I also have observe that you are joining to windows Active Directory Domain Controller instead of ubuntu Active Directory Domain Controller. As mentioned in the comment #15 on 2017-12-18
When i changed /etc/ldap/ldap.conf: to TLS_REQCERT Allow and connect to Windows Active directory Domain controller i was able to join with client ldap sasl wrapping = plain workaround but when used tried to join Ubuntu AD DC i get below error:- Sign or Seal are required.>, res_matched: <> kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: Strong(er) authentication required. Please re run this test when other ubuntu is configured as AD DC. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1576799 Title: Regression: 2:4.3.8+dfsg-0ubuntu0.14.04.2 Failed to Issue the StartTLS instruction To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1576799/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs