[Samba] Cannot find KDC for requested realm

Rowland Penny rpenny at samba.org
Wed Aug 22 18:52:56 UTC 2018


On Wed, 22 Aug 2018 20:19:28 +0200
Kai Pöritz via samba <samba at lists.samba.org> wrote:

> Hi folks,
> 
> this is my first time setting up samba4 as AD.
> 
> Using the 'samba_dnsupdate' tool, I get the error:
> 
> Failed to get Kerberos credentials, falling back to samba-tool: kinit
> for AD$@AD.FIRMA.ANDRICK.DE failed (Cannot find KDC for requested
> realm)
> 
> How would I get at this error?

For various reasons, can you post the following:

/etc/hostname
/etc/hosts
/etc/resolv.conf
/etc/krb5.conf
/etc/nsswitch.conf
smb.conf

> 
> I assume 'AD$' is some automatically generated user.

No it is the samaccountname of your DC, all computers in AD get the '$'
suffix

> I have no idea
> how to list the users.

wbinfo -u
samba-tool user list

> All I did was set a administrator password
> while provisioning.

So you will be using the internal dns server.

> 
> kinit and klist for the user 'administrator' seem to work. See me
> errors:
> 
> 
> 0:1265:root at ad (SB=unknown)~ [0]# samba_dnsupdate --verbose
> --all-names IPs: ['fd35:4534:20ac:0:200:ff:fe00:5', '192.168.4.53']

We have had this once today ;-)

The 'failure' is that all the updates already exist.

Rowland





More information about the samba mailing list