[Samba] Other domain sequence numbers are -1

Trimble, Ronald D Ronald.Trimble at unisys.com
Fri Sep 22 14:53:24 GMT 2006

I posted this yesterday, but didn't get any responses.  Can anyone help
me out?

            I have configured a new SLES 10 server exactly the same as I
had previously configured a SLES 9 server.  The only difference is the
version of samba.  On the SLES 10 server, I am running the 3.0.23c
level, the SLES 9 server is behind a little.  My problem is with
connecting to other AD domains.  Only my default domain has a valid
sequence number.  All the other domains are showing up as a -1.  This
information was retrieved from the logs since the wbinfo -sequence
command times out.

            Here are the relevant pieces of information.  Can someone
suggest what I may be doing wrong?  This is very confusing to me since
it works perfectly on my SLES 9 server and I copied the configuration
from there.




>From krb5.conf:



        default_tgs_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC

        default_tkt_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC

        preferred_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC

        default_realm = NA.UIS.UNISYS.COM

        dns_lookup_kdc = true



        NA.UIS.UNISYS.COM = {

        kdc =

        admin_server =



        EU.UIS.UNISYS.COM = {

        kdc =

        admin_server =



        AP.UIS.UNISYS.COM = {

        kdc =

        admin_server =



        LAC.UIS.UNISYS.COM = {

        kdc =

        admin_server =




        .na.uis.unisys.com = NA.UIS.UNISYS.COM

        na.uis.unisys.com = NA.UIS.UNISYS.COM

        .eu.uis.unisys.com = EU.UIS.UNISYS.COM

        eu.uis.unisys.com = EU.UIS.UNISYS.COM

        .ap.uis.unisys.com = AP.UIS.UNISYS.COM

        ap.uis.unisys.com = AP.UIS.UNISYS.COM

        .lac.uis.unisys.com = LAC.UIS.UNISYS.COM

        lac.uis.unisys.com = LAC.UIS.UNISYS.COM


>From smb.conf:



       workgroup = NA

       realm = NA.UIS.UNISYS.COM

       netbios name = M1016

       encrypt passwords = yes

       security = ADS

       password server =

       passdb backend = smbpasswd

       log level = 2 winbind:10 ads:10 auth:10

       syslog = 0

       log file = /var/log/samba/%m.log

       max log size = 5000

       socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192

       winbind use default domain = no

       winbind uid = 16777216-33554431

       winbind gid = 16777216-33554431

       winbind enum users = no

       winbind enum groups = no

