Displaying 20 results from an estimated 2000 matches similar to: "Join ADS domain - Insufficient Access"
2005 Jun 11
1
Problem joining a domain using ads
server: ms 2003 with ads
client: debian 3.1/samba 3.0.14
smb.conf:
..
[global]
workgroup = SP-GRUPPE
password server = 10.85.117.150
realm = SP-GRUPPE.DE
encrypt passwords = no
server string = %h server (Samba %v)
obey pam restrictions = yes
passdb backend = tdbsam, guest
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\sUNIX\spassword:* %n\n
*Retype\snew\sUNIX\spassword:* %n\n .
2004 Jun 14
2
Member Server in Active Directory
I'm trying to join a Samba 3.0.4 (compiled from source on Debian) to an
Active Directory as a member server. I believe Kerberos is configured
correctly as kinit creates a ticket for the realm. Executables appear to have
support for Kerberos and LDAP (smbd -b | grep KRB and grep LDAP) return OK.
When I try to join the AD with
net ads join -U myadminusername
I'm prompted for my
2005 Nov 08
1
ADS Join and Insufficient Access
My agency is moving all users and computers to a new domain. Our current domain uses AD and the new domain will use AD. My current samba servers are running 3.0.20a with ADS security with winbind on Debian Stable (Sarge) with no problems.
I set up a test samba server using 3.0.20b, the new krb5.conf and smb.conf.
kinit works fine. ("Authenticated to Kerberos v5")
I prestage the server
2004 Nov 02
1
net ads join fails
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
~ /usr/bin/net ads join -Udennisb
dennisb password:
[2004/11/02 17:31:56, 0] libads/ldap.c:ads_add_machine_acct(1006)
~ Host account for if-srv-hos1 already exists - modifying old account
[2004/11/02 17:31:56, 0] libads/ldap.c:ads_join_realm(1342)
~ ads_add_machine_acct: No such object
ads_join_realm: No such object
Also:
net user | wc -l
reports
2004 May 21
3
Suse 9.1 Samba
I have been trying for two weeks to get onto a Win2k domain which has
active directory with no success. The Suse YAST samba client will not do
ADS, only domain, server, or user, so I went to the command line stuff I
found the the Samba documentation.
I can do kinit and get back the following:
sha-linux:/etc/samba # kinit art_fore@3MTS.COM
art_fore@3MTS.COM's Password:
kinit: NOTICE:
2004 Jul 20
1
Chasing the "ads_add_machine_acct: Insufficient access" problem
Okay, the jist of this whole thing, I get this infamous (?) problem, I
have been trying to search though the archives of samba-general on gmane
and also in my archive of this list. I have only seen requests for the
magical answer.
Environment: W2K/W2K3 mixed ADS going Native ADS only soon. Samba 3.0.4
compiled from source on a RHEL AS30 machine. MIT Kerberos v1.3.4 also
compiled from source.
2005 May 24
1
ADS join troubles 3.0.14a
Hi List,
I'm attempting to join a win2k3 domain as a member server with great difficulty.
I've read The HowTo, but am hung when attempting to join the Domain. I can kinit & klist
Which seems good, but the ads join fails.
Can someone help me understand what is causing the error listed below?
Component particulars are:
RH AS3, samba-3.0.14a compiled from source (./configure
2006 Nov 01
1
Windows != Samba - NETBIOS name handling
Hi,
I'm using samba just for its "net join" functionality. Computer accounts and kerberos keytabs are
created by Samba in Active Directory via "net ads join", then used by UNIX clients to authorise and
authenticate via LDAP and Kerberos.
Samba works perfectly until the computers hostname is longer than 15 characters. Then any attempt to
join the domain fails with:
----
2005 May 31
1
Samba AD member
hello
have such problems with my samba 3.0.12 @ FreeBSD 5.4
we have an Active Directory here. and a domain.
root@freeway# testparm
Load smb config files from /usr/local/etc/smb.conf
Processing section "[public]"
Processing section "[private]"
Loaded services file OK.
