Samba + AD - No Logon Servers
Добавлено: 2009-04-03 8:15:23
погуглил все темы тут, не помогает ничего.
мой krb5.conf:
мой smb.conf:
testparm говорит:
а должно быть ROLE_DOMAIN_MEMBER кажется.
куда копать?
Код: Выделить всё
komp# kinit
marin_aa@TMIR.LOCAL's Password:
kinit: NOTICE: ticket renewable lifetime is 1 week
Код: Выделить всё
komp# klist
Credentials cache: FILE:/tmp/krb5cc_0
Principal: marin_aa@TMIR.LOCAL
Issued Expires Principal
Apr 3 11:03:36 Apr 3 21:03:36 krbtgt/TMIR.LOCAL@TMIR.LOCAL
Код: Выделить всё
komp# net ads testjoin
[2009/04/03 10:56:31, 0] utils/net_ads.c:ads_startup_int(286)
ads_connect: No logon servers
Join to domain is not valid: No logon servers
Код: Выделить всё
komp# net ads join -U marin_aa
Host is not configured as a member server.
Invalid configuration. Exiting....
Failed to join domain: WERR_INVALID_DOMAIN_ROLE
Код: Выделить всё
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = AFRODITA.TMIR.LOCAL
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
forwardable = yes
[realms]
TMIR.LOCAL = {
kdc = 192.168.111.249
admin_server = 192.168.111.249
kpasswd_server = 192.168.111.249
}
[domain_realm]
.afrodita.tmir.local = AFRODITA.TMIR.LOCAL
[kdc]
profile = /var/kerberos/krb5kdc/kdc.conf
[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
Код: Выделить всё
#GLOBAL PARAMETERS
[global]
workgroup = AFRODITA.TMIR.LOCAL
realm = AFRODITA.TMIR.LOCAL
preferred master = no
server string = IT-06
security = ADS
hosts allow = 192.168.111.0/24 127.0.0.1
interfaces = 192.168.111.68
encrypt passwords = yes
auth methods=winbind
log level = 3
log file = /var/log/samba/%m
max log size = 50
printcap name = cups
printing = cups
winbind use default domain = Yes
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = Yes
winbind nested groups = Yes
winbind separator = \\
idmap uid = 600-20000
idmap gid = 600-20000
;template primary group = "Domain Users"
template shell = /bin/csh
[homes]
comment = Home Direcotries
valid users = %S
read only = No
browseable = No
[printers]
comment = All Printers
path = /var/spool/cups
browseable = no
printable = yes
guest ok = yes
Код: Выделить всё
komp# testparm
Load smb config files from /usr/local/etc/smb.conf
Processing section "[homes]"
Processing section "[printers]"
Loaded services file OK.
Server role: ROLE_STANDALONE
куда копать?