Bug#515767: samba: net ads join dont work(ads_sasl_spnego_krb5_bind failed:), but kinit klist are ok

2010-01-26 Thread Frank Matthieß
Package: samba Version: 2:3.4.3-2 Severity: normal nc-xfer:~# kinit administtra...@domain.tld Password for administra...@domain.tld: nc-xfer:~# klist Ticket cache: FILE:/tmp/krb5cc_0 Default principal: administra...@domain.tld Valid starting ExpiresService principal 01/26/10

Bug#515767: samba: net ads join dont work(ads_sasl_spnego_krb5_bind failed:), but kinit klist are ok

2010-01-26 Thread Frank Matthieß
The described bug seems to be an issue of the MIT kerberos behaviour. The adviced workaround does not work. Setting allow_weak_crypto=true in /etc/krb5.conf:libdefaults, will help to join the Windows 2003 AD, but wont work correct. See the comments from Holger Isenberg and me at