Displaying 3 results from an estimated 3 matches for "bfdi".
Did you mean:
bfd
2018 Aug 11
2
samba AD member does not renew kerberos ticket [kerberos_kinit_password BONN$@DOMAIN.DE failed: Preauthentication failed]
...krb5.keytab timestamp is from the last manual join.
# cat /etc/krb5.conf
[libdefaults]
default_realm = DOMAIN.DE
dns_lookup_realm = false
dns_lookup_kdc = true
ticket_lifetime = 24h
forwardable = yes
smb.conf
[global]
netbios name = BONN
workgroup = BFDI
security = ADS
realm = DOMAIN.DE
log level = 2 smb:4 winbind:6
idmap config *:backend = tdb
idmap config *:range = 70001-80000
idmap config DOMAIN:backend = ad
idmap config DOMAIN:schema_mode = rfc2307
idmap config DOMAIN:range = 500-40000
idmap_ldb use:rfc2307 = Yes...
2018 Aug 11
0
samba AD member does not renew kerberos ticket [kerberos_kinit_password BONN$@DOMAIN.DE failed: Preauthentication failed]
...etc/krb5.conf
> [libdefaults]
> default_realm = DOMAIN.DE
>
> dns_lookup_realm = false
> dns_lookup_kdc = true
> ticket_lifetime = 24h
> forwardable = yes
>
> smb.conf
> [global]
> netbios name = BONN
> workgroup = BFDI
> security = ADS
> realm = DOMAIN.DE
>
> log level = 2 smb:4 winbind:6
>
> idmap config *:backend = tdb
> idmap config *:range = 70001-80000
> idmap config DOMAIN:backend = ad
> idmap config DOMAIN:schema_mode = rfc2307
> idmap config DOMAIN:r...
2018 Aug 11
2
samba AD member does not renew kerberos ticket [kerberos_kinit_password BONN$@DOMAIN.DE failed: Preauthentication failed]
...n 11.08.2018, 14:55 +0100 schrieb Rowland Penny via
samba:
> > idmap config DOMAIN:backend = ad
> > idmap config DOMAIN:schema_mode = rfc2307
> > idmap config DOMAIN:range = 500-40000
>
> Is 'DOMAIN' a typo ? or did you not bother 'sanitising' 'BFDI' above ?
I overlooked the workgroup entry when "sanitising". sorry for
confusing.
> > idmap_ldb use:rfc2307 = Yes
>
> Why have you got a line meant for a Samba AD DC in your Unix domain
> member smb.conf ?
Then it is not intended.
> > wins server = 10.1...