Samba + ADS + Kerberos

Gerald (Jerry) Carter jerry at samba.org
Wed Jul 9 14:36:53 GMT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ron Short wrote:
> Samba (running on IRIX) appears to have lost its access to the domain
> contraoller for authentication purposes.
> 
> The error message on the domain controller is:
> 
> "session setup from the computer mcssan failed to authenticate"
> 
> the following error occurred when he tried to do a "kinit
> administrator at nmcs" on the Samba server:
> 
> "kinit(v5): kdc reply did not match expectations while getting initial
> credentials"
> 
> This has been working fine for over a year.
> 
> Yesterday we started seeing the following errors and the Windows systems
> are unable to connect to the Domain:
> 
> san1 160# ./net ads join -U administrator at NMCS
> administrator at NMCS's password: [2008/07/09 09:15:08, 0]
> libads/kerberos.c:(145)
>  kerberos_kinit_password administrator at NMCS failed: KDC reply did not
> match expectations
> [2008/07/09 09:15:08, 0] utils/net_ads.c:(191)
>  ads_connect: KDC reply did not match expectations
> san1 161#
> 
> Any ideas as to the problem and what needs to be done to correct it is
> appreciated.

Is this really the name of AD DNS domain ?   "NMCS"?  Make sure you real
the realm name and not the short (NT4) style name.




jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIdM0FIR7qMdg1EfYRAhDWAKDbxo4xuhVRMM0T3J5/mEnJljls1wCg2df8
aEPJ3Y1CZPgPZ+bGnRXuJ2E=
=KqXm
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list