Wed Jul 17 19:12:15 UTC 2019

On 17/07/2019 19:31, Robert A Wooldridge via samba wrote:
> Active Directory domain, the only DC is a Server 2003 machine.
Is the function level set to its highest level ?
>> /etc/resolv.conf
> nameserver
> nameserver
> search edm-inc.com
I take it '' is the 2003 DC
>> /etc/krb5.conf
> [libdefaults]
>     dns_lookup_realm = false
>     dns_lookup_kdc = true
>     default_realm = EDM-INC.COM
Try /etc/krb5.conf like the above
> Here's the full error:
> Could not find machine account in secrets database: Failed to fetch 
> machine account password for EDM from both secrets.ldb (Could not find 
> entry to match filter: '(&(flatname=EDM)(objectclass=primaryDomain))' 
> base: 'cn=Primary Domains': No such object: dsdb_search at 
> ../source4/dsdb/common/util.c:4705) and from 
> /var/lib/samba/private/secrets.tdb: NT_STATUS_CANT_ACCESS_DOMAIN_INFO

Problem is (so I have been told) neither secrets.tdb or secrets.ldb will 
have been created at this point, so this could be a red herring.

Does the windows DC run a dns server

What actual command are you running ?

Can you try it again with '-d3' on the end.


