Displaying 20 results from an estimated 400 matches similar to: "temporary problems with authorization in windows domain"
2015 Sep 19
0
is R syntax closed?
> comment, some marker for 'command doesn't end at this line' etc.
That is not necessary since R supports multi-line commands without the need
for marking continuation.
> R syntax done and any extensions are forbidden?
R is maintained and extended by the R code team[1] who decide on the GNU R
project. Suggestions (or sometimes patches) are posted on this list and may
or may
2006 Mar 14
3
Daily changetrustpw breaks authentication
Samba 3.0.21b
The Samba docs indicate [0] we should be running changetrustpw [1] at some
point (cron.daily) to update a machines trust account.
However, I've seen multiple instances with 2 seperate AD environments
where this breaks our ability to enumerate/authenticate with the domain.
In both instances, we see something similar to the following in the
winbind logs:
(ntlm_auth):
2015 Aug 19
1
net ads changetrustpw on Samba4 DC (4.2.3)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hey,
I'm running a Samba4 DC domain and I'd like to change the machine
trust password of the current DC. This doesn't seem possible using net
ads changetrustpw or net rpc changetrustpw on the DC itself, and I
can't seem to find any command in samba-tool to achieve this.
Is there any way to change the trust password of the DC?
- --
2024 Mar 03
2
'Scripted' machine account renewal?!
Mandi! Kees van Vloten via samba
In chel di` si favelave...
> There is "net changetrustpw" to do this.
I've correctly just joined the firewall to the domain, i can check join
status:
root at vfwacpn1:~# net ads testjoin
Join is OK
but if i try to renew credentials i catch:
root at vfwacpn1:~# net ads changetrustpw -I 10.172.1.8
Changing password for principal:
2024 Mar 03
1
'Scripted' machine account renewal?!
On Sun, 3 Mar 2024 16:12:04 +0100
Marco Gaiarin via samba <samba at lists.samba.org> wrote:
> Mandi! Kees van Vloten via samba
> In chel di` si favelave...
>
> > There is "net changetrustpw" to do this.
>
> I've correctly just joined the firewall to the domain, i can check
> join status:
>
> root at vfwacpn1:~# net ads testjoin
> Join is
2025 May 02
1
procedure to change DC password
Hello,
net ads changetrustpw
this command works fine on domain members, but on domain controller
there is hard fail with:
ads_change_trust_account_password: Machine account password change only
supported on a DOMAIN_MEMBER
W dniu 23.04.2025 o?15:32, Rowland Penny via samba pisze:
> net ads changetrustpw
--
Ta wiadomo?? e-mail zosta?a sprawdzona pod k?tem wirus?w przez oprogramowanie
2025 May 02
1
procedure to change DC password
Hi Kacper,
maybe you've overlooked my answer from April 23th.
Kees has written a script especially for this:
See "dc_password_change" on
https://github.com/kvvloten/samba_integrations/tree/main/domain_controller/manage_scripts
This script works in my AD without problems for some time...
Regards
Ingo
https://github.com/WAdama
Kacper Wirski via samba schrieb am 02.05.2025 um
2024 Jun 06
1
'Scripted' machine account renewal?!
Op 24-03-2024 om 17:42 schreef Marco Gaiarin via samba:
> Mandi! Kees van Vloten via samba
> In chel di` si favelave...
>
>> Solution is easy: upgrading winbind from Debian backports solves the issue !
> I've upgraded to latest buster version 4.18.10+dfsg-1~buster, but still does
> not work for me...
>
> Now display:
>
> root at vfwacpn1:~# net ads
2007 Aug 22
1
winbind problem, have workaround but...
Greetings list,
I have a member server in a w2k3 AD domain that has been happily spinning
for a couple of years. As of yesterday morning, we've been having some
issues with it. I've had it configured correctly, and haven't touched it.
I'll provide the configs if needed.
I've kept it updated as time's gone on for security updates etc..
the wonkyness seems to rear is
2018 Jul 27
0
Winbind Craziness
so I had some time to follow this bunny trailand found that even though all the other servers had no problems this one continued to.Every so often a new computer couldn't connect and then it would be all better after a net leave/net join.
Net join would not work without -S <MyDC> in the command lineWhat I found out was that most net rpc commands such as net rpc testjoin would also fail
2024 Feb 25
2
'Scripted' machine account renewal?!
