Alessandro Baretta alessandro.baretta at radiomaria.org
Mon Nov 24 02:47:52 GMT 2008

Hi everyone,

I am trying to set up a file server on Linux for Windows XP boxes in a 
Windows Server 2003 environment. I followed an excellent tutorial on 
Samba and ADS, which I recommend to all newbies like myself: 
Kerberos authentication seems to succeed, and apparently there is 
nothing wrong with my smb.conf file, yet when I try to add the server to 
the ADS I get the following error message: "Failed to join domain: 
Invalid configuration and configuration modification was not requested". 
This error seems to be undocumented: I have found nothing either on 
Google or on the samba.org site.

Here's a transcript of a shell session showing this error.

samba:~# kinit
Password for Administrator at ARM.PRIV: <--- Authentication succeeds
samba:~# testparm
Load smb config files from /etc/samba/smb.conf
Processing section "[homes]"
Processing section "[fileserver]"
Processing section "[printers]"
Processing section "[print$]"
Loaded services file OK.
Press enter to see a dump of your service definitions
    workgroup = ARM.PRIV
    realm = ARM.PRIV
    server string = File server avanzato
    security = ADS
    log level = 3
    syslog = 0
    log file = /var/log/samba/log.%m
    max log size = 1000
    panic action = /usr/share/samba/panic-action %d
    idmap uid = 10000-20000
    idmap gid = 10000-20000

    comment = Home Directories
    valid users = %S
    create mask = 0700
    directory mask = 0700
    browseable = No

    comment = Cartelle condivise
    path = /var/samba
    read only = No
    create mask = 0700

    comment = All Printers
    path = /var/spool/samba
    create mask = 0700
    printable = Yes
    browseable = No

    comment = Printer Drivers
    path = /var/lib/samba/printers
samba:~# net ads join -U administrator
Enter administrator's password:
Failed to join domain: Invalid configuration and configuration 
modification was not requested

If I mistype the password I get a different error message:
samba:~# net ads join -U administrator%wrongpassword
Failed to join domain: failed to lookup DC info for domain 'ARM.PRIV' 
over rpc: Logon failure

Can anyone help me?

