[Samba] ads_join_realm: Insufficient access

Brijesh Shukla shukla.brijesh at gmail.com
Fri Feb 9 11:37:51 GMT 2007

Hi Samba List;
Kindly help me, I am stuck with this problem since long time.
I am trying to join windows 2003 Active Directory using Linux client.
I am able to join Windows 2003 Active directory using administrator account
(I mean if i am giving the command like
net ads join -U administrator then it work perfectly ) on the other hand if
i try to with normal user account let say "bshukla" then I am always getting
this problem..."ads_join_realm: Insufficient access"..

On the same time I am able to access Windows 2003 Active directory with
bshukla account using windows-xp based PC..

I am astonish kerberos is working fine because I am able to get ticket on
bshukla user account but "net ads join -U bshukla" is not giving desired
I am attaching the log of my work...
Kindly suggest me what i have to do..
******************LOG FILE*************************************

[root at localhost ~]# kinit bshukla at TECPDC1.CO.JP
Password for bshukla at TECPDC1.CO.JP:

[root at localhost ~]#  net ads join -U bshukla

[2007/02/09 20:21:36, 0] libads/ldap.c:ads_add_machine_acct(1405)
  ads_add_machine_acct: Host account for localhost already exists -
modifying old account
[2007/02/09 20:21:36, 0] libads/ldap.c:ads_join_realm(1763)
  ads_join_realm: ads_add_machine_acct failed (localhost): Insufficient
ads_join_realm: Insufficient access
***********************End of Log****************************

Thanks in advance
Brijesh Shukla

More information about the samba mailing list