Authentification issues -- ads_verify_ticket

gbcgbc gbc_yoyo at hotmail.com
Thu Mar 25 11:34:56 MDT 2010


Hello,

We accidentally deleted 3 unix servers that where configured in the AD.
After further investigation we noticed our samba clients where not able to
connect anymore.

I ran net join -U cc1416
root at mclaren# ./net ads join -U cc1416
cc1416's password:

[2010/03/25 10:15:55, 0] libads/ldap.c:ads_add_machine_acct(1086)
  Warning: ads_set_machine_sd: Unexpected information received
Using short domain name -- DEV
Joined 'MCLAREN' to realm 'DEV.HYDRO.QC.CA'

After the client tested, he mentioned that he got a pop up asking him to log
in....something that never happened before.

After looking in to the logs, i noticed ticket errors.
My 3 samba servers are running solaris 9, and dont have the kinit binary,
and after googling for awhile,
the procedure states that i need to use "kinit" then do a "net join" 

here are the error messages in the samaba logs I noticed

log.10.4.34.136:[2010/03/25 12:06:19, 3]
libads/kerberos_verify.c:ads_verify_ticket(185)
log.10.4.34.136:  ads_verify_ticket: enc type [23] failed to decrypt with
error Decrypt integrity check failed
log.10.4.34.136:[2010/03/25 12:06:19, 3]
libads/kerberos_verify.c:ads_verify_ticket(193)
log.10.4.34.136:  ads_verify_ticket: krb5_rd_req with auth failed (Bad
encryption type)

Thx in advance


-- 
View this message in context: http://old.nabble.com/Authentification-issues----ads_verify_ticket-tp28032331p28032331.html
Sent from the Samba - samba-technical mailing list archive at Nabble.com.



More information about the samba-technical mailing list