I've followed through the howto and am having good success on Ubuntu 8.10 (Intrepid Ibex, I think) until the "net ads join" stage. I'm getting my ticket fine:
Code:
$ klist
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: myusername@MYSUBDOMAIN.MYDOMAIN.ICS
Valid starting Expires Service principal
11/06/08 13:01:01 11/06/08 19:41:01 krbtgt/MYSUBDOMAIN.MYDOMAIN.ICS@MYSUBDOMAIN.MYDOMAIN.ICS
Kerberos 4 ticket cache: /tmp/tkt1000
klist: You have no tickets cached
But when I perform the net ads join, I get the following (with debug enabled):
Code:
$ net ads join -U myusername@MYSUBDOMAIN.MYDOMAIN.ICS -d1
Enter myusername@MYSUBDOMAIN.MYDOMAIN.ICS's password:
[2008/11/06 13:01:18, 1] libnet/libnet_join.c:libnet_Join(1770)
libnet_Join:
libnet_JoinCtx: struct libnet_JoinCtx
in: struct libnet_JoinCtx
dc_name : NULL
machine_name : 'MYHOSTNAME'
domain_name : *
domain_name : 'MYSUBDOMAIN.MYDOMAIN.ICS'
account_ou : NULL
admin_account : 'myusername@MYSUBDOMAIN.MYDOMAIN.ICS'
admin_password : *
machine_password : NULL
join_flags : 0x00000023 (35)
0: WKSSVC_JOIN_FLAGS_JOIN_WITH_NEW_NAME
0: WKSSVC_JOIN_FLAGS_JOIN_DC_ACCOUNT
0: WKSSVC_JOIN_FLAGS_DEFER_SPN
0: WKSSVC_JOIN_FLAGS_MACHINE_PWD_PASSED
0: WKSSVC_JOIN_FLAGS_JOIN_UNSECURE
1: WKSSVC_JOIN_FLAGS_DOMAIN_JOIN_IF_JOINED
0: WKSSVC_JOIN_FLAGS_WIN9X_UPGRADE
0: WKSSVC_JOIN_FLAGS_ACCOUNT_DELETE
1: WKSSVC_JOIN_FLAGS_ACCOUNT_CREATE
1: WKSSVC_JOIN_FLAGS_JOIN_TYPE
os_version : NULL
os_name : NULL
create_upn : 0x00 (0)
upn : NULL
modify_config : 0x00 (0)
ads : NULL
debug : 0x01 (1)
secure_channel_type : SEC_CHAN_WKSTA (2)
[2008/11/06 13:01:19, 1] libnet/libnet_join.c:libnet_Join(1801)
libnet_Join:
libnet_JoinCtx: struct libnet_JoinCtx
out: struct libnet_JoinCtx
account_name : NULL
netbios_domain_name : NULL
dns_domain_name : NULL
dn : NULL
domain_sid : NULL
domain_sid : (NULL SID)
modified_config : 0x00 (0)
error_string : 'failed to find DC for domain MYSUBDOMAIN.MYDOMAIN.ICS'
domain_is_ad : 0x00 (0)
result : WERR_DOMAIN_CONTROLLER_NOT_FOUND
Failed to join domain: failed to find DC for domain MYSUBDOMAIN.MYDOMAIN.ICS
I can ping the DC machine by hostname without issue, fwiw. Any thoughts on how to work around this?
~~Douglas K
Bookmarks