[Samba] migrating NT-style domain SID-error

Rowland Penny rpenny at samba.org
Mon May 14 15:59:03 UTC 2018


On Mon, 14 May 2018 17:37:23 +0200
Stefan Kania via samba <samba at lists.samba.org> wrote:

> 
> 
> Hello,
> 
> after migrating a samba NT-style domain from Samba 4.2.14-debian
> (debian 8.10) to samba 4.5.12-debian (debian 9.4)

> root at addc:~# smbclient -L addc -d 10
> .
> .
> .
> SPNEGO login failed: Indicates the SID structure is not valid.
> session setup failed: NT_STATUS_INVALID_SID
> 
> ----------
> 
> Then we checked the local sid for the DC and get the following result:
> ----------
> root at addc:~# net getlocalsid
> Can't fetch domain SID for name: ADDC
> ----------
> 
> But we get the domain-SID:
> ----------
> root at addc:~# net getdomainsid
> SID for domain EXAMPLE is: S-1-5-21-2513443738-1937210514-736184894
> ----------

OK, lets start with the obvious things, can you post the contents of:
/etc/resolv.conf
/etc/hostname
/etc/hosts
The Bind9 conf files from /etc/bind
/etc/krb5.conf
The result of 'hostname -i'
/etc/samba/smb.conf

Rowland




More information about the samba mailing list