search for: 2008_r2

Displaying 20 results from an estimated 133 matches for "2008_r2".

2016 Jul 07
2
Unable to transfer ForestDns/DomainDNS
...rted to BIND, then > tested. Seems like it was working. I forced the 2003 machine out, > cleaned up the meta data and everything seemed to be working ok. So I > raised the domain level like this > > samba-tool domain level raise > samba-tool domain level raise --domain-level=2008_R2 > samba-tool domain level raise --forest-level=2008_R2 > > everything shows as 2008_R2 > > so now I think I'm making progress. I spin up another linux box, get > it ready to join, starts to join, then fails > > says LDAP error 16 LDAP_NO_SUCH_ATTRIBUTE - <0000200A:...
2016 Jul 12
2
Unable to transfer ForestDns/DomainDNS
...BIND, then > tested. Seems like it was working. I forced the 2003 machine out, > cleaned > up the meta data and everything seemed to be working ok. So I raised > the > domain level like this > > samba-tool domain level raise > samba-tool domain level raise --domain-level=2008_R2 > samba-tool domain level raise --forest-level=2008_R2 > > everything shows as 2008_R2 > > so now I think I'm making progress. I spin up another linux box, get > it > ready to join, starts to join, then fails > > says LDAP error 16 LDAP_NO_SUCH_ATTRIBUTE - <000...
2016 Jul 07
2
Unable to transfer ForestDns/DomainDNS
...d. Seems like it was working. I forced the 2003 > machine out, cleaned up the meta data and everything seemed to > be working ok. So I raised the domain level like this > > samba-tool domain level raise > samba-tool domain level raise --domain-level=2008_R2 > samba-tool domain level raise --forest-level=2008_R2 > > everything shows as 2008_R2 > > so now I think I'm making progress. I spin up another linux > box, get it ready to join, starts to join, then fails > > says LDAP error 16...
2018 May 22
4
Functional Levels
HI!! I have one question, in samba 4.8.2 , --forest-level and --domain-level is worked 2012/2012 R2 ? samba-tool domain level --help --forest-level=FOREST_LEVEL                         The forest function level (2003 | 2008 | 2008_R2 |                         2012 | 2012_R2)   --domain-level=DOMAIN_LEVEL                         The domain function level (2003 | 2008 | 2008_R2 |                         2012 | 2012_R2) I see in wiki https://wiki.samba.org/index.php/Raising_the_Functional_Levels but dont understan.... * Fun...
2016 Jul 12
0
Unable to transfer ForestDns/DomainDNS
So you are saying samba-tool domain level raise --forest-level=2008_R2 does nothing with the schema, just changes the value that is returned when doing samba-tool domain level show? If that is the case I think it would be nice to put something like that on the wiki page about raising the functional level! I spent a ton of time trying to go from Windows 2003 directly...
2016 Jul 08
1
Unable to transfer ForestDns/DomainDNS
I bumped the logging up. samba-tool domain level raise --domain-level=2008_R2 schema_fsmo_init: we are master[yes] updates allowed[no] schema_fsmo_init: we are master[yes] updates allowed[no] The updates_allowed[no] concerns me? On Fri, Jul 8, 2016 at 9:45 AM, Jason Waters <jason at geeknocity.com> wrote: > I'm pretty sure the domain level raise is faili...
2015 Jan 11
2
Domain level 2008 and last interactive logons
...kstation The time of the last successful logon attempt at a Windows Server 2008 server or a Windows Vista workstation For more information, see Active Directory Domain Services: Last Interactive Logon (http://go.microsoft.com/fwlink/?LinkId=180387). I have tried this with a test DC on level 2008_R2. But when I create a GPO to show this information of last logon there comes an error, that this information is not stored in the AD. The user (administrator) can't logon to the Windows 7 workstation and I needed to delete the GPO link via samba-tool. Are these respective fields not created in S...
2016 Jul 07
3
Unable to transfer ForestDns/DomainDNS
On 07/07/16 17:14, Jason Waters wrote: > I'm going to keep going and see if I can get samba joined and then > migrated over. Maybe I'm still focusing on the wrong thing! Ugh.... > > On Thu, Jul 7, 2016 at 12:12 PM, Jason Waters <jason at geeknocity.com > <mailto:jason at geeknocity.com>> wrote: > > So I wanted to test if something was broke in my DC
2013 Jan 12
3
Samba4 Domain Account Lockout
First off, I apologize if this is a duplicate - I had some issues with the first email I tried to join this list with! I'm currently using samba4 as an AD DC (domain and forest are both configured with the samba-tool command to be at the 2008_R2 functional level) for both Windows and Linux systems. I've got the default password settings set using the "samba-tool domain passwordsettings" command and I have all the GPOs configured as I need them for clients. However, I would like to configure how the account lockout functions...
