problem with joining domain

Galloway, Dan Dan.Galloway at turner.com
Wed Jun 17 16:36:01 GMT 1998


I've been trying to set up a samba server to authenticate passwords to
an NT domain, specifically to the PDC. I've tried using security=server,
and now I'm trying security=domain. The error I keep getting for
security=server is:
Connecting to 157.166.87.190 at port 139
connected to password server 157.166.87.190
write_socket(7,76)
write_socket(7,76) wrote 76
Sent session request
got smb length of 1
157.166.87.190 rejected the session

This happens on two different domains. The samba server is on a different
network subnet than the PDC. The other error I get in the security=server
mode is:
password server is not connected.

Using security=domain, I get a different error:
Connecting to 157.166.87.252 at port 139
write_socket(5,76)
write_socket(5,76) wrote 76
Sent session request
got smb length of 1
modify_trust_password: machine 157.166.87.252 rejected the session setup.
Error 
was : code 131.
1998/06/17 11:52:50 : change_trust_account_password: Failed to change
password f
or domain CNN_INTERACTIVE.
./smbpasswd: Unable to join domain CNN_INTERACTIVE.

When I use the smb-enabled tcpdump, I get this:
10:00:26.928639 xanadu.33097 > cnnitech1.turner.com.netbios-ssn: S
92202168:9220
2168(0) win 8760 <mss 1460> (DF)
                         4500 002c 95a1 4000 ff06 00c3 9da6 521e
                         9da6 57fc 8149 008b 057e e4b8 0000 0000
                         6002 2238 247c 0000 0204 05b4
10:00:26.930442 cnnitech1.turner.com.netbios-ssn > xanadu.33097: S
276304538:276
304538(0) ack 92202169 win 8760 <mss 1460> (DF)
                         4500 002c 9a1d 4000 7f06 7c47 9da6 57fc
                         9da6 521e 008b 8149 1078 129a 057e e4b9
                         6012 2238 0159 0000 0204 05b4 0000
10:00:26.930581 xanadu.33097 > cnnitech1.turner.com.netbios-ssn: . ack 1 win
876
0 (DF)
                         4500 0028 95a2 4000 ff06 00c6 9da6 521e
                         9da6 57fc 8149 008b 057e e4b9 1078 129b
                         5010 2238 1916 0000
10:00:27.182806 xanadu.33097 > cnnitech1.turner.com.netbios-ssn: P 1:77(76)
ack 
1 win 8760
>>> NBT Packet
NBT Session Request
Flags=0x81000048
Destination=157             NameType=0x20 (Server)
Source=XAN             NameType=0x00 (Workstation)
Data: (4 bytes)
[000] 20 7A 0D 1E                                        z.. 

 (DF)
                         4500 0074 95a3 4000 ff06 0079 9da6 521e
                         9da6 57fc 8149 008b 057e e4b9 1078 129b
                         5018 2238 0102 0000 8100 0048 2044 4244
                         4644 4843 4143 4143 4143 4143 4143 4143
                         4143 4143 4143 4143 4143 4143 4100 2046
                         4945 4245 4f45
10:00:27.208402 cnnitech1.turner.com.netbios-ssn > xanadu.33097: FP 1:6(5)
ack 7
7 win 8684
>>> NBT Packet
NBT SessionReject
Flags=0x83000001
Reason=0x82
Called name not present

 (DF)
                         4500 002d 9b1d 4000 7f06 7b46 9da6 57fc
                         9da6 521e 008b 8149 1078 129b 057e e505
                         5019 21ec 1406 0000 8300 0001 8200
10:00:27.208622 xanadu.33097 > cnnitech1.turner.com.netbios-ssn: . ack 7 win
876
0 (DF)
                         4500 0028 95a4 4000 ff06 00c4 9da6 521e
                         9da6 57fc 8149 008b 057e e505 1078 12a1
                         5010 2238 18c4 0000
10:00:27.220934 xanadu.33097 > cnnitech1.turner.com.netbios-ssn: F 77:77(0)
ack 
7 win 8760 (DF)
                         4500 0028 95a5 4000 ff06 00c3 9da6 521e
                         9da6 57fc 8149 008b 057e e505 1078 12a1
                         5011 2238 18c3 0000
10:00:27.222416 cnnitech1.turner.com.netbios-ssn > xanadu.33097: . ack 78
win 86
84 (DF)
                         4500 0028 9c1d 4000 7f06 7a4b 9da6 57fc
                         9da6 521e 008b 8149 1078 12a1 057e e506
                         5010 21ec 190f 0000 0000 0000 0000


The part that really gets me is that I can't find a table of NBT errors to
look up that 0x82 anywhere.

I did get on the PDC and do a nbtstat -a <sambaserver> to verify that it
knows
about the samba server and that it thinks it is a part of the domain.

I'm running samba on a Sparc5, Solaris 2.6.

Thanks in advance for any help.
Dan


More information about the samba-ntdom mailing list