[Samba] Win2K3 DNS losing Samba DNS entries? - Samba

This is a discussion on [Samba] Win2K3 DNS losing Samba DNS entries? - Samba ; Hi there We are having a problem where the DNS "A" records of ADS member Samba servers are disappearing from DNS. It's not routine, but it is definitely real. What we normally do is assign static IPs, create DNS records ...

+ Reply to Thread
Results 1 to 13 of 13

Thread: [Samba] Win2K3 DNS losing Samba DNS entries?

  1. [Samba] Win2K3 DNS losing Samba DNS entries?

    Hi there

    We are having a problem where the DNS "A" records of ADS member Samba
    servers are disappearing from DNS. It's not routine, but it is
    definitely real. What we normally do is assign static IPs, create DNS
    records manually and then install and configure the Samba server (mainly
    CentOS4 and CentOS5) and "net ads join" it to the domain. This is
    normally good for a week or so - but then suddenly the "A" record
    disappears from DNS!

    If we manually add other Linux or non-Windows servers to the domain, and
    they don't run Samba - then this problem doesn't seem to occur - so it
    smells like some "Samba-to-AD" problem to me...

    Does this ring any bells? Would recompiling Samba with
    "--with-dnsupdate" (which still seems to be disabled by default) enable
    Samba to *continually* ensure its "A" record is kept intact? Weirdly
    enough, we find that if you go through this grief of disappearing "A"
    records for a week or so (and adding it back in), then suddenly it seems
    to all go right and the problem disappears for that particular server.
    But then the next one you install goes through the same problem.

    Any ideas appreciated.

    --
    Cheers

    Jason Haar
    Information Security Manager, Trimble Navigation Ltd.
    Phone: +64 3 9635 377 Fax: +64 3 9635 417
    PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  2. Re: [Samba] Win2K3 DNS losing Samba DNS entries?

    Jason Haar wrote:
    >
    > Does this ring any bells? Would recompiling Samba with
    > "--with-dnsupdate" (which still seems to be disabled by default)
    > enable Samba to *continually* ensure its "A" record is kept intact?
    > Weirdly enough, we find that if you go through this grief of
    > disappearing "A" records for a week or so (and adding it back in),
    > then suddenly it seems to all go right and the problem disappears for
    > that particular server. But then the next one you install goes through
    > the same problem.

    My bad - I just checked and we'd already rolled out Samba with DDNS
    updates enabled some 4-6 months ago (around 3.0.25). Could it be there
    are bugs in that code that leads to Samba deleting the DNS entry?

    --
    Cheers

    Jason Haar
    Information Security Manager, Trimble Navigation Ltd.
    Phone: +64 3 9635 377 Fax: +64 3 9635 417
    PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  3. [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  4. RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba
    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  5. RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba
    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  6. RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba
    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  7. RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  8. RE: [Samba] joining an AD

    Thanks for this. The problem appears to be that I can't create the workstation in the OU. I can use my same credentials to log into the AD and create a workstation in that OU through Windows but not through Linux.

    # net help ads join
    net ads join [options]
    Valid options:
    createupn[=UPN] Set the userPrincipalName attribute during the join.
    The deault UPN is in the form host/netbiosname@REALM.
    createcomputer=OU Precreate the computer account in a specific OU.
    The OU string read from top to bottom without RDNs and delimited by a '/'.
    E.g. "createcomputer=Computers/Servers/Unix"
    NB: A backslash '\' is used as escape at multiple levels and may
    need to be doubled or even quadrupled. It is not used as a separator


    So when I try

    # net ads join createcomputer="Servers/Windows/Computers/AD" -U willy%password


    Failed to pre-create the machine object in OU createcomputers=Servers/Windows/Computers/AD.
    [2008/01/28 20:15:30, 1] utils/net_ads.c:net_ads_join(1533)
    error calling net_precreate_machine_acct: No such object
    Failed to join domain: No such object
    [2008/01/28 20:15:30, 2] utils/net.c:main(1032)
    return code = -1


    * * * *
    Willy Calderon
    Contractor LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Mon 1/28/2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba


    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  9. RE: [Samba] joining an AD

    You may just have to join it to the domain and then move it manually
    into the OU through windows.

    Unless you upgrade to a newer version of samba that supports that
    feature.

