Joining AD domain fails: "Failed to set servicePrincipalNames.
[...] Type or value exists"
Kurt Pfeifle
kurt.pfeifle at infotec.com
Fri Jun 22 23:37:33 GMT 2007
Guenther Deschner wrote:
> Hi Kurt,
>
> Kurt Pfeifle wrote:
>> Hi, list,
>
>> I'm having a problem to join a current Debian Sid/unstable system
>> (running Samba 3.0.25a) to an AD domain (where the DC is a Windows
>> 2003 Server with SP2):
>
> yeah, I've seen this happen also. This usually is caused as samba tries
> to add the same SPN twice (where the 2nd is caused by a fauled
> name_to_fqdn call).
>
>
> Can you run your join with debug level 10 set and see if that is the
> case ?
Indeed, I see the following lines in the output now:
-------------------------------------------------------------------
[2007/06/22 22:33:58, 10] lib/util.c:name_to_fqdn(3013)
name_to_fqdn: lookup for PDFMAKER failed.
Failed to set servicePrincipalNames. Please ensure that
the DNS domain of this server matches the AD domain,
-------------------------------------------------------------------
> pdfserver and pdfserver.infotecsys.de probably need to resolve to
> an ip-address.
Which they don't:
-------------------------------------------------------------------
root at pdfserver:~# nslookup pdfserver.infotecsys.de
Server: 10.162.2.3
Address: 10.162.2.3#53
** server can't find pdfserver.infotecsys.de: NXDOMAIN
root at pdfserver:~# host pdfserver.infotecsys.de
pdfserver.infotecsys.de does not exist (Authoritative answer)
-------------------------------------------------------------------
However, I do not really understand why this is the case. After
all, I've a valid entry for pdfserver in its local /etc/hosts, and
I have in /etc/nsswitch.conf a line
hosts: files wins dns
Shouldn't the latter therefor at first try to resolve the pdfserver
from the hosts file?
(BTW, I now also added an entry for pdfserver in the DC's
"%windir%\system32\etc\drivers\hosts" file, to no avail; I'm still
trying to figure out how to teach the ADS DC's DNS service what IP
address the pdfserver uses. Tomorrow I'll try to teach myself that
Windows trick...).
> Guenther
Cheers & Thanks,
Kurt
---
Infotec Deutschland GmbH
Hedelfingerstrasse 58
D-70327 Stuttgart
Telefon +49 711 4017-0, Fax +49 711 4017-5752
www.infotec.com
Geschaeftsfuehrer: Elmar Karl Josef Wanderer, Frank Grosch, Heinz-Josef Jansen
Sitz der Gesellschaft: Stuttgart, Handelsregister HRB Stuttgart 20398
Der Inhalt dieser E-Mail ist vertraulich und ist nur für den Empfänger bestimmt. Falls Sie nicht der angegebene Empfänger sind oder falls diese E-Mail irrtümlich an Sie adressiert wurde, verständigen Sie bitte den Absender sofort und löschen Sie die E-Mail sodann. Das unerlaubte Veröffentlichen, Kopieren sowie die unbefugte Übermittlung komplett oder in Teilen sind nicht gestattet.Private Ansichten und Meinungen sind, wenn nicht ausdrücklich erklärt, die des Autors und nicht die der Infotec Deutschland GmbH oder deren verantwortliche Direktoren und Angestellte. Eine Haftung für Schäden oder Verlust von Daten durch den Gebrauch dieser Email oder deren Anhänge wird ausgeschlossen.
Weitere Informationen erhalten Sie im Internet unter www.infotec.com oder in jeder Infotec Niederlassung.
This E-Mail is for the exclusive use of the recipient and may contain information which is confidential. Any disclosure, distribution or copying of this communication, in whole or in part, is not permitted. Any views or opinions presented are those of the author and (unless otherwise specifically stated) do not represent those of Infotec Deutschland GmbH or their directors or officers; none of whom are responsible for any reliance placed on the information contained herein. Although reasonable precautions have been taken to ensure that no viruses are present, all liability is excluded for any loss or damage arising from the use of this email or attachments.
For further information please see our website at www.infotec.com or refer to any Infotec office.
More information about the samba-technical
mailing list