On Wed, 2013-01-30 at 21:49 +0100, İhsan Doğan wrote: > Hi, > > I'm running a Active Directory domain on Samba 4.0.1 and I'm trying to > join a Solaris 11 machine this domain: > > # smbadm join -u Administrator DOMAIN > After joining DOMAIN the smb service will be restarted automatically. > Would you like to continue? [no]: yes > Enter domain password: > Locating DC in DOMAIN ... this may take a minute ... > Joining DOMAIN ... this may take a minute ... > failed to join DOMAIN: UNSUCCESSFUL > Please refer to the system log for more information. > > In /var/adm/messages: > Jan 30 21:33:34 host smbd[827]: [ID 232655 daemon.notice] ldap_modify: > Insufficient access > Jan 30 21:33:34 host smbd[827]: [ID 702911 daemon.notice] Workstation > trust account update failed > > Windows 7 clients are able to join, but Solaris 11 fails. > > Kerberos seems to be fine: > # kinit oskar > Password for [email protected]: > Warning: Your password will expire in 41 days on Wed Mar 13 19:44:52 2013 > > But if I run it for Administrator: > # kinit Administrator > Password for [email protected]: > Warning: Your password will expire in 41 days on Wed Mar 13 18:36:46 2013 > kinit: no ktkt_warnd warning possible > > Any idea what is going wrong here?
Does this work against a freshly provisioned Samba 4.0.3 domain? We fixed a lot of ACL related things with that release. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
