Displaying 20 results from an estimated 3000 matches similar to: "Samba ADS domain member issues"
2004 Sep 02
2
Can't mount samba drive or join domain with W2K3 server
Please cc me on replies.
My employer recently upgraded to W2K3. I have no control over the
employer's set up and limited access to information. Under the old
server, everything was working fine. Now I can't mount the shared drive
anymore.
I'm running Debian sid; samba 3.0.6-3.
################################################
# mount shared_drive
cli_negprot: SMB signing is
2004 Oct 15
4
member server and kerberos
hello
i have been struggling for to long trying to setup the following
configuration:
debian samba 3 member server of a win 2000 AD
here is my configuration:
## smb.conf ##
[global]
log level = 4
interfaces = 192.168.10.11/255.255.255.0
workgroup = datom
realm = datom.dyndns.org
server string = samba membre
security = ads
netbios name = cafeine
log file = /var/log/samba/samba.log
max log size
2003 Sep 22
2
re: Anyone looking for IP Phones?
My company has approx. 500 Cisco CP-7960G IP Phones that are coming out of
service. They were deployed for about 6 months. These include the AC power
adapter and station license. We also have some other related equipment. If
someone is reading this and is interested, shoot me an email
candrews@b2llc.com
Thanks
Cory Andrews
*****************
b2 Technologies
2006 Nov 01
1
Windows != Samba - NETBIOS name handling
Hi,
I'm using samba just for its "net join" functionality. Computer accounts and kerberos keytabs are
created by Samba in Active Directory via "net ads join", then used by UNIX clients to authorise and
authenticate via LDAP and Kerberos.
Samba works perfectly until the computers hostname is longer than 15 characters. Then any attempt to
join the domain fails with:
----
2005 Jun 11
1
Problem joining a domain using ads
server: ms 2003 with ads
client: debian 3.1/samba 3.0.14
smb.conf:
..
[global]
workgroup = SP-GRUPPE
password server = 10.85.117.150
realm = SP-GRUPPE.DE
encrypt passwords = no
server string = %h server (Samba %v)
obey pam restrictions = yes
passdb backend = tdbsam, guest
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\sUNIX\spassword:* %n\n
*Retype\snew\sUNIX\spassword:* %n\n .
2004 Jun 14
2
Member Server in Active Directory
I'm trying to join a Samba 3.0.4 (compiled from source on Debian) to an
Active Directory as a member server. I believe Kerberos is configured
correctly as kinit creates a ticket for the realm. Executables appear to have
support for Kerberos and LDAP (smbd -b | grep KRB and grep LDAP) return OK.
When I try to join the AD with
net ads join -U myadminusername
I'm prompted for my
2004 Jul 20
1
Chasing the "ads_add_machine_acct: Insufficient access" problem
Okay, the jist of this whole thing, I get this infamous (?) problem, I
have been trying to search though the archives of samba-general on gmane
and also in my archive of this list. I have only seen requests for the
magical answer.
Environment: W2K/W2K3 mixed ADS going Native ADS only soon. Samba 3.0.4
compiled from source on a RHEL AS30 machine. MIT Kerberos v1.3.4 also
compiled from source.
2005 Nov 01
1
Join ADS domain - Insufficient Access
SLES 9 SP2
samba-3.0.14a-0.4
heimdal-lib-0.6.1rc3-55.15
samba-winbind-3.0.14a-0.4
pam-modules-9-18.10
pam_krb5-1.3-201.7
I've been searching for days for a concrete answer to this question:
Is it possible to join an ADS domain from a Linux Samba server without
having Administrator privileges? Yes or No.
If so exactly what are the minimal requirements for joining the Linux
box to the
2005 Dec 18
1
Lessons learned
Hello,
I would like to share few things I have learned over time in my attempt
to integrate all my Linux clients to an existing corporate Windows 2000
Active Directory (AD). I am a Linux admin for a small division in a large
company and do not posses any special rights as far as AD goes. I ONLY have
privileges on my division part of the tree in AD.
Goals:
- Integrate all Linux client to
2005 Feb 10
2
net ads join requires full domain admin account?
Problem: I have an account that allows me to join an AD domain, this works
fine from any win box. However it fails with "ads_add_machine_acct
(client_name): Insufficient access" when I do a net ads join from a linux
box. To get samba to join the domain, I have to use an account with full
domain admin privs. (ie net ads join -Ufull_domain_admin)
Is this expected behavior?
2004 Nov 02
1
net ads join fails
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
~ /usr/bin/net ads join -Udennisb
dennisb password:
[2004/11/02 17:31:56, 0] libads/ldap.c:ads_add_machine_acct(1006)
~ Host account for if-srv-hos1 already exists - modifying old account
[2004/11/02 17:31:56, 0] libads/ldap.c:ads_join_realm(1342)
~ ads_add_machine_acct: No such object
ads_join_realm: No such object
Also:
net user | wc -l
reports
2007 May 22
2
kerberos_kinit_password -- Preauthentication falied ??
