The push for 6850508 is a flag day for the use of kclient or smbadm
to join a Windows 2008 domain:
6850508 Unable to join Windows 2008 domain (SP2 or later)
Prior to SXCE Build 119, the Solaris CIFS services contained a
workaround for
the Windows 2008 SP1 problem described in KB951191.
http://support.microsoft.com/default.aspx/kb/951191
If you upgrade to SXCE Build 119 or later and your Windows 2008 domain
controller
is running Windows Server 2008 SP2 or R2, no action is required.
If you upgrade to SXCE Build 119 or later and your Windows 2008 domain
controller
is running Windows Server 2008 SP1, you must apply the hotfix described
in KB951191 or install Windows 2008 SP2.
Otherwise you will see the following error messages when attempting to
join a Windows 2008 domain:
smbd[100938]: [ID 702911 daemon.debug] NETR[0x0f]: error: ACCESS_DENIED
(0xc0000022)
idmap[100512]: [ID 706612 daemon.debug] LDAP SASL bind to
w2k8dc.w2k8ads.com:389 failed (Local error)
smbd[100938]: [ID 526780 daemon.notice] Failed to establish NETLOGON
credential chain
smbd[100938]: [ID 871254 daemon.error] smbd: failed joining w2k8ads.com
(UNSUCCESSFUL)
NOTE: Installing Windows 20008 SP2 or the Microsoft Kerberos hotfix
KB951191 or Windows Server 2008 R2 without upgrading to SXCE Build 119 will
break idmapd and other Solaris applications using Kerberos. If make
any of these changes on Windows 2008, you must upgrade to SXCE Build 119
(or
later) and rejoin the domain.
Regards,
Natalie
_______________________________________________
cifs-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/cifs-discuss