[Samba] Windows login problem to a Samba AD DC

tizo tizone at gmail.com
Wed Nov 24 16:24:57 UTC 2021

> Where did you get the Samba packages from ? Out of the box the OS Samba
> packages cannot provision an AD domain.

My installation and configuration was a mix between
So the packages were obtained from this repo:
https://samba.tranquil.it/redhat8/samba-4.15/, and I could make the
provision process without problem.

> How did you provision the domain ?

More specifically:

samba-tool domain provision --realm=ADTEST.XX.XX.UY --domain ADTEST
--server-role=dc --use-rfc2307

> Does the DC use itself as nameserver (and not ?

At OS level?. No, it wasn't. But I change it now, reboot the DC, reboot the
windows client, and the issue persists.

What is in /etc/krb5.conf ?

default_realm = ADTEST.XX.XX.UY
dns_lookup_realm = false
dns_lookup_kdc = true

default_domain = adtest.xx.xx.uy

smbtest = ADTEST.XX.XX.UY

> What is in your smb.conf ?

# Global parameters
dns forwarder =
netbios name = SMBTEST
server role = active directory domain controller
workgroup = ADTEST
idmap_ldb:use rfc2307 = yes

path = /var/lib/samba/sysvol
read only = No

path = /var/lib/samba/sysvol/adtest.xx.xx.uy/scripts
read only = No