Hi,
I'm fairly new to samba so apologies if this is an old problem....
When I try 'net ads join -U administrator' I get the following:
[2007/05/22 12:15:15, 0] libads/ldap.c:ads_add_machine_acct(1368)
ads_add_machine_acct: Host account for storage4 already exists -
modifying old account
Using short domain name -- ABSOLUTESTUDIOS
[2007/05/22 12:15:15, 0]
2005 Nov 08
1
ADS Join and Insufficient Access
My agency is moving all users and computers to a new domain. Our current domain uses AD and the new domain will use AD. My current samba servers are running 3.0.20a with ADS security with winbind on Debian Stable (Sarge) with no problems.
I set up a test samba server using 3.0.20b, the new krb5.conf and smb.conf.
kinit works fine. ("Authenticated to Kerberos v5")
I prestage the server
2004 Nov 23
1
CP-7960
Anyone in need of some of these?
Garrett Smith
Sales Executive
garrett.smith@b2llc.com
B2 Technologies
454 Sonwil Drive
Buffalo, NY 14225
(716) 250-3408 Direct
(716) 630-1548 Fax
(716) 903-9495 Cell
AOL IM: B2sales
Specializing in New and Used equipment from vendors including Cisco Systems,
Juniper, Adtran, Dialogic, Lucent, Nortel, Sipura, Granstream, Snom,
Mediatrix,
2004 Dec 02
3
net ads join fails - "Preauthetication failed"
After a lot of different problems and variations of krb5.conf and
samba.conf files I am currently stuck with the following error trying to
join a domain
net ads join -U nfybw@UIB.NO 'Klienter\IT\MatNat\IFT\Samba
Servers\IT-gruppen'
nfybw@UIB.NO's password:
[2004/12/02 15:34:36, 0] libads/ldap.c:ads_add_machine_acct(1367)
ads_add_machine_acct: Host account for iftsmb100 already
2004 May 21
3
Suse 9.1 Samba
I have been trying for two weeks to get onto a Win2k domain which has
active directory with no success. The Suse YAST samba client will not do
ADS, only domain, server, or user, so I went to the command line stuff I
found the the Samba documentation.
I can do kinit and get back the following:
sha-linux:/etc/samba # kinit art_fore@3MTS.COM
art_fore@3MTS.COM's Password:
kinit: NOTICE:
2005 May 16
1
Username DOMAIN\SAMBA_CLIENT1$ is invalid...
I'm seeing a lot of:
[2005/05/16 08:35:46, 1] smbd/sesssetup.c:reply_spnego_kerberos(250)
Username DOMAIN\SAMBA_CLIENT1$ is invalid on this system
in the logs on my samba server after joining our ad DOMAIN, and
accessing from SAMBA_CLIENT1 (also a member of the ad DOMAIN).
Otherwise, it appears to be functioning well.
Is this something to be worried about?
-- Rex
2005 May 23
1
CentOS 3.4 + Samba 3.0.9-1.3E.2, winbind problems
Hi all,
Thus far, I have managed to get wbinfo -[u|g] to display users/group
correctly, and getent passwd/group works. However, wbinfo -t fails to
work, giving me this error:
[root@billing samba]# wbinfo -t
checking the trust secret via RPC calls failed
error code was NT_STATUS_ACCESS_DENIED (0xc0000022)
Could not check secret
Further, this seems to be related to a problem with wbinfo -a:
2007 Feb 20
2
A problem On the integrate Samba and AD 2k3 ..
A problem On the integrate Samba and AD 2k3 ..
the page is my reference
http://www.infosecwriters.com/text_resources/pdf/AD_and_Linux_TMunn.pdf
i wnat to use users group for squid' wbinfo_group.pl use auth...
now i can join the samba server to AD domain
but i can't read user's group..
can any one tell me what is happend..
like this
[root@wxyz-dns1 samba]# wbinfo -u
2004 Dec 29
1
Samba 3.0.10 joining Windows 20003 ADS
abrams:~# kinit admin@CORP.TCC.INET
This seems to work just fine.
abrams:~# net ads join "TwinCities\TTAGS\SERVERS"
[2004/12/28 18:52:20, 0] libads/ldap.c:ads_add_machine_acct(1475)
Warning: ads_set_machine_sd: Unexpected information received
Using short domain name -- CORP
[2004/12/28 18:52:23, 0] libads/kerberos.c:get_service_ticket(335)
get_service_ticket: kerberos_kinit_password