Displaying 20 results from an estimated 30000 matches similar to: "Kerberos errors during ads operations"
2014 May 09
1
samba4 : [kerberos part kinit work but no kpasswd
hi,
?
i have recently installed a samba 4 in a DC role.
The distribution is a debian jessie/sid, the version of samba is 4.1.7.
The server is globally working but there is some litle trouble.
on the server itself, i can do a kinit without probleme but if i try a kpasswsd, i obtain the following
?
root at station:/var/log/samba# kinit
Password for administrator at TOTO.FR:
root at
2007 Mar 04
1
net ads join to w2k3 hangs, every encryption type fails
I am able to get a kerberos ticket with kinit. When I try to net ads join, it seems to loop. In running net ads join in -d 10,
I found that it tries enctypes 18,17,16,and 2 and then repeats, over and over. It does not seem to work on any of these. I'm
trying to get it to join a win2k3 domain. Below is the bottom part of the log from net ads join, as well as some of my
krb5.conf. Any
2018 Feb 05
1
Using Samba AD for NFSV4 Kerberos servers and clients
Hello Kevin,
We have a Samba/Windows20008R2 domain that's been running a few years now.
Here are the details:
* clients auth with SSSD (ldap, kerberos, ldap_schema=rfc2307bis)
* idmap
* samba on clients/server for joining domain
We have scripts that automatically create users with UnixHomeDir, UID
and GUID numbers within AD.
I don't know about using WInbind... I dropped that
2024 Jun 26
1
Kerberos issues
On Wed, 26 Jun 2024 14:00:03 +0300
?????? ??????? via samba <samba at lists.samba.org> wrote:
> Hello Samba community!
>
> I have an legacy system with 7 Windows VM.
> In this system, the domain user is used to run services and interact
> with individual parts.
> I also have one PC on a domain from which I can run RSAT and can
> check the Zentyal webconfig.
>
>
2019 Nov 29
2
security = ads parameter not working in samba 4.9.5
Hi Rowland,
I get below error while running the script again.
bash samba-collect-debug-info.sh > samba-output
kinit: Client's credentials have been revoked while getting initial
credentials
cat samba-output
Please wait, collecting debug info.
Wrong password or kerberos REALM problems, exiting now.
Below is my /etc/krb5.conf
[libdefaults]
default_realm = EMEA.MEDIA.GLOBAL.LOC
2024 Jun 26
2
Kerberos issues
Hello Samba community!
I have an legacy system with 7 Windows VM.
In this system, the domain user is used to run services and interact
with individual parts.
I also have one PC on a domain from which I can run RSAT and can check
the Zentyal webconfig.
domain controller objectVersion: 47
#samba-tool domain level show
Domain and forest function level for domain
Forest function level: (Windows)
2004 Jul 19
1
Windows 2003 AD/Kerberos Ticket error
I'm attempting to configure Samba 3.0.4 to work with Windows 2003 Active
Directory, mapping users' home directories automatically. Currently we
use this method in production with Windows 2000 but wish to migrate to
2003. The problem seems to be Kerberos related. I was able to join the
Linux box (RedHat 9) to the AD. I can do a "kinit <username>"
successfully. Klist shows a
2020 Oct 30
1
Samba4 ROLE_STANDALONE vs Kerberos = NT_STATUS_LOGON_FAILURE
>
I do not understand why you are doing this, for kerberos to work
correctly, you need to be able to find everything easily and everything
must be using the same time. So, you need kerberos, a dns server and an
ntp server and if you want more than authentication, you need a
fileserver. OH look, I just described Active Directory ?
Not saying you cannot get this setup to work, but why are
2014 May 09
0
(no subject)
hi,
?
i have recently installed a samba 4 in a DC role.
The distribution is a debian jessie/sid, the version of samba is 4.1.7.
The server is globally working but there is some litle trouble.
on the server itself, i can do a kinit without probleme but if i try a kpasswsd, i obtain the following
?
root at station:/var/log/samba# kinit
Password for administrator at TOTO.FR:
root at
2005 Feb 16
1
RedHat+Samba+Winbind to ADS
Hi,
I 've a gateway and I want to use squid authenticated with Windows 2000
Active Directory users.
I've a development platform with Debian/Sarge as gateway, and it works.
