Univention Bugzilla – Bug 55873
AD-Member: univention-samba joinscript doesn't store machine secret for samba idmap and ldap access
Last modified: 2024-02-12 08:45:08 CET
In AD-Member mode, the joinscript of univention-samba doesn't store the machine secret for samba idmap and ldap access. Support re-ran the joinscript, but it didn't update the password stored in `secrets.tdb`. Note: This resulted in `WBC_ERR_DOMAIN_NOT_FOUND` messages when accessing file shares or when running `wbinfo --sid-to-uid=<Well-Known-SID-of-Administrator>`. Due to the invalid LDAP-password, the "winbindd: idmap child" failed to initialize the default idmap backend and then apparently also skipped intialization of idmap_nss for the domain.
Now this occured after server-password-change and therefore after running 26univention-samba.inst ======================== Stopping winbind (via systemctl): winbind.service. Setting samba/user Not updating samba/user/pwdfile Multifile: /etc/samba/smb.conf lpcfg_do_global_parameter: WARNING: The "client use spnego" option is deprecated lpcfg_do_global_parameter: WARNING: The "domain logons" option is deprecated Setting stored password for "cn=ucs-fs02,cn=memberserver,cn=computers,dc=uni,dc=schein,dc=intranet" in secrets.tdb New SMB password:Failed to read new password! setting idmap secret for '*' from /etc/machine.secret Secret stored Stopping smbd (via systemctl): smbd.service. Stopping nmbd (via systemctl): nmbd.service. Starting nmbd (via systemctl): nmbd.service. Starting smbd (via systemctl): smbd.service. Object modified: cn=ucs-fs02,cn=memberserver,cn=computers,dc=uni,dc=schein,dc=intranet Failed to join domain: failed to lookup DC info for domain 'UNI.SCHEIN.INTRANET' over rpc: The attempted logon is invalid. This is either due to a bad username or authentication information. Failed to join domain: failed to find DC for domain UNI - A domain controller for this domain was not found. Failed to join domain: failed to find DC for domain UNI - A domain controller for this domain was not found. ERROR: Failed to join via net ads join. Please check your Samba DCs and your DNS and WINS configuration. EXITCODE=1 ==============================