Displaying 20 results from an estimated 2000 matches similar to: "samba v3b3, SuSE 8.0 enterprise, heimdal 0.6, openssl ADS issues"
2003 Oct 21
2
krb5_cc_get_principal failed (No such file or directory)
Hello,
I am using the brand new SuSE 9.0 with Samba 3.0.0.
I installed:
Heimdal kerberos development libraries 0.6-67,
Openldap development libraries 2.2.22-65,
which are shipped with the distribution.
If I running "kinit administrator@NWTRADERS.COM" I am getting a ticket.
But if I try to run "net ads join -U administrator@NWTRADERS.COM" I am
getting following messages:
2004 Mar 26
2
kerberos problem
# smbclient -k -L //radius/music$
krb5_get_credentials failed for radius$@SBRC.LOCAL (Unknown
error -1765328352)
spnego_gen_negTokenTarg failed: Unknown error -1765328352
session setup failed: NT_STATUS_OK
# wbinfo -u
Error looking up domain users
log:
[2004/03/26 10:48:30, 1] libsmb/clikrb5.c:ads_krb5_mk_req(276)
krb5_get_credentials failed for shadow$@SBRC.LOCAL (Unknown
error -1765328343)
2006 Feb 16
1
kerberos error when users in trusted win2k domain try to browse samba server
I have users from Domain A trying to browse a domain member samba server in
Domain B. Domain A and Domain B are both Windows 2k domains. Domain B has
a one way trust to A. A users can browse Domain B Windows server with no
problem so I no the trust is fine. Samba version is 3.0.21b on RH Linux ES
3.
The winbindd log is giving me the following error:
[2006/02/16 08:28:50, 0]
2003 Sep 10
1
Trouble joining a W2K3 Native Mode Domain
Hi Guys,
I'm having trouble with joining a W2K3 Native Mode Domain.
Can anyone point me in the right direction to look for answers?
I intslled from rc3 SRPM. When I do:
net ads join DOMAIN -U domadm@REALM -d10
I get this error towards the end.
Thanks,
Dulantha.
....
....
[2003/09/10 17:48:27, 3] libads/sasl.c:ads_sasl_spnego_bind(184)
got OID=1 2 840 113554 1 2 2 3
[2003/09/10
2009 Sep 23
2
winbind and smb tries to auth as pdc$ rather than local name when using ADS
Hi all,
I've been working on getting Samba to authenticate via ADS for the
past few weeks with some lack of success. I had somewhat of a
breakthrough the other day realizing that the problem was related to
the kerberos authentication between Samba and the Win 2008 R2 AD
server. Trying to fix this I generated a keytab with ktpass which I
uploaded to the server.
I've been successful to
2003 Sep 30
2
Trouble with 'NET ADS JOIN'
Hi All,
Any clues as to what is causing this? I have seen similar questions asked
before in regards to joining ADS domain but have not been able to find a
solution to my problem.
The domain is a Native mode ADS on win2k3 with signing required. Please let me
know if additional info or logs are required to diagnose the problem.
I did a 'net ads join ADSDOM -U
2009 Mar 19
1
Can join ADS domain, all accounts/auth work fine, but leaving domain fails
Hello all,
As the subject says, as far as I can tell everything works on my ads
integrated samba server. Domain accounts can be used for ssh, and
accessing shares, I just can't leave the domain. Here is a successful
join command followed by an unsuccessful leave command at debug level 4.
Any ideas?
TIA,
Mark
user@dordal:~$ sudo net ads join -U administrator@MYDOMAIN.COM -d 4
[2009/03/19
2004 Dec 01
2
AD Domain member not authenticating
I had samba working, then I tried (unsuccessfully) to setup ssh pam auth.
Now users are prompted for a password when accessing shares, but no password
works. I am using Redhat AS 3, samba-3.0.9-1, and krb5-1.3.
I forgot to backup pam file system-auth before modifying things, so I'm not sure if that is the problem.
-------------------------------
These commands succeed:
wbinfo -u,
2008 Nov 05
1
Samba, Solaris, Windows 2008 - Kerberos Guess Realm Wrong?
I've just built Samba 3.2.4 on Solaris 10, with ADS support. Domain join
to a Windows 2008 domain works perfectly, having pre-created the
servername in the appropriate OU.
