[Samba] kinit succeeded but ads_sasl_spnego_krb5_bind failed: Program lacks support for encryption type

simongithub simongithub at gmail.com
Wed Feb 12 00:01:03 MST 2014


Hello All,

Having some trouble connecting to my Windows domain with my Solaris server.
Some details included below that might give you an idea of what is going on
here. I have tried setting allow weak crypto in the krb5.conf, I have tried
specifying the encryption types and leaving it blank to use the defaults all
to no avail...

bash-3.2# kinit me at DOMAIN.LOCAL
Password for me at DOMAIN.LOCAL:

bash-3.2# klist -e
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: me at DOMAIN.LOCAL

Valid starting               Expires               Service principal
12/02/2014 14:41  13/02/2014 00:41  krbtgt/DOMAIN.LOCAL at DOMAIN.LOCAL
        renew until 19/02/2014 14:41, Etype(skey, tkt): AES-128 CTS mode
with 96-bit SHA-1 HMAC, unsupported encryption type 18

bash-3.2# net ads join -U me
Enter me's password:
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Program lacks support
for encryption type
Failed to join domain: failed to connect to AD: Program lacks support for
encryption type

bash-3.2# smbd -V
Version 3.6.20

bash-3.2# uname -a
SunOS myserver 5.10 Generic_147440-19 sun4v sparc sun4v

Any ideas you have would be greatly appreciated.

Cheers





--
View this message in context: http://samba.2283325.n4.nabble.com/kinit-succeeded-but-ads-sasl-spnego-krb5-bind-failed-Program-lacks-support-for-encryption-type-tp4660730.html
Sent from the Samba - General mailing list archive at Nabble.com.


More information about the samba mailing list