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 5:15 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks for this. The problem appears to be that I can't create the
    workstation in the OU. I can use my same credentials to log into the AD
    and create a workstation in that OU through Windows but not through
    Linux.

    # net help ads join
    net ads join [options]
    Valid options:
    createupn[=UPN] Set the userPrincipalName attribute during the
    join.
    The deault UPN is in the form
    host/netbiosname@REALM.
    createcomputer=OU Precreate the computer account in a specific OU.
    The OU string read from top to bottom without RDNs
    and delimited by a '/'.
    E.g. "createcomputer=Computers/Servers/Unix"
    NB: A backslash '\' is used as escape at multiple
    levels and may
    need to be doubled or even quadrupled. It is
    not used as a separator


    So when I try

    # net ads join createcomputer="Servers/Windows/Computers/AD" -U
    willy%password


    Failed to pre-create the machine object in OU
    createcomputers=Servers/Windows/Computers/AD.
    [2008/01/28 20:15:30, 1] utils/net_ads.c:net_ads_join(1533)
    error calling net_precreate_machine_acct: No such object
    Failed to join domain: No such object
    [2008/01/28 20:15:30, 2] utils/net.c:main(1032)
    return code = -1


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Mon 1/28/2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the
    options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration
    Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba


    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  10. RE: [Samba] joining an AD

    In our AD environment, I pre-create computer records in our AD OU
    computers container via a Windows system using the Active Directory
    Users and Computers console. I then bind Samba domain members using "net
    ads join -U domain_admin_login".

    Andrew Philipoff
    Programmer Analyst
    Information Technology Services
    Department of Medicine
    University of California, San Francisco
    Phone: 415-476-1344
    Help Desk: 415-476-6827

    -----Original Message-----
    From: samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg
    [mailto:samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg] On
    Behalf Of Guillermo Gutierrez
    Sent: Monday, January 28, 2008 5:59 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You may just have to join it to the domain and then move it manually
    into the OU through windows.

    Unless you upgrade to a newer version of samba that supports that
    feature.

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 5:15 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks for this. The problem appears to be that I can't create the
    workstation in the OU. I can use my same credentials to log into the AD
    and create a workstation in that OU through Windows but not through
    Linux.

    # net help ads join
    net ads join [options]
    Valid options:
    createupn[=UPN] Set the userPrincipalName attribute during the
    join.
    The deault UPN is in the form
    host/netbiosname@REALM.
    createcomputer=OU Precreate the computer account in a specific OU.
    The OU string read from top to bottom without RDNs
    and delimited by a '/'.
    E.g. "createcomputer=Computers/Servers/Unix"
    NB: A backslash '\' is used as escape at multiple
    levels and may
    need to be doubled or even quadrupled. It is
    not used as a separator


    So when I try

    # net ads join createcomputer="Servers/Windows/Computers/AD" -U
    willy%password


    Failed to pre-create the machine object in OU
    createcomputers=Servers/Windows/Computers/AD.
    [2008/01/28 20:15:30, 1] utils/net_ads.c:net_ads_join(1533)
    error calling net_precreate_machine_acct: No such object
    Failed to join domain: No such object
    [2008/01/28 20:15:30, 2] utils/net.c:main(1032)
    return code = -1


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Mon 1/28/2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the
    options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration
    Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba


    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  11. RE: [Samba] joining an AD

    I tried that. I created the machine in the correct OU but this when I
    try to do this I get various errors:


    # net ads join -U username
    username's password:
    Using short domain name -- DOMAIN
    Failed to set servicePrincipalNames. Please ensure that
    the DNS domain of this server matches the AD domain,
    Or rejoin with using Domain Admin credentials.
    Deleted account for 'SERVERNAME' in realm 'DOMAIN'
    Failed to join domain: Constraint violation



    When I look back in the OU I find that the server has been removed.



    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913

    -----Original Message-----
    From: Philipoff, Andrew [mailto:aphilipoff@medicine.ucsf.edu]
    Sent: Monday, January 28, 2008 11:00 PM
    To: Guillermo Gutierrez; Calderon, Willy (NIH/NINDS) [C];
    samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    In our AD environment, I pre-create computer records in our AD OU
    computers container via a Windows system using the Active Directory
    Users and Computers console. I then bind Samba domain members using "net
    ads join -U domain_admin_login".