Server role: ROLE_DOMAIN_MEMBER
Press enter to see a dump of your service definitions
# Global parameters
2004 May 21
0
Insufficient access error
I've been working on getting Samba 3.0.4-2 to join our test W2k3 Active
Directory for most of the day. When I try to join with this command :
net ads join -U w702a-palmadesso "w702\NonCatComputers"
According to my official Samba HowTo Book this should join the domain
specified in my smb.conf. Instead I get the following output :
[root@w72l-tux samba]# net ads join -U
2006 May 22
1
Join ADS problem
Problem with join to Active Directory
[root@clust-master samba]# net ads join -S 10.0.0.1 -U Administrator
Administrator's password:
[2006/05/22 10:24:05, 0] libads/ldap.c:ads_join_realm(1640)
ads_add_machine_acct (clust): Type or value exists
ads_join_realm: Type or value exists
[root@clust-master samba]# kinit Administrator@COROD.LOCAL
Password for Administrator@COROD.LOCAL:
As you can
2005 May 27
1
ADS Join problem samba3.0.14a kerberos 1.3.5
Hi List,
I'm getting an error join an ADS Domain, using samba 3.0.14a & kerberos
1.3.5.
When I look at the debug output from the join attempt, it almost seems
as though
The join is looking for an OU or something from the AD that doesn't
exist. I'm not an
Windows person and the AD admins are not around to help peep this out.
Can anyone take a look at the debug output below and
2005 Jul 20
5
Samba Server not using domain users as samba users
Good evening everyone:
I am struggling with a problem here.
I have a brand new FC3 server set up. My Windows domain is a windows 2003 active directory domain.
I have samba configured as below
[global]
netbios name = SRVWEB-01
server string = MCA Production Web Server
printing = cups
idmap gid = 15000-20000
password server = srvdc01
idmap
2004 May 20
6
net ads join hangs forever
I am trying to join my Linux workstation to my ADS domain.
Unfortunately, I'm not having much success. net ads join hangs forever
(or at least for more than 12 hours) when run. The computer account is
created in the domain, but the process never completes. tdbdump
secrets.tdb shows no results, and wbinfo shows users and groups from the
trusted domains but not from the domain I am trying to
2004 Sep 02
2
Can't mount samba drive or join domain with W2K3 server
Please cc me on replies.
My employer recently upgraded to W2K3. I have no control over the
employer's set up and limited access to information. Under the old
server, everything was working fine. Now I can't mount the shared drive
anymore.
I'm running Debian sid; samba 3.0.6-3.
################################################
# mount shared_drive
cli_negprot: SMB signing is
2004 Nov 17
0
Authenticating off a Windows 2003 ADS DC with Samba/Winbind
[originally posted to fedora-users]
I'm having difficulty getting samba/winbind to authenticate of a W2K3
box. I've searched the list archives and although there
are some similar problems, none have seemed to help resolve this one.
Here's the network configuration:
- Windows 2003 Server gx270-rmaniar [192.168.0.100]
- Fedora Core 3 gx280rmaniarFC3 [192.168.0.5]
FYI: A Windows XP box
2004 Mar 10
0
Followup to previous request
As a followup to my previous question, here is the debug log of the issue:
[root@bonair samba]# net join -U dchait -d 10
[2004/03/10 13:49:23, 5] lib/debug.c:debug_dump_status(360)
INFO: Current debug levels:
all: True/10
tdb: False/0
printdrivers: False/0
lanman: False/0
smb: False/0
rpc_parse: False/0
rpc_srv: False/0
rpc_cli: False/0
passdb: False/0
2008 Nov 13
1
Domain Member Server problems
Hi all,
I'm not having any success adding samba (3.0.28 on Solaris 10) to a Windows
AD server (2003 R2) per the instructions here: (In addition to much
googling)
http://us3.samba.org/samba/docs/man/Samba-Guide/unixclients.html#adssdm
The error is:
bash-3.00# /usr/sfw/sbin/net ads join -U Administrator
Administrator's password:
Using short domain name -- BETA
Failed to set
2009 Mar 19
1
Can join ADS domain, all accounts/auth work fine, but leaving domain fails
Hello all,
As the subject says, as far as I can tell everything works on my ads
integrated samba server. Domain accounts can be used for ssh, and
accessing shares, I just can't leave the domain. Here is a successful
join command followed by an unsuccessful leave command at debug level 4.
Any ideas?
TIA,
Mark
user@dordal:~$ sudo net ads join -U administrator@MYDOMAIN.COM -d 4
[2009/03/19
2008 Apr 01
1
Strong(er) authentication required when joining Active Directory (Samba 3.0.28)
Hello all,
I'm having problems getting Samba to join a Windows AD. I am delegated
OU admin, and have no direct access to the domain controller. We have 3
DCs in one domain where my OU exists. The users I wish to authenticate
are in a different domain.
I have set up Kerberos and can receive tickets correctly.
I run
net -d 4 ads join createcomputer=[Delegated OU] -U [account with join