On 25-02-2024 11:56, Marco Gaiarin via samba wrote:
> I need to access the LDAP AD server from a debian box, but i don't need
> shares nor winbind.
>
> For a sake of simplicity i'm thinking to use machine account (-P).
There is "net changetrustpw" to do this.
When you domain-join the machine the machine password is managed by
winbind, so you don't need to this.
2024 Mar 24
3
'Scripted' machine account renewal?!
Mandi! Kees van Vloten via samba
In chel di` si favelave...
> Solution is easy: upgrading winbind from Debian backports solves the issue !
I've upgraded to latest buster version 4.18.10+dfsg-1~buster, but still does
not work for me...
Now display:
root at vfwacpn1:~# net ads changetrustpw
get_kdc_ip_string: get_kdc_list fail NT_STATUS_NO_LOGON_SERVERS
Changing password for
2025 Apr 23
3
procedure to change DC password
On Wed, 23 Apr 2025 14:35:16 +0200
Kacper Wirski via samba <samba at lists.samba.org> wrote:
> What is the best approach to change samba ad dc's own password?
> Windows machines change periodically, linux domain members can simply
> re-join domain, but when it comes to DC's I can't find any
> recommended steps? Is re-joining domain as domain controller viable
>
2024 Mar 04
1
'Scripted' machine account renewal?!
On 04-03-2024 21:54, Rowland Penny via samba wrote:
> On Mon, 4 Mar 2024 14:14:18 +0100
> Marco Gaiarin via samba <samba at lists.samba.org> wrote:
>
>> Mandi! Kees van Vloten via samba
>> In chel di` si favelave...
>>
>>> Interesting, I tried running it with -d 10, it shows a lot of
>>> output.
>> The same. My output is a bit more
2024 Feb 26
1
'Scripted' machine account renewal?!
Mandi! Kees van Vloten via samba
In chel di` si favelave...
>> For a sake of simplicity i'm thinking to use machine account (-P).
> There is "net changetrustpw" to do this.
Ok, i've missed that. Thanks.
> If you just have a service that does LDAP-queries, I would create an
> ordinary user-account for it (and start it's name e.g. with "svc_").
2006 Mar 22
4
How to write this SQL query?
Hi!
Is there rails version of "where column in (value1, value2, ...)"?
I know i could do OR many times, but this way is shorter.
I''m ruby/rails newbie, so i have a problem with converting the hash,
which i''m receving from the search form into the string for :conditions
in find method.
Could i instead of creating one, complicated (for me) query do something
like
2007 Jul 07
1
AD domain membership problem
Hello, and thanks in advance for any assistance.
I have a linux machine that I'm trying to join to a windows 2003 sp1
active directory. The specifics are:
RHEL5, samba version samba-3.0.23c-2.el5.2.0.2
a firewall between this server and the rest of the world (which includes
the DCs), ports are open for kerberos and CIFS inbound and kerberos,
CIFS, NTP and UDP oubtound.
this machine
2019 Sep 21
2
Dovecot proxying to some backend using LOGIN proxy_mech
Hello list,
I am currently testing a setup for a PoC wit this configuration.
- 1 x Frontend dovecot for proxying IMAP/POP3/LMTP/ManageSieve/Submission
- 2 x Backend dovecot with local mail storage
The frontend does the user authentification and communicate with the backends using a master password
The fronted accepts PLAIN and LOGIN auth mechanisms and talk with backends using PLAIN auth
2016 Dec 06
2
winbind terminates after machine password change and needs domain rejoin
Hello,
Samba 4.4.7 AD member on Linux SLES 12 here ...
We've been running flawlessly for weeks with version 4.4.5 until we updated to 4.4.6 and experienced this bug: https://bugzilla.samba.org/show_bug.cgi?id=12369
So we updated to 4.4.7 in which this issue was fixed with an interim downgrade to version 4.4.5 until 4.4.7 was available.
Now, we're experiencing another issue and it seems
2004 Dec 01
0
Samba 3.0.9 with W2003 ADS, Segmentation fault
Hello,
My System:
Debian woody
Samba-3.0.9
build with:
./configure --prefix=/opt/samba-3.0.9 --exec-prefix=/opt/samba-3.0.9
--with-ads --with-winbind
make
make install
if i want to join to the W2003 ADS Domain with
/opt/samba/bin/net ads join -U Administrator
i see the following errors
Using short domain name -- TESTDOMAIN
[2004/12/01 12:32:07, 0] libads/kerberos.c:get_service_ticket(335)