[Samba] 'Scripted' machine account renewal?!

Marco Gaiarin gaio at lilliput.linux.it
Mon Mar 4 13:14:18 UTC 2024


Mandi! Kees van Vloten via samba
  In chel di` si favelave...

> Interesting, I tried running it with -d 10, it shows a lot of output. 

The same. My output is a bit more complex, i think because the joined
machine is a firewall, that have no whatsoever info about the domain, so i
have tons of error relatives to dns record missing.

But, as just stated, join with:

	net ads join -I 10.172.1.8 -U gaio

worked as expected, a simple 'net ads testjoin' work (with the same DNS
errors, of course).


> Another thing I tried was "systemctl stop winbind" and then the "net 
> changetrustpw", but even then the same error occurs.

I've not winbind running in joined machine.


> And I checked the machine's ldap record "pwdLastSet" attribute. Indeed 
> it shows that the password has not changed.

I've not specified it, but, clearly, yes.

-- 
   Di questa cavolo di pianura, di questa gente senza misura, che gia`
   confonde la notte e il giorno, e la partenza con il ritorno, e la
   richezza con i rumore, ed il diritto con il favore	(F. De Gregori)





More information about the samba mailing list