[Samba] Problem with SAMBA 4 on Debian default installation

Szostak Grzegorz szostak.grzegorz at gmail.com
Thu May 22 11:13:59 MDT 2014

Dear All,
I have samba 4 installation which was upgraded from samba 3. Everything was
working fine for about 6 months. Then I don't remember what I have done but
after restart of server, it is impossible to log into Windows using
The setup consists of several Windows XP and Windows 7 computer. Samba jest

Looks like problems with configuration of Kerberos or around it.

        server role = active directory domain controller
        host msdfs = yes
        workgroup = DOMAIN
        realm = net.domain.com.pl
        netbios name = PR254
        passdb backend = samba4
        server services = -smb +s3fs +dnsupdate +winbind +kdc +cldap +ldap
+drepl +nbt
        dcerpc endpoint servers = +winreg +srvsvc
        log level = 5
        interfaces = eth3
        bind interfaces only = yes
        rpc_server:samr = external

        path = /var/lib/samba/sysvol/net.domain.com.pl/scripts
        browsable = yes
        read only = No

        path = /var/lib/samba/sysvol
        read only = No

        default_realm = NET.DOMAIN.COM.PL
        dns_lookup_realm = false
        dns_lookup_kdc = true
#       clock-skew = 600

        NET.DOMAIN.COM.PL = {
                kdc = pr254.net.domain.com.pl
                default_domain = DOMAIN
                admin_server = pr254.net.domain.com.pl

Bind as Dns backend.

kadmin:  getprincs
administrator/admin at NET.DOMAIN.COM.PL
administrator at NET.DOMAIN.COM.PL
kadmin/admin at NET.DOMAIN.COM.PL
kadmin/changepw at NET.DOMAIN.COM.PL
kadmin/pr254.net.domain.com.pl at NET.DOMAIN.COM.PL

pr254:~# less /var/lib/samba/private/smbd.tmp/fileserver.conf
# auto-generated config for fileserver
passdb backend = samba4
rpc_server:default = external
rpc_server:svcctl = embedded
rpc_server:srvsvc = embedded
rpc_server:eventlog = embedded
rpc_server:ntsvcs = embedded
rpc_server:winreg = embedded
rpc_server:spoolss = embedded
rpc_daemon:spoolssd = disabled
rpc_server:tcpip = no
vfs objects = acl_xattr
map hidden = no
map system = no
map readonly = no
store dos attributes = yes
include = /etc/samba/smb.conf
 vfs objects = dfs_samba4

- on windows, windows says that user doesn't exists or has wrong password
- on linux:
When I issue: pr254:~# samba-tool user password -U administrator

finddcs: searching for a DC by DNS domain net.domain.com.pl
finddcs: looking for SRV records for _ldap._tcp.net.domain.com.pl
ads_dns_lookup_srv: 1 records returned in the answer section.
finddcs: DNS SRV response 0 at ''
finddcs: DNS SRV response 1 at ''
finddcs: DNS SRV response 2 at ''
finddcs: DNS SRV response 3 at ''

Result is: finddcs:
No matching CLDAP server found
ERROR: Failed to change password : Connection to SAMR pipe of PDC of domain
  File "/usr/lib/python2.7/dist-packages/samba/netcmd/user.py", line 455,
in run

Thank you for help.