    Andrew Philipoff
    Programmer Analyst
    Information Technology Services
    Department of Medicine
    University of California, San Francisco
    Phone: 415-476-1344
    Help Desk: 415-476-6827

    -----Original Message-----
    From: samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg
    [mailto:samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg] On
    Behalf Of Guillermo Gutierrez
    Sent: Monday, January 28, 2008 5:59 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You may just have to join it to the domain and then move it manually
    into the OU through windows.

    Unless you upgrade to a newer version of samba that supports that
    feature.

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 5:15 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks for this. The problem appears to be that I can't create the
    workstation in the OU. I can use my same credentials to log into the AD
    and create a workstation in that OU through Windows but not through
    Linux.

    # net help ads join
    net ads join [options]
    Valid options:
    createupn[=UPN] Set the userPrincipalName attribute during the
    join.
    The deault UPN is in the form
    host/netbiosname@REALM.
    createcomputer=OU Precreate the computer account in a specific OU.
    The OU string read from top to bottom without RDNs
    and delimited by a '/'.
    E.g. "createcomputer=Computers/Servers/Unix"
    NB: A backslash '\' is used as escape at multiple
    levels and may
    need to be doubled or even quadrupled. It is
    not used as a separator


    So when I try

    # net ads join createcomputer="Servers/Windows/Computers/AD" -U
    willy%password


    Failed to pre-create the machine object in OU
    createcomputers=Servers/Windows/Computers/AD.
    [2008/01/28 20:15:30, 1] utils/net_ads.c:net_ads_join(1533)
    error calling net_precreate_machine_acct: No such object
    Failed to join domain: No such object
    [2008/01/28 20:15:30, 2] utils/net.c:main(1032)
    return code = -1


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Mon 1/28/2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the
    options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration
    Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba


    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  12. RE: [Samba] joining an AD

    The error I got "Failed to set servicePrincipalNames. Please ensure that the DNS domain of this server matches the AD domain, Or rejoin with using Domain Admin credentials" seems to point to the way that Kerberos requires a flat namespace to function. SO I would have to make sure the DNS name the server is DOMAIN.COM instead of SUB.DOMAIN.COM, which is going to be a problem.




    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Tue 1/29/2008 9:16 AM
    To: Philipoff, Andrew; Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    I tried that. I created the machine in the correct OU but this when I
    try to do this I get various errors:


    # net ads join -U username
    username's password:
    Using short domain name -- DOMAIN
    Failed to set servicePrincipalNames. Please ensure that
    the DNS domain of this server matches the AD domain,
    Or rejoin with using Domain Admin credentials.
    Deleted account for 'SERVERNAME' in realm 'DOMAIN'
    Failed to join domain: Constraint violation



    When I look back in the OU I find that the server has been removed.



    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913

    -----Original Message-----
    From: Philipoff, Andrew [mailto:aphilipoff@medicine.ucsf.edu]
    Sent: Monday, January 28, 2008 11:00 PM
    To: Guillermo Gutierrez; Calderon, Willy (NIH/NINDS) [C];
    samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    In our AD environment, I pre-create computer records in our AD OU
    computers container via a Windows system using the Active Directory
    Users and Computers console. I then bind Samba domain members using "net
    ads join -U domain_admin_login".

    Andrew Philipoff
    Programmer Analyst
    Information Technology Services
    Department of Medicine
    University of California, San Francisco
    Phone: 415-476-1344
    Help Desk: 415-476-6827

    -----Original Message-----
    From: samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg
    [mailto:samba-bounces+aphilipoff=medicine.ucsf.edu@lists.samba.o rg] On
    Behalf Of Guillermo Gutierrez
    Sent: Monday, January 28, 2008 5:59 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You may just have to join it to the domain and then move it manually
    into the OU through windows.

    Unless you upgrade to a newer version of samba that supports that
    feature.

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 5:15 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks for this. The problem appears to be that I can't create the
    workstation in the OU. I can use my same credentials to log into the AD
    and create a workstation in that OU through Windows but not through
    Linux.

