[RHEL6] Problems joining RHEL6 to AD 2008 trusted domain

Solution Verified - Updated -

Environment

  • Red Hat Enterprise Linux 6.1
  • samba3.5.6-86

Issue

Using samba-3.5.6-86.el6 is not possible to join samba machine in AD 2008 using an user and password from a trusted domain. and the following error is logged:

#net ads join -S s123dc01 -U user@DOMAIN.TEST

libads/kerberos.c:333(ads_kinit_password)
  kerberos_kinit_password user@DOMAIN.TEST@TRUSTED.TEST failed: Malformed representation of principal
Failed to join domain: failed to connect to AD: Malformed representation of principal

How to solve it?

Resolution

In samba-3.5.6-86.el6 there is a bug that causes samba fail in joining AD 2008 when using a user account from a trusted domain.

To  definitely solve this problem you need to update samba package to version samba-3.5.10-114.el6 that contains a fix for this problem and a lot of other improvements.

More details about this new package version can be found in Errata details: RHBA-2011:1519

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.

Comments