[Samba] Domain self join

Marc Muehlfeld mmuehlfeld at samba.org
Fri Nov 11 16:33:41 UTC 2016

Hello Ronny,

Am 11.11.2016 um 17:19 schrieb Ronny Forberger via samba:
> I want to authenticate against Samba 4 using samba and sssd on FreeBSD
> using this guide:
> http://serverfault.com/questions/599200/how-to-integrate-active-directory-with-freebsd-10-0-using-security-sssd
> The problem is, the machine I want to install authentication on is the
> domain controller itsself.
> So the following commands show the errors:
> net ads join createupn=host/macy.ronnyforberger.de at RONNYFORBERGER.DE -k -d1
> Host is not configured as a member server.
> Invalid configuration.  Exiting....
> Failed to join domain: This operation is only allowed for the PDC of the
> domain.
> The host role is active directory domain controller.
> Any ideas how i can join the domain with this host?

If you set up the host as DC, then it is naturally already a member of
the AD domain. You don't join it.

Just install SSSD and configure it to retrieve user and groups from AD +
configure PAM. There are several guides on the internet how to configure
SSSD for AD.


More information about the samba mailing list