Samba: failed to set machine kerberos encryption types: Insufficient access
Issue
net ads join
command is failing with below error.
ads_sasl_spnego_bind: got server principal name = not_defined_in_RFC4178@please_ignore
context (service ticket) valid for 23925 seconds
name_to_fqdn: lookup for rhel1-> rhel1.example.com.
ads_domain_func_level: 6
libnet_Join:
libnet_JoinCtx: struct libnet_JoinCtx
out: struct libnet_JoinCtx
account_name : NULL
netbios_domain_name : 'EXAMPLE'
dns_domain_name : 'example.com'
forest_name : 'example.com'
dn : 'CN=rhel1,CN=Computers,DC=example,DC=com'
domain_sid : *
domain_sid : S-1-5-21-3319110045-1062523165-2216423467
modified_config : 0x00 (0)
error_string : 'failed to set machine kerberos encryption types: Insufficient access'
domain_is_ad : 0x01 (1)
result : WERR_GENERAL_FAILURE
return code = -1
Failed to join domain: failed to set machine kerberos encryption types: Insufficient access
Environment
- Red Hat Enterprise Linux 7
- Samba
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.