(samba 3.0.10-1 and Kerberos 1.3.6-1)
On the other side the production platform uses RedHat Enterprise AS3,
initially with Samba 3.0.6 and Kerberos 1.2.7-28. I was not able to use
Active directory groups without get
2018 Nov 23
0
Setup a Samba AD DC as an additional DC
Samba 4.7.6 Ubuntu
/etc/hosts:
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
# The following lines are desirable for IPv6 capable hosts
::1 localhost ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
ff02::3 ip6-allhosts
/etc/resolv.conf:
# This file is managed by man:systemd-resolved(8). Do
2007 May 29
5
Restricting to a subset of the domain controllers on a site
Had a situation where users could not map drives from Windows XP to
Solaris 9 system running Samba-3.0.10 for Active Directory. This
system has been running for a couple of years without problems. Now
recently, the site administrators have added some new servers to the
domain which may have introduced a problem.
This krb5.conf file has been modified to hide the site in question.
[libdefaults]
2008 Oct 13
1
heimdal/AD documentation
as i promise last week, a incomplete documentation about configuring a trust
beetween a heimdal kdc and a windows AD domain
really sorry for non-french speakers
of course, i'm very interresting in any feedback...
Pascal
configuration
- le realm Kerberos est DEMO.LOCAL
- le realm du domaine AD est ad.demo.local
La configuration du KDC lui m?me ne pr?sente pas de difficult?
2007 Apr 25
0
[Samba4] KDC
Hello,
I've installed a samba4 server and now I've tried to get a kerberos ticket,
like this:
base:/usr/local/samba# kinit stefan
stefan@SAMBA4.LOCAL's Password:
kinit: converting creds: Invalid argument
I'm using heimdal-clients (0.6.3) and samba4 svn r22508. My krb5.conf test
configuration:
[libdefaults]
default_realm = SAMBA4.LOCAL
kdc_timesync = 1
2005 Sep 01
2
Kerberos problem with net ads join under AIX
Hello!
If i try a net ads join i get a kerberos error , but my kerberos works
fine, i can do a kinit,klist and so on.
the error i get is the following.
[2005/09/01 08:02:16, 0] libads/kerberos.c:ads_kinit_password(146)
kerberos_kinit_password root@MY.DOMAIN.COM failed: Cannot resolve network
address for KDC in requested realm
[2005/09/01 08:02:16, 0] utils/net_ads.c:ads_startup(191)
2006 Sep 12
0
Samba, winbind, krb5 Auth problem
Hi all
I'm actually trying to setup an AD authentication on linux workstations.
- I've setup an windows AD 2003 server, which work fine.
- I've setup linux redhat 4 enterprise server (used as a workstation for the moment)
- On the redhat, I already have setup smb.conf, krb5.conf, nsswitch.conf, pam.d/login, pam.d/system_auth. I have pasted all these files below.
==> I get
2010 Aug 20
0
samba and kerberos tickets
Hi,
I'm running a mixed linux/Windows network with authentication done using
Active Directory. The Linux clients use Samba/Winbind for
authentication (with help from the list, thanks!). I've setup smb.conf
such that doing 'net ads join -Uadministrator' populates
my /etc/krb5.keytab (see configuration files below).
klist shows me a nice set of principals from /etc/krb5.keytab
2020 Oct 01
2
Kerberos ticket lifetime
On 9/30/2020 7:23 PM, Jason Keltz wrote:
> On 9/30/2020 4:11 PM, Remy Zandwijk via samba wrote:
>
>>> On 30 Sep 2020, at 21:42, Jason Keltz via samba
>>> <samba at lists.samba.org> wrote:
>>>
>>>
>>> On 9/30/2020 3:01 PM, Remy Zandwijk via samba wrote:
>>>>>>> On the client, add:
>>>>>>>
2007 Jun 25
0
KDC Lookup errors only on ads joins.
Hi,
As I recall, 3.0.25a creates it's OWN krb5.conf file based on info it gets back from the DC to try to handle site stuff (so it uses the 'nearest' kdc, etc). I forget exactly how this mech. works, but if the kdc returned with the site info (which subsequently gets built into samba's personal 'krb5.conf' file) is down, or replication is off, your kinit would work,
2007 Jan 09
0
Can't get kerberos ticket with samba 3.0.23d and Windows Server 2k3 SP1
Hi,
i've installed Samba 3.0.23d on Solaris 10 (SPARC) with MIT Kerberos
1.5.1, openLDAP 2.3.30 and openSSL 0.9.8d.
I have 2 Windows Server 2003 SP1 Domain Controller and about 20 Windows
XP SP2 clients.
My problem is that i can't get a kerberos ticket to join the domain.
If i try to get a ticket with 'kinit Administrator@PONTOS.LOCAL' i get
always the error
kinit(v5): KDC