[Samba] Error when attempting to join ads domain:

Sean Kennedy skennedy at qualitydentists.com
Sat Sep 24 18:57:15 GMT 2005

I am running into the following error when attempting to join a domain:

    root at sparky:/usr/local/samba# ./bin/net ads join -U administrator
    administrator's password:
    [2005/09/24 11:22:41, 0] utils/net_ads.c:ads_startup(191)
      ads_connect: Cannot contact any KDC for requested realm

However, this seems to work:

    root at sparky:/usr/local/samba# kinit administrator at BOCA.PRI
    Password for administrator at BOCA.PRI:

I have no krb5.conf file.  Here's my smb.conf:

            workgroup = BOCA
            netbios name = SPARKY
            realm = BOCA.PRI
            security = ADS
            server string = Sparky Data
            security = ADS
            allow trusted domains = no
            idmap backend = idmap_rid:BOCA=500-100000000
            idmap uid = 500-100000000
            idmap gid = 500-100000000
            template shell = /bin/bash
            winbind use default domain = yes
            winbind enum users = no
            winbind enum groups = no
            winbind nested groups = yes

I am using the latest Samba, MIT Kerberos and Openldap ( along with the 
latest Berkeley DB ).  My network config is as follows:

My main network is ( with the DC living at 
).  This machine in question lives at, a remote site linked 
via openvpn.  DNS records are set correctly, in fact this machine is set 
to use as it's DNS server.  I can ping boca.pri and it 
resolves to the dc.  kinit works when I enter in the correct username 
and password combo ( ie: kinit administrator at BOCA.PRI works fine ).

Can anybody give me any other ideas to try?


More information about the samba mailing list