<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SAMBA 3 Authenticating to a Windows 2003 Active Directory HOWTO</title>
	<atom:link href="http://www.brentnorris.net/blog/archives/179/feed" rel="self" type="application/rss+xml" />
	<link>http://www.brentnorris.net/blog/archives/179</link>
	<description>The random ramblings of diablo</description>
	<lastBuildDate>Tue, 29 Nov 2011 20:15:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Alex Ruwinskij</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75842</link>
		<dc:creator>Alex Ruwinskij</dc:creator>
		<pubDate>Mon, 31 Oct 2011 08:29:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75842</guid>
		<description>Hi,

I am running a SAMBA 3.5.8 Server on Solaris (non global zone) and trying to join MS2003 AD Server.
Indeed it´s possible to create the appropriate computer account in AD, but further authtication fails:

net ads join -d 7 -S hlsif000 -U ******

[2011/10/31 09:02:46.239017,  3] libads/sasl.c:791()
  ads_sasl_spnego_bind: got server principal name = server$@sub.domain.DE
[2011/10/31 09:02:46.436305,  0] libads/sasl.c:821()
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: NT_STATUS_NOT_SUPPORTED
[2011/10/31 09:02:46.436725,  1] libnet/libnet_join.c:1978()
  libnet_Join:
      libnet_JoinCtx: struct libnet_JoinCtx
          out: struct libnet_JoinCtx
              account_name             : NULL
              netbios_domain_name      : &#039;HLB&#039;
              dns_domain_name          : &#039;sub.domain.de&#039;
              forest_name              : &#039;sub.domain.de&#039;
              dn                       : NULL
              domain_sid               : *
                  domain_sid               : S-1-5-21-1691891752-616008026-1446451325
              modified_config          : 0x00 (0)
              error_string             : &#039;failed to connect to AD: NT_STATUS_NOT_SUPPORTED&#039;
              domain_is_ad             : 0x01 (1)
              result                   : WERR_GENERAL_FAILURE
Failed to join domain: failed to connect to AD: NT_STATUS_NOT_SUPPORTED
[2011/10/31 09:02:46.437083,  2] utils/net.c:916()
  return code = -1
root@int-app1

Perhaps I should say, that my winbind service produces following error all the time: 
[2011/10/31 09:19:55.543982,  1] winbindd/winbindd_util.c:289()
  Could not receive trustdoms

The configured parameter on AD-site for network security is: Send NTLMv2 response only/refuse LM.

Many thanks in advance
Alex</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I am running a SAMBA 3.5.8 Server on Solaris (non global zone) and trying to join MS2003 AD Server.<br />
Indeed it´s possible to create the appropriate computer account in AD, but further authtication fails:</p>
<p>net ads join -d 7 -S hlsif000 -U ******</p>
<p>[2011/10/31 09:02:46.239017,  3] libads/sasl.c:791()<br />
  ads_sasl_spnego_bind: got server principal name = server$@sub.domain.DE<br />
[2011/10/31 09:02:46.436305,  0] libads/sasl.c:821()<br />
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: NT_STATUS_NOT_SUPPORTED<br />
[2011/10/31 09:02:46.436725,  1] libnet/libnet_join.c:1978()<br />
  libnet_Join:<br />
      libnet_JoinCtx: struct libnet_JoinCtx<br />
          out: struct libnet_JoinCtx<br />
              account_name             : NULL<br />
              netbios_domain_name      : &#8216;HLB&#8217;<br />
              dns_domain_name          : &#8216;sub.domain.de&#8217;<br />
              forest_name              : &#8216;sub.domain.de&#8217;<br />
              dn                       : NULL<br />
              domain_sid               : *<br />
                  domain_sid               : S-1-5-21-1691891752-616008026-1446451325<br />
              modified_config          : 0&#215;00 (0)<br />
              error_string             : &#8216;failed to connect to AD: NT_STATUS_NOT_SUPPORTED&#8217;<br />
              domain_is_ad             : 0&#215;01 (1)<br />
              result                   : WERR_GENERAL_FAILURE<br />
Failed to join domain: failed to connect to AD: NT_STATUS_NOT_SUPPORTED<br />
[2011/10/31 09:02:46.437083,  2] utils/net.c:916()<br />
  return code = -1<br />
root@int-app1</p>
<p>Perhaps I should say, that my winbind service produces following error all the time:<br />
[2011/10/31 09:19:55.543982,  1] winbindd/winbindd_util.c:289()<br />
  Could not receive trustdoms</p>
<p>The configured parameter on AD-site for network security is: Send NTLMv2 response only/refuse LM.</p>
<p>Many thanks in advance<br />
Alex</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prachi</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75827</link>
		<dc:creator>Prachi</dc:creator>
		<pubDate>Thu, 20 Oct 2011 09:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75827</guid>
		<description>Hi,

