/24 16:08:25, 1] winbindd/winbindd_ads.c:127(ads_cached_connection) ads_connect for domain DACRIB failed: Preauthentication failed [2010/04/24 16:08:25, 1] winbindd/idmap.c:438(idmap_init_passdb_domain) Could not init passdb idmap domain Googling leads me to believe that the machine secret password is wrong. But I haven't been able to figure out how to fix it. Should I delete the machine account in AD, and try to add again?