I added: allow_weak_crypto = true to the [libdefaults] section in krb5.conf, as described in /usr/share/doc/libkrb5-3/NEWS.Debian.gz:
# net ads join -U Administrator Enter Administrator's password: Using short domain name -- LAB Joined 'VML-AMB' to realm 'mydomain.it' [2010/01/26 17:06:10, 0] libads/kerberos.c:332(ads_kinit_password) kerberos_kinit_password vml-a...@mydomain.it failed: Preauthentication failed The machine was apparently joined to the domain, but I cannot login with my domain credentials, getting always an authentication failure. "getent passwd" lists local users only. The file log.wb-LAB contains these lines: [2010/01/26 17:02:38, 1] libsmb/clikrb5.c:848(cli_krb5_get_ticket) cli_krb5_get_ticket: krb5_set_default_tgs_ktypes failed (Program lacks support for encryption type) [2010/01/26 17:02:38, 1] libsmb/cliconnect.c:745(cli_session_setup_kerberos) cli_session_setup_kerberos: spnego_gen_negTokenTarg failed: Program lacks support for encryption type [2010/01/26 17:02:39, 1] libsmb/clikrb5.c:848(cli_krb5_get_ticket) cli_krb5_get_ticket: krb5_set_default_tgs_ktypes failed (Program lacks support for encryption type) [2010/01/26 17:02:39, 1] libsmb/clikrb5.c:848(cli_krb5_get_ticket) cli_krb5_get_ticket: krb5_set_default_tgs_ktypes failed (Program lacks support for encryption type) [2010/01/26 17:02:39, 0] libads/sasl.c:819(ads_sasl_spnego_bind) kinit succeeded but ads_sasl_spnego_krb5_bind failed: Program lacks support for encryption type [2010/01/26 17:02:39, 1] winbindd/winbindd_ads.c:127(ads_cached_connection) ads_connect for domain LAB failed: Program lacks support for encryption type -- Winbind failed to connect to AD: Program lacks support for encryption type https://bugs.launchpad.net/bugs/512459 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in ubuntu. -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs