[Samba] kerberos_kinit_password failed: Preauthentication failed

Rowland Penny rpenny at samba.org
Mon Jan 9 11:16:54 UTC 2017

On Mon, 9 Jan 2017 08:59:40 -0200
"Carlos A. P. Cunha" <carlos.hollow at gmail.com> wrote:

> Hello!
> I do not use sssd use winbind.
> When I mentioned in the lines workgroup and realm, they are like this 
> (for example)
> Workgroup = INTRNAL
> I do not know if that was what caused the confusion ....

Yes it was, if you are going to sanitize smb.conf (or anything) please
use the same thing everywhere ;-)

Your 'idmap config' set up is entirely wrong, you should use 'tdb' for
the '*' domain and you should also have a separate range for the
'INTERNAL' domain
i.e. you should have lines similar to these:

    idmap config *:backend = tdb
    idmap config *:range = 2000-9999
    idmap config INTERNAL : backend = rid
    idmap config INTERNAL : range = 10000-999999


More information about the samba mailing list