Samba + ADS + Kerberos

Ron Short short at sgi.com
Wed Jul 9 13:30:02 GMT 2008


Samba (running on IRIX) appears to have lost its access to the domain 
contraoller for authentication purposes.

The error message on the domain controller is:

"session setup from the computer mcssan failed to authenticate"

the following error occurred when he tried to do a "kinit 
administrator at nmcs" on the Samba server:

"kinit(v5): kdc reply did not match expectations while getting initial 
credentials"

This has been working fine for over a year.

Yesterday we started seeing the following errors and the Windows systems 
are unable to connect to the Domain:

san1 160# ./net ads join -U administrator at NMCS
administrator at NMCS's password: [2008/07/09 09:15:08, 0] 
libads/kerberos.c:(145)
  kerberos_kinit_password administrator at NMCS failed: KDC reply did not 
match expectations
[2008/07/09 09:15:08, 0] utils/net_ads.c:(191)
  ads_connect: KDC reply did not match expectations
san1 161#

Any ideas as to the problem and what needs to be done to correct it is 
appreciated.

thanks

-- 

Ron Short                                       email: short at sgi.com
Solutions Architect                             office: 651/683-5680
SGI Professional Services                       fax: 651/683-5599      



More information about the samba-technical mailing list