I have setup sambe as you mentioned. However I am getting error while adding the host to domain using net join command.

error:
Failed to join domain: The network name cannot be found


The linux host is able to ping/nslooup to domain controller with IP/name.
Please suggest what could be the reason.

thanks,
Prachi</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have setup sambe as you mentioned. However I am getting error while adding the host to domain using net join command.</p>
<p>error:<br />
Failed to join domain: The network name cannot be found</p>
<p>The linux host is able to ping/nslooup to domain controller with IP/name.<br />
Please suggest what could be the reason.</p>
<p>thanks,<br />
Prachi</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brahma</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75800</link>
		<dc:creator>brahma</dc:creator>
		<pubDate>Fri, 22 Jul 2011 07:07:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75800</guid>
		<description>My access log returns following message

failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/cache/samba/winbindd_privileged are set correctly.] 
[2011/07/21 18:30:26, 0] utils/ntlm_auth.c:manage_squid_ntlmssp_request(603) 
  NTLMSSP BH: NT_STATUS_ACCESS_DENIED 

MY KDC server info

LDAP server: 171.18.0.45
LDAP server name: bnsr259.platform.com
Realm: PLATFORM.COM
Bind Path: dc=PLATFORM,dc=COM
LDAP port: 389
Server time: Wed, 20 Jul 2011 20:34:57 IST
KDC server: 171.18.0.45
Server time offset: 180</description>
		<content:encoded><![CDATA[<p>My access log returns following message</p>
<p>failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/cache/samba/winbindd_privileged are set correctly.]<br />
[2011/07/21 18:30:26, 0] utils/ntlm_auth.c:manage_squid_ntlmssp_request(603)<br />
  NTLMSSP BH: NT_STATUS_ACCESS_DENIED </p>
<p>MY KDC server info</p>
<p>LDAP server: 171.18.0.45<br />
LDAP server name: bnsr259.platform.com<br />
Realm: PLATFORM.COM<br />
Bind Path: dc=PLATFORM,dc=COM<br />
LDAP port: 389<br />
Server time: Wed, 20 Jul 2011 20:34:57 IST<br />
KDC server: 171.18.0.45<br />
Server time offset: 180</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brahma</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75799</link>
		<dc:creator>brahma</dc:creator>
		<pubDate>Fri, 22 Jul 2011 06:50:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75799</guid>
		<description>Hi,
i setup samba as you mentioned, added domain to samba,while testing with net rpc shows JOINED OK but testing with net ads it shows following error and also iam not added ACL, please help me.

 [ samba]#  net ads join -U Administrator%welcome*123
[2011/07/21 18:30:26, 0] libads/sasl.c:ads_sasl_spnego_bind(330)
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: Invalid credentials
Failed to join domain: Invalid credentials
[ samba]# net rpc join -U Administrator%welcome*123
Joined domain PLATFORM.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
i setup samba as you mentioned, added domain to samba,while testing with net rpc shows JOINED OK but testing with net ads it shows following error and also iam not added ACL, please help me.</p>
<p> [ samba]#  net ads join -U Administrator%welcome*123<br />
[2011/07/21 18:30:26, 0] libads/sasl.c:ads_sasl_spnego_bind(330)<br />
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: Invalid credentials<br />
Failed to join domain: Invalid credentials<br />
[ samba]# net rpc join -U Administrator%welcome*123<br />
Joined domain PLATFORM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cloud81918</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75785</link>
		<dc:creator>Cloud81918</dc:creator>
		<pubDate>Tue, 17 May 2011 21:59:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75785</guid>
		<description>I just want to drop a thanks, I&#039;ve been following another how-to and ended up with everything the way they wanted, but it wasn&#039;t working. With your walk through I had it up in minutes. Thanks again for taking the time to put this up. 

