[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Adding Linux box to Active Directory to use NTLM with Squid proxy

Posted on 2007-09-28
3
Medium Priority
?
1,079 Views
Last Modified: 2012-05-05
Hello,

I'm trying to add a kubuntu box to my AD but everytime I try to join it I get the same message, which is:

Using short domain name -- DOMAINNAME
Failed to set servicePrincipalNames. Please ensure that
the DNS domain of this server matches the AD domain,
Or rejoin with using Domain Admin credentials.
Disabled account for 'machinename' in realm 'MY.DOMAIN.COM'

I use some tutorials I found on the web to configure my smb.conf and my krb5.conf files. Here's how I set them up:

smb.conf

[global]
      log file = /var/log/samba/%m.log
      socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
      wins server = IP.ADDRESS
      domain master = False
      encrypt passwords = Yes
      realm = MY.DOMAIN.COM
      dns proxy = No
      netbios name = machinename
      server string = Proxy Server
      password server = dc
      local master = No
      workgroup = DOMAIN
      security = ads
      preferred master = False
      winbind separator = /
      winbind use default domain = yes
      max log size = 0
      idmap gid = 10000-20000
      idmap uid = 10000-20000

krb5.conf

[libdefaults]
      default_realm = MY.DOMAIN.COM

[realms]
      MY.DOMAIN.COM = {
            kdc = DC.MY.DOMAIN.COM:88
            admin_server = DC.MY.DOMAIN.COM:749
            default_domain = MY.DOMAIN.COM
      }

[domain_realm]
      .my.domain.com = MY.DOMAIN.COM
      my.domain.com = MY.DOMAIN.COM

I can get a ticket using the kinit command with a domain admin account and I see it when typing klist but I can't go further than that...

Any idea what I could check or do to make it work? As mentionned above, the goal of this is to use NTLM authentication with my Squid proxy.

Thanks in advance!
0
Comment
Question by:DolGuldur
  • 2
3 Comments
 
LVL 4

Expert Comment

by:avatech
ID: 19992231
Or rejoin with using Domain Admin credentials.
Disabled account for 'machinename' in realm 'MY.DOMAIN.COM'


You are using a valid domain admin account to perform the net ads join?  I've also found that dotted names do not work for net ads join.

Does the machine name you've setup under your samba/winbind exist already in your AD environment?

I used this guide to the letter in setting up several AD integrated Samba boxes with Ubuntu 7.04

http://ubuntuforums.org/showthread.php?t=280702&highlight=active+directory+samba

Although this is for Dapper, making note of the changes in /etc/apt/sources.list at the very beginning, all of this was nearly identical and worked like a charm.  My only problem I experienced was the inability to use a dotted login name to join.

Also something else you can consider.  I used Vmware to do all of my testing for samba & winbind.  Once that was established working, I built a fresh machine and used my own guide from the VM testing.

Cheers!
0
 
LVL 5

Author Comment

by:DolGuldur
ID: 19993481
Hello avatech,

Yes I'm using a valid domain admins account to join. The machine name doesn't exist in my AD. I've looked at the link you provided and it looks a lot like what I already did but, since I've spent so much time on this already, I'll restart from the beginning using this howto.

I'll keep you posted about the result. Thanks for your time!
0
 
LVL 4

Accepted Solution

by:
avatech earned 2000 total points
ID: 19993535
Ok hope it helps just remember that there are some very minor modifications along the way that you will need to personalize, like the sources.list and default permissions and forced permissions on Samba in regards to the directory and file masks.  There's also another doc you may want to check out regarding ACL on the file system.  Take a gander here:

http://tlug.dnho.net/?q=node/171
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
Fine Tune your automatic Updates for Ubuntu / Debian
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Suggested Courses
Course of the Month18 days, 12 hours left to enroll

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question