Displaying 20 results from an estimated 11000 matches similar to: "Failed to establish your Kerberos Ticket cache due time differences with the domain controller"
2018 Jul 21
4
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On Sat, 21 Jul 2018 18:59:08 +0100
Rowland Penny via samba <samba at lists.samba.org> wrote:
> On Sat, 21 Jul 2018 18:30:48 +0100
> Roy Eastwood via samba <samba at lists.samba.org> wrote:
>
> > Thanks Rowland.
> >
> > > -----Original Message-----
> > > From: samba [mailto:samba-bounces at lists.samba.org] On Behalf Of
> > > Rowland
2018 Jul 21
0
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On Sat, 21 Jul 2018 18:30:48 +0100
Roy Eastwood via samba <samba at lists.samba.org> wrote:
> Thanks Rowland.
>
> > -----Original Message-----
> > From: samba [mailto:samba-bounces at lists.samba.org] On Behalf Of
> > Rowland Penny via samba
> > Sent: 21 July 2018 18:04
> > To: samba at lists.samba.org
> > Subject: Re: [Samba] Failed to establish
2018 Jul 21
1
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
>
> Try restarting Samba on 'debian-vb'.
> If this doesn't help, try 'samba-tool dbcheck' and compare the two DC's
> with 'samba-tool ldapcmp'
>
> Rowland
>
OK, have tried that but no change. I used Louis' script: samba-check-db-repl.sh which includes samba-tool ldapcmp and samba-tool drs showrepl it passes both tests.
Roy
2018 Jul 21
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
>
> Strange, you say the time is okay, but the error says it isn't.
>
> Try this, open a terminal on both DC's, run 'date' and 'samba-tool
> time' on both. The results should be virtually the same.
>
> e.g.
> root at dc4:~# samba-tool time
> Sat Jul 21 16:47:43 2018 BST
> root at dc4:~# date
> Sat 21 Jul 16:47:46 BST 2018
>
>
2018 Jul 21
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
I have this warning message when I try to logon using a domain user to the DC
itself:
"Failed to establish your Kerberos Ticket cache due time differences
with the domain controller. Please verify the system time."
I have set up PAM using this file: /usr/share/pam-configs/winbind:
Name: Winbind NT/Active Directory authentication
Default: yes
Priority: 192
Auth-Type: Primary
Auth:
2018 Jul 23
0
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
Hai,
I've reading this thread more closely.
I suggest you try the followoing.
Check the servers hardware clock in the bios first.
Set these within 5 min, if they are not about the same.
Run : dpkg-reconfigure tzdata
Check/set the correct timezones on both servers, and both servers should show you the same date/time and (optional) zone.
Run : ntpq -p
Check the offset on both servers.
2018 Jul 21
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On Sat, 21 Jul 2018 12:16:42 +0100
> Rowland Penny via samba<samba at lists.samba.org> wrote:
> On Sat, 21 Jul 2018 11:24:47 +0100
> Roy Eastwood via samba <samba at lists.samba.org> wrote:
>
> > "Failed to establish your Kerberos Ticket cache due time differences
> > with the domain controller. Please verify the system time."
>
> It looks
2018 Jul 21
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On 7/21/2018 3:50 PM, Rowland Penny via samba wrote:
> On Sat, 21 Jul 2018 14:13:45 +0100
> Roy Eastwood via samba <samba at lists.samba.org> wrote:
>
>> On Sat, 21 Jul 2018 12:16:42 +0100
>>> Rowland Penny via samba<samba at lists.samba.org> wrote:
>>> On Sat, 21 Jul 2018 11:24:47 +0100
>>> Roy Eastwood via samba <samba at
2020 Mar 03
2
Install Samba4 as File Server
Hi
I intend to install Samba 4 as a file server on Debian 10 with apt-get.
I understood it, I don't need to install the OS dependencies (
https://wiki.samba.org/index.php/Package_Dependencies_Required_to_Build_Samba#Debian_.2F_Ubuntu),
because I will use the distribution repository.
This way, do I need only packages below?
# apt-get install acl attr samba samba-dsdb-modules
2018 Jul 21
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
Thanks for that.
> > > Remove the following lines, they shouldn't be in a DC
> > > From here:
> > >> wins support = no
> > >> local master = yes
> > >> domain master = yes
> > >> preferred master = yes
> > > To here.