-Jerred</description>
		<content:encoded><![CDATA[<p>I just want to drop a thanks, I&#8217;ve been following another how-to and ended up with everything the way they wanted, but it wasn&#8217;t working. With your walk through I had it up in minutes. Thanks again for taking the time to put this up. </p>
<p>-Jerred</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ilayaraja</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75619</link>
		<dc:creator>ilayaraja</dc:creator>
		<pubDate>Tue, 01 Jun 2010 12:30:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75619</guid>
		<description>Thanks for your article. i successfully configured joined samba with my windows 2003 ADS.</description>
		<content:encoded><![CDATA[<p>Thanks for your article. i successfully configured joined samba with my windows 2003 ADS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: slarti</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75537</link>
		<dc:creator>slarti</dc:creator>
		<pubDate>Sun, 14 Feb 2010 03:53:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75537</guid>
		<description>Hi Brent,
 
I found your site by trying to solve my problem for the last 4 days. Maybe you can help.

I have Fedora 11 trying to join MS 2003 R2 AD server. I followed all the steps you outlined and then I did some more experimenting, but I am consistently getting the same error :

net ads join -U administrator
Enter administrator&#039;s password:
[2010/02/14 04:33:01,  0] libads/sasl.c:819(ads_sasl_spnego_bind)
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: Invalid credentials
Failed to join domain: failed to connect to AD: Invalid credentials

the net ads info works :

net ads info
LDAP server: 192.168.1.5
LDAP server name: bluead.blueteam.local
Realm: BLUETEAM.LOCAL
Bind Path: dc=BLUETEAM,dc=LOCAL
LDAP port: 389
Server time: Sun, 14 Feb 2010 04:51:54 CET
KDC server: 192.168.1.5
Server time offset: 0

I can&#039;t joint the domain. Is there anything I am missing ?
Do you need more info from me ?
Please help.

