Samba + ADS + Kerberos
Gerald (Jerry) Carter
jerry at samba.org
Wed Jul 9 14:36:53 GMT 2008
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Ron Short wrote:
> Samba (running on IRIX) appears to have lost its access to the domain
> contraoller for authentication purposes.
>
> The error message on the domain controller is:
>
> "session setup from the computer mcssan failed to authenticate"
>
> the following error occurred when he tried to do a "kinit
> administrator at nmcs" on the Samba server:
>
> "kinit(v5): kdc reply did not match expectations while getting initial
> credentials"
>
> This has been working fine for over a year.
>
> Yesterday we started seeing the following errors and the Windows systems
> are unable to connect to the Domain:
>
> san1 160# ./net ads join -U administrator at NMCS
> administrator at NMCS's password: [2008/07/09 09:15:08, 0]
> libads/kerberos.c:(145)
> kerberos_kinit_password administrator at NMCS failed: KDC reply did not
> match expectations
> [2008/07/09 09:15:08, 0] utils/net_ads.c:(191)
> ads_connect: KDC reply did not match expectations
> san1 161#
>
> Any ideas as to the problem and what needs to be done to correct it is
> appreciated.
Is this really the name of AD DNS domain ? "NMCS"? Make sure you real
the realm name and not the short (NT4) style name.
jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFIdM0FIR7qMdg1EfYRAhDWAKDbxo4xuhVRMM0T3J5/mEnJljls1wCg2df8
aEPJ3Y1CZPgPZ+bGnRXuJ2E=
=KqXm
-----END PGP SIGNATURE-----
More information about the samba-technical
mailing list