[Samba] Failure to add computer to domain

Michał Półrolniczak michal.polrolniczak at warp.org.pl
Thu Aug 7 23:52:41 MDT 2014

W dniu 2014-08-07 o 21:49, steve pisze:
> On Thu, 2014-08-07 at 21:20 +0200, Michał Półrolniczak wrote:
>> W dniu 2014-08-07 o 13:41, steve pisze:
>>> On Thu, 2014-08-07 at 09:31 +0200, Michał Półrolniczak wrote:
>>>> when adding computer using administrator account (which results in bad
>>>> password)
>>>>   Kerberos: Failed to decrypt PA-DATA -- administrator at warp.local
>>>> (enctype arcfour-hmac-md5) error Decrypt integrity check failed
>>>                                    ^^
>>> That's kerberos for wrong password.
>>> Do this on the DC:
>>> kinit administrator
>>> and
>>> kinit Administrator
>>> then
>>> kinit Administrator at WARP.LOCAL
>>> What do we get?
>> It ask me about password every time, everytime the Administrator
>> password which is used to add computer to domain is taken as good password
>> and every klist in middle of doing kinit give same think -> higher time
>> when ticket was renewed.
> Set the DNS on the windows 8.1 machine to be the same IP and search
> domain as the DC. Now try joining again.

I wasn't sure if i get that right so: I manualy added ip, netmas, gw, dns.
When i set ip and dns as, I didn't find domain (no real dns)
When i set ip as and dns as (which is PDC)
domain was found on .4 but still couldn't add the computer.

I removed previously added computer from Computer OU, but that didnt
help either.

More information about the samba mailing list