Bug 15905 - samba-4.21 fails to join AD when multiple DCs are returned
Summary: samba-4.21 fails to join AD when multiple DCs are returned
Status: RESOLVED FIXED
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Other (show other bugs)
Version: 4.21.0
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Jule Anger
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-09-05 00:56 UTC by Pavel Filipenský
Modified: 2025-11-11 12:30 UTC (History)
1 user (show)

See Also:


Attachments
4.22 patch (18.60 KB, patch)
2025-09-06 20:04 UTC, Pavel Filipenský
ab: review+
Details
4.21 patch (18.60 KB, patch)
2025-09-06 20:08 UTC, Pavel Filipenský
ab: review+
Details
4.23 patch (18.58 KB, patch)
2025-09-08 09:10 UTC, Pavel Filipenský
ab: review+
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Pavel Filipenský 2025-09-05 00:56:17 UTC
- 'net ads join' can create machine account at DC1
- keytab_create code triggered the join tries to read KVNO from DC2 and fails with e.g.


gensec_gse_client_prepare_ccache: Kinit for F0D26C71F6$@SAMBA.EXAMPLE.COM to access ldap/dc2.samba.example.com failed: Client not found in Kerberos database: NT_STATUS_LOGON_FAILURE


Fix will follow
Comment 1 Samba QA Contact 2025-09-05 13:39:03 UTC
This bug was referenced in samba master:

5d2f60ae5aa96751b74901ae5384291ef338b152
36f6ac547c09f492d1dcab11570e8bcbd377cf26
5d1d3a8b568b5a07ed1ed537d20aa93820cecc14
Comment 2 Pavel Filipenský 2025-09-06 20:04:52 UTC
Created attachment 18706 [details]
4.22 patch
Comment 3 Pavel Filipenský 2025-09-06 20:08:53 UTC
Created attachment 18707 [details]
4.21 patch
Comment 4 Alexander Bokovoy 2025-09-07 07:14:11 UTC
Comment on attachment 18706 [details]
4.22 patch

LGTM
Comment 5 Alexander Bokovoy 2025-09-07 07:14:39 UTC
Comment on attachment 18707 [details]
4.21 patch

LGTM
Comment 6 Alexander Bokovoy 2025-09-07 07:15:20 UTC
Jule, please push to corresponding releases. Thank you!
Comment 7 Alexander Bokovoy 2025-09-07 07:15:53 UTC
@Pavel, should we also do 4.23 backport?
Comment 8 Pavel Filipenský 2025-09-08 09:10:58 UTC
Created attachment 18710 [details]
4.23 patch
Comment 9 Alexander Bokovoy 2025-09-08 09:30:23 UTC
Comment on attachment 18710 [details]
4.23 patch

LGTM
Comment 10 Jule Anger 2025-09-09 06:52:33 UTC
Pushed to autobuild-v4-{23,22,21}-test.
Comment 11 Samba QA Contact 2025-09-09 12:47:12 UTC
This bug was referenced in samba v4-23-test:

65181b65b83f038e1f36ebfe094e17655fcf973d
5294b24f6e2df1906830638ab50b5967d546f765
5bbb682b0fc5852ef6ea21a7ee51b545481efc46
Comment 12 Samba QA Contact 2025-09-11 11:07:20 UTC
This bug was referenced in samba v4-22-test:

b26cc594a1e4e787a98164ded77be7b2ef152cb9
0034b13f23ab9d16d62dbf0619e24233c520dae3
6ee4a2bfcbdd432687a96caab69914b8b92abdbd
Comment 13 Samba QA Contact 2025-09-11 12:29:03 UTC
This bug was referenced in samba v4-21-test:

393e35dca2bb83492c879c9d044f2505daef377b
015c3ef6c1040ca64d29ae95ade7cc8970929b25
d1a778414e178bb1a3495d391d6f55ab883e8903
Comment 14 Jule Anger 2025-09-11 15:31:39 UTC
Closing out bug report.

Thanks!
Comment 15 Samba QA Contact 2025-09-12 08:29:21 UTC
This bug was referenced in samba v4-23-stable (Release samba-4.23.0):

65181b65b83f038e1f36ebfe094e17655fcf973d
5294b24f6e2df1906830638ab50b5967d546f765
5bbb682b0fc5852ef6ea21a7ee51b545481efc46
Comment 16 Samba QA Contact 2025-10-16 14:37:33 UTC
This bug was referenced in samba v4-22-stable (Release samba-4.22.6):

b26cc594a1e4e787a98164ded77be7b2ef152cb9
0034b13f23ab9d16d62dbf0619e24233c520dae3
6ee4a2bfcbdd432687a96caab69914b8b92abdbd
Comment 17 Samba QA Contact 2025-11-11 12:30:53 UTC
This bug was referenced in samba v4-21-stable (Release samba-4.21.10):

393e35dca2bb83492c879c9d044f2505daef377b
015c3ef6c1040ca64d29ae95ade7cc8970929b25
d1a778414e178bb1a3495d391d6f55ab883e8903