[Samba] Online AD Backup fails with "no auth" in 4.20?

Michael Tokarev mjt at tls.msk.ru
Fri Jun 28 05:31:19 UTC 2024


On 6/28/24 08:22, Matthias Kühne | Ellerhold Aktiengesellschaft via samba wrote:
> Hey Luis & Rowland,
> 
> this put me on the right track. Ive never had this error (please install
> samba-ad-provision).
> 
> First I upgraded to the newest samba version (2:4.20.2+dfsg-2~mjt-deb12
> to 2:4.20.2+dfsg-4~mjt-deb12). No change.
> 
> Then Ive installed samba-ad-provision. No change.
> 
> Then I installed samba-dsdb-modules. Now it works!!
> 
> Then I uninstalled samba-ad-provision. Now Im getting your error message
> ("Please install samba-ad-provision").
> 
> So from 4.20.2 onwards you need samba-ad-provision AND
> samba-dsdb-modules on a Debian 12 member server.
> 
> 4.20.1 did not have the split I think so thats why Rowlands backup works
> atm.

4.20.1 in debian (and hence on my repository) has exactly the same samba-dsdb-modules
and samba-ad-provision packages as current 4.20.2.

dsdb-modules has been separate package for many years.
samba-ad-provision created in 4.17.3+dfsg-4, it's been quite some time too.

The only noticeable recent change was the move of some stuff
from samba to samba-ad-dc (dc-only-related) or to python3-samba (samba-tool)
in 4.20.1+dfsg-2 which is the version Rowland seems to be using too.

So I'm a bit confused here.

*Especially* the order of installation you mentioned - it should not
matter at all.

I'll take a closer look what's going on here.

On the other hand, I dodn't expect domain-level operations to work on
a regular member server, to begin with.

Thanks,

/mjt

-- 
GPG Key transition (from rsa2048 to rsa4096) since 2024-04-24.
New key: rsa4096/61AD3D98ECDF2C8E  9D8B E14E 3F2A 9DD7 9199  28F1 61AD 3D98 ECDF 2C8E
Old key: rsa2048/457CE0A0804465C5  6EE1 95D1 886E 8FFB 810D  4324 457C E0A0 8044 65C5
Transition statement: http://www.corpit.ru/mjt/gpg-transition-2024.txt




More information about the samba mailing list