Edit /etc/samba.smb.conf and make sure you have the following
WORKGROUP = MYDOMAIN
REALM = MYDOMAIN.MYCOMPANY.COM
SECURITY = ADS
netbios name = MYCOMPUTER
Make sure your /etc/krb5.conf file has at least the following:
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = MYDOMAIN.MYCOMPANY.COM
dns_lookup_realm = false
dns_lookup_kdc = false
[realms]
MYDOMAIN.MYCOMPANY.COM = {
kdc = MYDOMAIN.MYCOMPANY.COM:88
admin_server = MYDOMAIN.MYCOMPANY.COM:749
default_domain = MYDOMAIN.MYCOMPANY.COM
}
[domain_realm]
.kerberos.server = MYDOMAIN.MYCOMPANY.COM
[kdc]
profile = /var/kerberos/krb5kdc/kdc.conf
[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
From command line you should do the following:
- kinit administrator@MYDOMAIN.MYCOMPANY.COM
- net join -U administrator
Your OSVault hostname MUST match your full host name on the PDC (i.e. the output from `hostname` command is MYMACHINE.MYDOMAIN.MYCOMPANY.COM
Go to http://www.joeware.net/freetools to get a set of tools for your Windows 2003 server, such as adfind, admod, oldcmp, findexpacc, and memberof.
No comments:
Post a Comment