[Samba] samba 3 / AD / krb5_cc_get_principal failed

Mark Roach mrroach at okmaybe.com
Fri Sep 10 12:45:53 GMT 2004

On Mon, 2004-09-06 at 11:51 +0200, Olaf Zaplinski wrote:
> Hi all,
> I successfully joined my Samba 3.0.6 box to our AD tree. wbinfo -t and -u 
> work as expected. But when I try to access a share on the samba box (Windows 
> AD controller), I am asked for a password, Samba then logs
> [2004/09/06 11:49:28, 1] smbd/sesssetup.c:reply_spnego_kerberos(173)
>    Failed to verify incoming ticket!
> winbindd sometimes logs
> [2004/09/06 11:42:55, 1] libsmb/clikrb5.c:ads_krb5_mk_req(313)
>    krb5_cc_get_principal failed (No credentials cache found)

I had this same problem. Samba + AD compatibility seems to be much
farther from complete than advertised, and is rather flimsy. It's easier
to use RPC, but if your domain is in native mode, there are likely to be
problems still. We have a server that worked great for several years,
and since we switched to native mode AD (which the samba FAQs say is
fine) we have had no end of problems. Numerous groups don't work, ACLs
stopped working, hangs, crashes etc. Not trying to discourage you, but
be warned that this is the sort of bleeding-edge stuff that will
actually leave you bleeding.


More information about the samba mailing list