On Mon, Feb 14, 2005 at 02:16:05PM -0500, Stephen Frost wrote:
> Package: samba
> Version: 3.0.10-1
> Severity: important

>   Having some trouble adding a machine into an AD realm:

> ===# net -U M28994 ads join
> M28994's password:
> [2005/02/14 13:59:48, 0] libads/ldap.c:ads_add_machine_acct(1368)
>   ads_add_machine_acct: Host account for saruman already exists -
> modifying old account
> Using short domain name -- MITRETEK
> [2005/02/14 13:59:54, 0] libads/kerberos.c:get_service_ticket(335)
>   get_service_ticket: kerberos_kinit_password
> [EMAIL PROTECTED]@MITRETEK.ORG failed: Preauthentication failed
> Memory fault
> ===#

Per discussion on IRC, Samba has been known in the past to fail to join ADS
domains when the machine account already exists and the admin account used
for the join doesn't have access to create the machine account from scratch,
a situation that's unfortunately common in corporate settings.

-- 
Steve Langasek
postmodern programmer

Attachment: signature.asc
Description: Digital signature

Reply via email to