[Samba] Failure to add computer to domain

Michał Półrolniczak michal.polrolniczak at warp.org.pl
Thu Aug 7 23:52:41 MDT 2014


W dniu 2014-08-07 o 21:49, steve pisze:
> On Thu, 2014-08-07 at 21:20 +0200, Michał Półrolniczak wrote:
>> W dniu 2014-08-07 o 13:41, steve pisze:
>>> On Thu, 2014-08-07 at 09:31 +0200, Michał Półrolniczak wrote:
>>>
>>>> when adding computer using administrator account (which results in bad
>>>> password)
>>>>   Kerberos: Failed to decrypt PA-DATA -- administrator at warp.local
>>>> (enctype arcfour-hmac-md5) error Decrypt integrity check failed
>>>                                    ^^
>>> That's kerberos for wrong password.
>>>
>>> Do this on the DC:
>>> kinit administrator
>>> and
>>> kinit Administrator
>>> then
>>> kinit Administrator at WARP.LOCAL
>>>
>>> What do we get?
>>>                                    
>>>
>>>
>> It ask me about password every time, everytime the Administrator
>> password which is used to add computer to domain is taken as good password
>> and every klist in middle of doing kinit give same think -> higher time
>> when ticket was renewed.
> Set the DNS on the windows 8.1 machine to be the same IP and search
> domain as the DC. Now try joining again.
>

I wasn't sure if i get that right so: I manualy added ip, netmas, gw, dns.
When i set ip and dns as 192.168.0.100, I didn't find domain (no real dns)
When i set ip as 192.168.0.100 and dns as 192.168.0.4 (which is PDC)
domain was found on .4 but still couldn't add the computer.

I removed previously added computer from Computer OU, but that didnt
help either.


More information about the samba mailing list