2015 Aug 18
2
Samba 4 DC - no AES kerberos tickets - only arcfour
...word: ⇒ Succeeds, with arcfour ticket This looks like the samba 4 DC does not offer AES encryption types at all. So I tried to raise the function level (if i recall correctly AES should be enabled with 2008 R2), however the behaviour stays the same. # samba-tool domain level raise --forest-level 2008_R2 --domain-level 2008_R2 I've reproduced this with Ubuntu 14.04.3 / Samba 4.1.6, but also with a current samba.git-Checkout - no difference so far. What am I missing here? Do I need to take some extra steps after the domain level raise to use AES? Bye, Marcel
2015 Dec 30
1
Samba 4 AD - Samba Fails to Start, hdb_samba4_create_kdc (setup KDC database) failed
...ard of it. A cursory search reveals it was implemented in alpha versions of Samba4, did I provision this domain incorrectly? Below are the commands I used when provisioning this domain: sudo samba-tool domain provision --use-rfc2307 --interactive sudo samba-tool domain level raise --domain-level 2008_R2 --forest-level 2008_R2 Thanks for your reply. JS
2023 Oct 18
1
Linux/Windows Domain Controller
If you take a look at: https://wiki.samba.org/index.php/Windows_2012_Server_compatibility You will find your error message. I think your domain is running with FL 2012 and you are using a samba version < 4.19. So you can only go up to FL 2008_R2. The new 4.19 is the first version supporting FL >2008_R2. There you can go up to FL 2016. Am 18.10.23 um 18:05 schrieb matti.kaupenjohann via samba: > DsAddEntry failed with status WERR_ACCESS_DENIED info (8567, > 'WERR_DS_INCOMPATIBLE_VERSION')
2023 Oct 18
1
Linux/Windows Domain Controller
...ania via samba wrote: > If you take a look at: > > https://wiki.samba.org/index.php/Windows_2012_Server_compatibility > > You will find your error message. I think your domain is running with > FL 2012 and you are using a samba version < 4.19. So you can only go > up to FL 2008_R2. The new 4.19 is the first version supporting FL > >2008_R2. There you can go up to FL 2016. > > > Am 18.10.23 um 18:05 schrieb matti.kaupenjohann via samba: >> DsAddEntry failed with status WERR_ACCESS_DENIED info (8567, >> 'WERR_DS_INCOMPATIBLE_VERSION') > &...
2018 May 22
1
Functional Levels
...> I have one question, in samba 4.8.2 , --forest-level and >> --domain-level is worked 2012/2012 R2 ? >> >> samba-tool domain level --help >> >> >> --forest-level=FOREST_LEVEL >>                         The forest function level (2003 | 2008 | >> 2008_R2 | 2012 | 2012_R2) >>   --domain-level=DOMAIN_LEVEL >>                         The domain function level (2003 | 2008 | >> 2008_R2 | 2012 | 2012_R2) >> >> I see in wiki >> https://wiki.samba.org/index.php/Raising_the_Functional_Levels >> >> but don...
2019 Apr 29
2
missing enctypes in exported keytab
>>> Thats a strange one.. >>> >>>> This is correct: 'dns-dc2' uses "msDS-SupportedEncryptionTypes": >>>> 31 (0x0000001f) >>> Try this first. >>> sudo samba-tool domain exportkeytab dns.keytab >>> --principal=dns-dc2 >> Same result. Cheers, >> > what is the output of 'samba-tool
2012 Nov 21
1
Failure demoting 2008_R2 DC (S4rc5)
Hello, We are currently testing S4rc5 for an upcoming S3 to S4 migration. I am able to duplicate this issue with both classicupgrade and a new provision (both cases using internal DNS). I am able to join a 2008R2 system to the domain and promote it to a DC, however I am unable to demote it. The problem appears to be that the 2008R2 server fails replicating to the S4 DC. The specific error that I
2024 Mar 20
3
Raise Domain Level, Forest Level and Schema for Bitlocker integration
On 18/03/2024 15:44, Paul Littlefield via samba wrote: > > I would like to add BitLocker integration to the three DCs we have running 4.15.13 on Ubuntu 22.04 LTS. > > The DC has been around a while and is currently on Schema version 47 and Domain level 2008_R2. > > Can I confirm that the procedure to upgrade the three DCs is as follows:- > > 1) backup > 2) upgrade domain and forest to latest 2012_R2 > 3) upgrade the schema to latest 2012_R2 > > Also, in what order of DCs should I perform these changes? > > DC5 (FSMO Role...
2015 Jan 09
4
Member Server SeDiskOperatorPrivilege
Hello all, I have a AD DC based on CentOS7 with sernet samba 4.1.14 with rfc2307 and function level 2008_R2. This one works so far and I can manage the AD from a windows client. Now I setup a member server based on CentOS7 with sernet samba 4.1.14 just like the wiki advises with the same smb.conf (realm etc is configured to my needs. I joined the AD and configured nsswitch. wbinfo works so far but gete...
2019 Apr 29
2
missing enctypes in exported keytab
...03 >> Lowest function level of a DC: (Windows) 2008 R2 >> >> root at dc1:~# >> >> Thanks, >> >> Christian >> >> > That explains it ;-) > > Try raising the functional level to 2008R2 > > samba-tool domain level raise --forest-level=2008_R2 --domain-level=2008_R2 > > Rowland > Still the same: root at dc1:~# rm -f dns.keytab root at dc1:~# samba-tool domain level show Domain and forest function level for domain 'DC=.......' Forest function level: (Windows) 2008 R2 Domain function level: (Windows) 2008 R2 Lowest funct...
2017 Jun 21
4
DRS stopped working after upgrade from debian Jessie to Stretch
...t save to use this command on all ad-dc's in an productive >> environment? > I would do it one at a time. Eventually I'll re-enable the code in > winbindd that does this. > > Andrew Bartlett Thank you works fine on an single test machine. Raise forest and domain level to 2008_R2 and recerated the password with chgrdcpass. Raising the functional level did not set the krbtgt password (it does if the level is raised on an windows ad). But there is chgkrbtgtpass which does the trick. Sorry for the offtopic noise to the OP.