    # net help ads join
    net ads join [options]
    Valid options:
    createupn[=UPN] Set the userPrincipalName attribute during the
    join.
    The deault UPN is in the form
    host/netbiosname@REALM.
    createcomputer=OU Precreate the computer account in a specific OU.
    The OU string read from top to bottom without RDNs
    and delimited by a '/'.
    E.g. "createcomputer=Computers/Servers/Unix"
    NB: A backslash '\' is used as escape at multiple
    levels and may
    need to be doubled or even quadrupled. It is
    not used as a separator


    So when I try

    # net ads join createcomputer="Servers/Windows/Computers/AD" -U
    willy%password


    Failed to pre-create the machine object in OU
    createcomputers=Servers/Windows/Computers/AD.
    [2008/01/28 20:15:30, 1] utils/net_ads.c:net_ads_join(1533)
    error calling net_precreate_machine_acct: No such object
    Failed to join domain: No such object
    [2008/01/28 20:15:30, 2] utils/net.c:main(1032)
    return code = -1


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Mon 1/28/2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the
    options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration
    Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba


    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

  13. RE: [Samba] joining an AD - SOLVED

    The problem is that Kerberos can only deal with flatname space to
    function so you cannot have subdomain.domain.com as the Linux server
    name in DNS. Changing that solved this for me.



    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 7:58 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Thanks. I keep getting this error every time I log in now with the
    options you've given below


    [2008/01/28 19:49:22, 4] libads/sasl.c:ads_sasl_bind(521)
    Found SASL mechanism GSS-SPNEGO
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 48018 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 2 840 113554 1 2 2 3
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(213)
    ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
    [2008/01/28 19:49:22, 3] libads/sasl.c:ads_sasl_spnego_bind(222)
    ads_sasl_spnego_bind: got server principal name = nihdc$@NIH.GOV
    [2008/01/28 19:49:22, 4] libsmb/clikrb5.c:ads_krb5_mk_req(610)
    ads_krb5_mk_req: Advancing clock by 63 seconds to cope with clock skew
    [2008/01/28 19:49:22, 3] libsmb/clikrb5.c:ads_cleanup_expired_creds(528)
    ads_cleanup_expired_creds: Ticket in ccache[MEMORY:net_ads] expiration
    Tue, 29 Jan 2008 05:50:25 EST
    Bad option: SEVERN
    Failed to join domain: Invalid parameter
    [2008/01/28 19:49:22, 2] utils/net.c:main(1032)
    return code = -1






    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Unix Systems Administrator
    Bldg. 10, NIH/NINDS
    Tel: 301 435 1913



    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Mon 1/28/2008 4:57 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Whoops,

    The trailing (") should be at the end of the OU path, in your case after
    the 'AD'.

    The computername is a separate value that you are feeding it.

    net ads join createcomputer="Servers/Windows/Computers/AD" computername

    -----Original Message-----
    From: Calderon, Willy (NIH/NINDS) [C] [mailto:calderow@ninds.nih.gov]
    Sent: Monday, January 28, 2008 1:59 PM
    To: Guillermo Gutierrez; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    Is there a trailing quote (") after computer name ?


    * * * *
    Willy Calderon
    Contractor - LCG Systems
    Tel: 301 435 1913


    -----Original Message-----
    From: Guillermo Gutierrez [mailto:ggutierrez@marketscan.com]
    Sent: Monday, January 28, 2008 4:45 PM
    To: Calderon, Willy (NIH/NINDS) [C]; samba@lists.samba.org
    Subject: RE: [Samba] joining an AD

    You have to use the "createcomputer" parameter if you want to specify
    the OUs.

    Ex: net ads join createcomputer="Servers/Windows/Computers/AD
    computername

    -----Original Message-----
    From: samba-bounces+ggutierrez=marketscan.com@lists.samba.org
    [mailto:samba-bounces+ggutierrez=marketscan.com@lists.samba.org] On
    Behalf Of Calderon, Willy (NIH/NINDS) [C]
    Sent: Monday, January 28, 2008 1:17 PM
    To: samba@lists.samba.org
    Subject: [Samba] joining an AD



    Hi there -

    I am trying to join the domain using the net ads join command but keep
    getting a "

    Bad option: Servers/Windows/Computers/AD
    Failed to join domain: Invalid parameter

    when I try to add the computer into the correct OU like so:

    net ads join "Servers/Windows/Computers/AD



    Is there a correct way to get this to work?

    I'm on a Red Hat Enterprise 4 system with samba-3.0.25b-1.el4_6.4



    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba
    --
    To unsubscribe from this list go to the following URL and read the
    instructions: https://lists.samba.org/mailman/listinfo/samba

+ Reply to Thread