[Samba] samba 4.5.0 strange windows 10 issue | incorrect password

Rowland Penny rpenny at samba.org
Mon Oct 17 21:14:09 UTC 2016


On Mon, 17 Oct 2016 13:51:18 -0700 (PDT)
yabko via samba <samba at lists.samba.org> wrote:

> hi server role is
> 
> server role = active directory domain controller
> 
> i googled the error and it says that there could be two computer
> accounts of the same name
> 
> i pulled this from the event log
> 
> The Kerberos client received a KRB_AP_ERR_MODIFIED error from the
> server 50wks19$. The target name used was 50WKS19$. This indicates
> that the target server failed to decrypt the ticket provided by the
> client. This can occur when the target server principal name (SPN) is
> registered on an account other than the account the target service is
> using. Ensure that the target SPN is only registered on the account
> used by the server. This error can also happen if the target service
> account password is different than what is configured on the Kerberos
> Key Distribution Center for that target service. Ensure that the
> service on the server and the KDC are both configured to use the same
> password. If the server name is not fully qualified, and the target
> domain (WMPNY.LAN) is different from the client domain (WMPNY.LAN),
> check if there are identically named server accounts in these two
> domains, or use the fully-qualified name to identify the server.
> 
> but checking DNS/ADUC i don't see any 50wks19 twice. all are windows
> 10x64
> 

Well, all I gained from that is you haven't got a PDC, it is an AD DC.

What OS are you using ?
What is in smb.conf ?
What is in /etc/krb5.conf ?
what is in /etc/resolv.conf ?
what is in /etc/hosts ?
what is in /etc/hostname ?
what is the ipaddress of the AD DC ?

Rowland





More information about the samba mailing list