In my winbind logs, I see the following (domain name obfuscated):
[2008/11/05 11:28:06, 3]
libsmb/cliconnect.c:cli_session_setup_spnego(839)
got principal=not_defined_in_RFC4178@please_ignore
[2008/11/05 11:28:06,
2009 May 06
1
Kerberos and 2008 AD troubles
I've been trying to get Kerberos to work for the last couple of days so
that we can use SSO. I can't seem to get past a roadblock and Google
doesn't seem to provide any answers. I've got Samba connected to the AD
and running. I can wbinfo everything and can login to the machine using
PAM with the pam_winbind modules just fine. I can get user tickets just
fine. When I try to get ssh
2006 May 22
1
Join ADS problem
Problem with join to Active Directory
[root@clust-master samba]# net ads join -S 10.0.0.1 -U Administrator
Administrator's password:
[2006/05/22 10:24:05, 0] libads/ldap.c:ads_join_realm(1640)
ads_add_machine_acct (clust): Type or value exists
ads_join_realm: Type or value exists
[root@clust-master samba]# kinit Administrator@COROD.LOCAL
Password for Administrator@COROD.LOCAL:
As you can
2010 Jun 07
1
resolve KDC network address error
Hello Samba-List-Users
I have a problem with KDC network name resolution. I tried to google it
and sought help on IRC#samba, to no avail. So I'll post my problem here.
In the spirit of privacy and normalization all server names in this post
are replaced. CAPTIAL server names are actually capitalized in the
configuration files.
Setup:
1x Debian5 x64 server running samba 3.2.5
2x Windows
2007 Mar 04
1
net ads join to w2k3 hangs, every encryption type fails
I am able to get a kerberos ticket with kinit. When I try to net ads join, it seems to loop. In running net ads join in -d 10,
I found that it tries enctypes 18,17,16,and 2 and then repeats, over and over. It does not seem to work on any of these. I'm
trying to get it to join a win2k3 domain. Below is the bottom part of the log from net ads join, as well as some of my
krb5.conf. Any
2006 Feb 16
3
Authenticating another domain
When I attempt to authenticate a user from another domain, I am seeing
some strange issues. My winbindd.log shows that I am indeed already
trusting the other domain. (I am a member of the na.uis.unisys.com
domain.) However, when I try to gain access to a share where the
username EU\INBLR-AUTH1 has access, I get prompted for a username and
password over and over. Obviously, it can't
2008 Nov 21
2
Failed to join domain
hi all,
I've got an issue during a machine join, my kerberos setup seem to be
good (tested with kinit), my current version of samba is : samba
2:3.2.3-1ubuntu3
Example :
net ads join -U adm-tsondag
Enter adm-tsondag's password:
Failed to join domain: failed to set machine spn: Out of memory
We've got a very complex AD setup with something like 16 AD servers on
distant sites, if you
2003 Oct 13
1
winbindd: krb5_cc_get_principal failed
Hiya,
I'm using Fedora Test 2 and Samba 3.0.0-15 packages from Redhat/Fedora rawhide
with a Windows 2003 Server. I'm also using MIT Kerberos 1.3.1.
Everytime winbindd ist started, it writes following error into
/var/log/samba/winbindd.log:
[2003/10/13 10:13:40, 1] nsswitch/winbindd.c:main(832)
winbindd version 3.0.0-15 started.
Copyright The Samba Team 2000-2003
[2003/10/13
2003 Jun 25
1
KDC has no support for encryption type
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I'm using samba 3.0.0beta1.
When I try join ADS I got error:
# net ADS JOIN -U Administrator
[2003/06/25 13:03:34, 1] param/loadparm.c:lp_do_parameter(3103)
~ WARNING: The "winbind uid" option is deprecated
[2003/06/25 13:03:34, 1] param/loadparm.c:lp_do_parameter(3103)
~ WARNING: The "winbind gid" option is deprecated
2008 Jun 04
3
Can't join AD anymore after migration to 3.0.30
After migrating from 3.0.26a to 3.0.30 I cannot join my AD member server
to the domain anymore:
I get a DCERPC_FAULT_INVALID_TAG.
As I didn't change my Windows 2000 SBS Server, this looks like a new
feature in Samba 3.0.30.
Do I have to also migrate my Heimdal - if so, which version is required?
Kind regards,
Jens
P.S: Is there a way to find out the code changes in Samba 3.0.30?
I
2007 Dec 18
2
SAMBA ADS integration - windows user account rights
Hi all,
first of all is it possible to join a Linux machine to AD using a
windows user account that is not a member of the group Domain Admins?
Cause when I do this I get the following error while executing `net ads
join -d 3 -U syncuser`:
#net ads join -d 3 -U syncuser
[2007/12/11 13:47:12, 3] param/loadparm.c:lp_load(4953) lp_load:
refreshing parameters
[2007/12/11 13:47:12, 3]
2002 Oct 31
2
Error joining Win2K domain: ads_connect: DSA is unavailable
I'm running 3.0alpha (both current CVS pull and alpha20 from dist) and trying to have my samba server join our already in place Win2K ADS domain. I am able to 'kinit user@DOMAIN' and auth successfully, but upon attempting 'net ads join', I get the following:
# net ads join -Uadministrator
administrator password:
[2002/10/31 05:11:19, 1] libsmb/clikrb5.c:krb5_mk_req2(63)