> > >
> > > If you have chrony (or ntp) running, then you don't need another
2018 Jul 21
0
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On Sat, 21 Jul 2018 17:09:12 +0100
Roy Eastwood via samba <samba at lists.samba.org> wrote:
> >
> > Strange, you say the time is okay, but the error says it isn't.
> >
> > Try this, open a terminal on both DC's, run 'date' and 'samba-tool
> > time' on both. The results should be virtually the same.
> >
> > e.g.
> >
2018 Jul 23
3
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
Thanks Louis. Results below.
> Hai,
>
> I've reading this thread more closely.
>
> I suggest you try the followoing.
>
> Check the servers hardware clock in the bios first.
> Set these within 5 min, if they are not about the same.
>
There no RTC in the pi; the other DC is running in a VM with RTC set to UTC. I have disabled the guest from getting the time
2018 Jul 24
2
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
I did re-read the whole thread again.
Im running out of options..
When i look at :
https://wiki.samba.org/index.php/PAM_Offline_Authentication
You can do these last checks.
Run the : Testing offline authentication as show on the wiki.
Debian normaly does not have /etc/security/pam_winbind.conf, check if its there if so backup it remove it.
Check if these packages are installed.
2019 Sep 18
2
Upgraing a DC using the 'DC rejoin' method
I used the DC rejoin method as described in the WiKi to upgrade one of my DCs to version 4.11.0. Following the steps, when I came
to rejoin the domain, it initially failed, complaining that the DC already existed, but to force the rejoin, remove the files:
secrets.ldb and secrets.tdb. I assume you don't demote the DC before the upgrade, as there's no mention of this? Anyway, I
2018 Feb 07
5
Replication fails after DC re-joined to domain
Hi,
First some background:
==================
I had a test environment which had two samba DCs (running v 4.8.0rc2) and 1
Windows Server 2008R2 DC. The samba DCs had been upgraded from v 4.6x and the
secrets database was not encrypted (as far as I know). I decided to downgrade
one of the samba DCs to v 4.7.4.
On re-starting samba after the downgrade the log shows:
ldb: unable to dlopen
2019 Sep 18
1
Upgraing a DC using the 'DC rejoin' method
On 18/09/2019 13:10, Rowland penny via samba wrote:
> On 18/09/2019 12:34, Roy Eastwood via samba wrote:
> > I used the DC rejoin method as described in the WiKi to upgrade one of my DCs to version 4.11.0. Following the steps, when I
came
> > to rejoin the domain, it initially failed, complaining that the DC already existed, but to force the rejoin, remove the files:
> >
2018 Jul 24
1
Failed to establish your Kerberos Ticket cache due time differences with the domain controller
On Tue, 24 Jul 2018 10:32:32 +0100
Roy Eastwood via samba <samba at lists.samba.org> wrote:
>
>
> > -----Original Message-----
> > From: samba [mailto:samba-bounces at lists.samba.org] On Behalf Of
> > L.P.H. van Belle via samba
> > Sent: 24 July 2018 09:41
> > To: samba at lists.samba.org
> > Subject: Re: [Samba] Failed to establish your Kerberos
2019 Aug 29
4
Online Backup Fails - list index out of range
In another thread on this list (https://lists.samba.org/archive/samba/2019-August/225607.html), Rowland suggested that the following
command doesn't work ie it still requests the password:
samba-tool domain backup online --targetdir=<output-dir> --server=<DC-server> -k yes
However, I tried it out on one of my DCs and found it created the backup but failed at the end as this
2018 Jan 05
3
Adding a Windows Server 2008 as a DC to the domain fails
Hi,
I have a samba domain based on Samba version 4.7.4 compiled from sources
running on Debian Stretch v 9.3. The domain is working fine, but when I try to
add another DC (a Windows Server 2008 Standard Edition) using the Wiki at
https://wiki.samba.org/index.php/Joining_a_Windows_Server_2008_/_2008_R2_DC_to_a
_Samba_AD it fails with the error:
"The operation failed because:
The functional
2019 Jul 29
2
Cleanup after site deleted
Some time ago I created two sites in AD using RSAT tools. Recently the need for these separate sites has gone, so I removed all
the servers and workstations etc from these sites and put them back into 'Default-First-Site-Name' and deleted the sites. I have
just noticed that the DNS Manager is still showing one of the sites remaining (the other has disappeared). Whilst it is possible