Please disable the packet signing on the domain controller.
Natalie
Marco Kuehn wrote:
>Hello, could anyone help me ?
>
>I have done the steps in the mail "CIFS Server - joining a domain?", but ..
>
>1) /etc/resolv.conf
>domain smb.de
>nameserver 10.99.1.11
>search smb.de
>
>2) /etc/nsswitch.conf
>hosts: files dns
>ipnodes: files dns
>
>ADS lookup:
># nslookup xeny
>Server: 10.99.1.11
>Address: 10.99.1.11#53
>
>Name: xeny.smb.de
>Address: 10.99.1.11
>
>
>2) /etc/krb5/krb5.conf
>
>[libdefaults]
> default_realm = SMB.DE
>[realms]
> SMB.DE = {
> kdc = xeny.smb.de
># admin_server = xeny.smb.de
> kpasswd_server = xeny.smb.de
> kpasswd_protocol = SET_CHANGE
> }
>
>[domain_realm]
> xeny.smb.de = SMB.DE
>
>3) sharectl get smb
>
>ads_enable=true
>ads_user=QWRtaW5pc3RyYXRvcg==
>ads_user_container=cn=Users
>ads_domain=smb.de
>ads_passwd=XCFiaW5nbzEyMw==
>
>4) svccfg -s idmap -> listprop
>
>config/domain_name astring
>config/forest_name astring
>config/site_name astring
>config/domain_controller astring
>
>5) restart smb/server and idmap
>
>6) smbadm join -u Administrator SMB
>
>Enter domain password:
>Joining 'SMB' ... this may take a minute ...
>failed to join domain 'SMB' (LOGON_FAILURE)
>
>What's wrong ? Are some steps more for kerberos ? DNS works fine !
>
>--- /var/adm/messages ---
>
>Dec 18 17:51:05 sunsmb smbd[453]: [ID 801289 daemon.error] DNS server internal
>error
>Dec 18 17:51:05 sunsmb smbd[453]: [ID 256202 daemon.error] smb_ads: DNS query
>for ADS host error: 3:
>Dec 18 17:51:05 sunsmb smbd[453]: [ID 894882 daemon.error] DNS entry should
>exist but does not exist
>Dec 18 17:51:07 sunsmb smbd[453]: [ID 597896 daemon.error] nb_write_msg:
>writev rc=-1
>Dec 18 17:51:07 sunsmb smbd[453]: [ID 478435 daemon.error] nb_keep_alive:
>write failed
>Dec 18 17:51:07 sunsmb smbd[453]: [ID 350819 daemon.error]
>SmbrdrExchange[115]: bad signature
>Dec 18 17:51:07 sunsmb smbd[453]: [ID 286894 daemon.error] SmbrdrSessionSetup:
>INVALID_NETWORK_RESPONSE
>Dec 18 17:51:07 sunsmb smbd[453]: [ID 871254 daemon.error] smbd: failed
>joining SMB (LOGON_FAILURE)
>
>--- /var/adm/messages ---
>
>Thanks for help.
>Marco
>
>
>This message posted from opensolaris.org
>_______________________________________________
>storage-discuss mailing list
>[email protected]
>http://mail.opensolaris.org/mailman/listinfo/storage-discuss
>
>
_______________________________________________
storage-discuss mailing list
[email protected]
http://mail.opensolaris.org/mailman/listinfo/storage-discuss