Thanks,
Mirek</description>
		<content:encoded><![CDATA[<p>Hi Brent,</p>
<p>I found your site by trying to solve my problem for the last 4 days. Maybe you can help.</p>
<p>I have Fedora 11 trying to join MS 2003 R2 AD server. I followed all the steps you outlined and then I did some more experimenting, but I am consistently getting the same error :</p>
<p>net ads join -U administrator<br />
Enter administrator&#8217;s password:<br />
[2010/02/14 04:33:01,  0] libads/sasl.c:819(ads_sasl_spnego_bind)<br />
  kinit succeeded but ads_sasl_spnego_krb5_bind failed: Invalid credentials<br />
Failed to join domain: failed to connect to AD: Invalid credentials</p>
<p>the net ads info works :</p>
<p>net ads info<br />
LDAP server: 192.168.1.5<br />
LDAP server name: bluead.blueteam.local<br />
Realm: BLUETEAM.LOCAL<br />
Bind Path: dc=BLUETEAM,dc=LOCAL<br />
LDAP port: 389<br />
Server time: Sun, 14 Feb 2010 04:51:54 CET<br />
KDC server: 192.168.1.5<br />
Server time offset: 0</p>
<p>I can&#8217;t joint the domain. Is there anything I am missing ?<br />
Do you need more info from me ?<br />
Please help.</p>
<p>Thanks,<br />
Mirek</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andres PH</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75503</link>
		<dc:creator>Andres PH</dc:creator>
		<pubDate>Sat, 07 Nov 2009 01:26:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75503</guid>
		<description>Thanks for your article, I am not so experienced with linux but I got.
I am using Linux Centos 3.9 with Win2k3R2 servers and is working fine.
I saw that some people did not get and this is why I want to colaborate considering that I also didnt get the first time.
1.in /etc/samba/smb.conf all lines to &quot;add:&quot; have to be in the [Global] section 
2.before joining to the domain with #net ads join..., you have to sincronize the linux server time with de AD server using the command:
#ntpupdate 
or using the GUI in SystemSetting/DateTime (enable network time protocol an declaring your AD server)
3.you have to put the smb and winbind services to start automatically, do this using the GUI in Services
4. in my case I will use the linux as a printer server and just share the /home partition with full access for AD Domain Users
5.when setting ACL for the partition you want to create user folders is better to explicity declare starting with /dev/... as in my case:
/dev/hda5 /home ext3 default,acl 1 2
because it was (and leave commented):
LABEL=/home /home etx3 default 1 2
6.I give the access to /home to all domain users
#setfacl -m g:&quot;MYDOMAIN\Domain Users&quot;:rwx /home
7.I confirmed the assignment with
#getfacl /home
and appears this line:
group:Domain Users: rwx
8.now every user that is in the domain can connect to the linux server with full access to the /home partition without asking user/password
9.only in the PCs that are not in the domain, ie in workgroup I have to log with user@mydomain.com and password usisng the credential with some account from AD
10.I also can see the printers shared on the linux server but I still can connect to it, if someone can help me i will apreciate otherwise I will search how to do by myself
thanks.</description>
		<content:encoded><![CDATA[<p>Thanks for your article, I am not so experienced with linux but I got.<br />
I am using Linux Centos 3.9 with Win2k3R2 servers and is working fine.<br />
I saw that some people did not get and this is why I want to colaborate considering that I also didnt get the first time.<br />
1.in /etc/samba/smb.conf all lines to &#8220;add:&#8221; have to be in the [Global] section<br />
2.before joining to the domain with #net ads join&#8230;, you have to sincronize the linux server time with de AD server using the command:<br />
#ntpupdate<br />
or using the GUI in SystemSetting/DateTime (enable network time protocol an declaring your AD server)<br />
3.you have to put the smb and winbind services to start automatically, do this using the GUI in Services<br />
4. in my case I will use the linux as a printer server and just share the /home partition with full access for AD Domain Users<br />
5.when setting ACL for the partition you want to create user folders is better to explicity declare starting with /dev/&#8230; as in my case:<br />
/dev/hda5 /home ext3 default,acl 1 2<br />
because it was (and leave commented):<br />
LABEL=/home /home etx3 default 1 2<br />
6.I give the access to /home to all domain users<br />
#setfacl -m g:&#8221;MYDOMAIN\Domain Users&#8221;:rwx /home<br />
7.I confirmed the assignment with<br />
#getfacl /home<br />
and appears this line:<br />
group:Domain Users: rwx<br />
8.now every user that is in the domain can connect to the linux server with full access to the /home partition without asking user/password<br />
9.only in the PCs that are not in the domain, ie in workgroup I have to log with <a href="mailto:user@mydomain.com">user@mydomain.com</a> and password usisng the credential with some account from AD<br />
10.I also can see the printers shared on the linux server but I still can connect to it, if someone can help me i will apreciate otherwise I will search how to do by myself<br />
thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oes tsetnoc</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75490</link>
		<dc:creator>oes tsetnoc</dc:creator>
		<pubDate>Mon, 28 Sep 2009 08:02:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75490</guid>
		<description>Hi, Just like to tell you that this piece of info is one quick to the point, no nonsense, workable and effective way to have directories shared in Ubuntu as fast as possible. It worked for me and thank you for the effort. Keep up the good work.</description>
		<content:encoded><![CDATA[<p>Hi, Just like to tell you that this piece of info is one quick to the point, no nonsense, workable and effective way to have directories shared in Ubuntu as fast as possible. It worked for me and thank you for the effort. Keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lawrence Okpoho</title>
		<link>http://www.brentnorris.net/blog/archives/179/comment-page-2#comment-75450</link>
		<dc:creator>Lawrence Okpoho</dc:creator>
		<pubDate>Tue, 07 Jul 2009 10:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.brentnorris.net/blog/?p=179#comment-75450</guid>
		<description>i got this error when i type net ads join -U username@DOMAIN
ads_connect: Transport endpoint is not connected</description>
		<content:encoded><![CDATA[<p>i got this error when i type net ads join -U username@DOMAIN<br />
ads_connect: Transport endpoint is not connected</p>
]]></content:encoded>
	</item>
</channel>
</rss>

