since this morning, my TS-459U (Current firmware version: 3.2.6 Build 0423T) is not more willing to connect/join our AD (SBS 2008).
Generel setup:
Network: 192.168.1.0/24
DNS & AD-Server: SERVER1-0 192.168.1.1
NAS: 192.168.1.7
Settings1 on MS Networking:
X AD-Dom. member
Domain NetBIOS Name: MCM
AD Server Name: SERVER1-0
Domain: mcm.local
User: mcmadmin
PW: guess
Result:
Code: Select all
Microsoft network settings failed. Please check the DNS server, domain name, and user name and password for logging in the domain.
======== DEBUG START =======
/usr/local/samba/bin/net time set -S SERVER1-0.mcm.local
[command] echo ******** | /usr/bin/kinit "mcmadmin@mcm.LOCAL"
Password for mcmadmin@mcm.LOCAL:
Specify WORKGROUP = mcm
[command] /usr/local/samba/bin/net ads join -S SERVER1-0 -U "mcmadmin%********" -s /etc/config/smb.conf
[2010/08/17 14:42:57, 0] libads/sasl.c:ads_sasl_spnego_bind(819)
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Strong(er) authentication required
Failed to join domain: failed to connect to AD: Strong(er) authentication required
[command] /usr/local/samba/bin/net ads join -S SERVER1-0.mcm.local -U "mcmadmin%********" -s /etc/config/smb.conf
[2010/08/17 14:42:58, 0] libads/sasl.c:ads_sasl_spnego_bind(819)
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Strong(er) authentication required
Failed to join domain: failed to connect to AD: Strong(er) authentication required
[command] /usr/local/samba/bin/net ads join -U "mcmadmin%********" -s /etc/config/smb.conf
[2010/08/17 14:42:58, 0] libads/sasl.c:ads_sasl_spnego_bind(819)
kinit succeeded but ads_sasl_spnego_krb5_bind failed: Strong(er) authentication required
Failed to join domain: failed to connect to AD:
(I can't say what's displayed from here because it is cut)
X AD-Dom. member
Domain NetBIOS Name: MCM
AD Server Name: 192.168.1.1
Domain: mcm.local
User: mcmadmin
PW: guess
Result:
Code: Select all
Microsoft Networking configured failed. Cannot resolve domain, please check DNS server, AD Server Name and Domain.
======== DEBUG START =======
/usr/local/samba/bin/net time set -S 192.168.1.1.mcm.local
Sync time with domain name fail, try to sync time with IP
/usr/local/samba/bin/net time set -S
[command] echo ******** | /usr/bin/kinit "mcmadmin@mcm.LOCAL"
kinit(v5): Cannot resolve network address for KDC in realm mcm.LOCAL while getting initial credentials
[command] echo ******** | /usr/bin/kinit "mcmadmin@mcm.LOCAL"
http://support.microsoft.com/?scid=kb%3 ... 4&x=19&y=9
An update to FW 3.3.1 is not possible: Update failed. Please check the firmware version.
All other stuff like FTP, SSH, webmanagement is running.
I can connect with SSH to the TS and ping the AD-server using IP oder the servername, so network and name resolution seems to work.
Code: Select all
[/bin] # ping server1-0
PING server1-0 (192.168.1.1): 56 data bytes
64 bytes from 192.168.1.1: icmp_seq=0 ttl=128 time=0.1 ms
64 bytes from 192.168.1.1: icmp_seq=1 ttl=128 time=0.1 ms
^C
--- server1-0 ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 0.1/0.1/0.1 ms