Bug 5815 - Cant join ADS domain with NonAdmin User
Summary: Cant join ADS domain with NonAdmin User
Alias: None
Product: Samba 3.0
Classification: Unclassified
Component: net utility (show other bugs)
Version: 3.0.32
Hardware: x86 Windows XP
: P3 major
Target Milestone: none
Assignee: Jim McDonough
QA Contact: Samba QA Contact
Depends on:
Reported: 2008-10-07 06:32 UTC by Karthikeyan
Modified: 2009-06-11 17:20 UTC (History)
2 users (show)

See Also:

Network Trace (12.41 KB, application/x-zip-compressed)
2008-10-07 06:35 UTC, Karthikeyan
no flags Details
Debug Level 10 Logs (9.41 KB, application/x-zip-compressed)
2008-10-07 06:36 UTC, Karthikeyan
no flags Details
smb.conf file (1.11 KB, text/plain)
2008-10-07 06:40 UTC, Karthikeyan
no flags Details
Network capture (13.06 KB, application/x-zip-compressed)
2008-10-07 09:30 UTC, Feroz Ahmed (dead mail address)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Karthikeyan 2008-10-07 06:32:50 UTC
When i do "net ads join" with non admin user in 2008 server im unable to join samba to 2008 ADS domain.
But im able to join windows vista machine to domain with same user.
Comment 1 Karthikeyan 2008-10-07 06:35:40 UTC
Created attachment 3664 [details]
Network Trace
Comment 2 Karthikeyan 2008-10-07 06:36:20 UTC
Created attachment 3665 [details]
Debug Level 10 Logs
Comment 3 Karthikeyan 2008-10-07 06:40:45 UTC
Created attachment 3666 [details]
smb.conf file
Comment 4 Gerald (Jerry) Carter (dead mail address) 2008-10-07 08:34:58 UTC
The SMB signaturesa are good.  The failure is the set_userinfo2:

  rpc_api_pipe: Remote machine ENG2K8SMB.2k8.com pipe \samr fnum 0x4004 returned 8 bytes.
  000000 samr_io_r_set_userinfo2
      0000 status: NT_STATUS_ACCESS_DENIED

How are you pre-creating the account in AD and delegating the rights to join the
machine to the domain?  If the network trace you uploaded is not from the Vista client's
successful domain join, would you mind send us one of those traces as well?  Thanks.
Comment 5 Guenther Deschner 2008-10-07 09:18:13 UTC
Ok, just re-tested with 3.0.32 and w2k8, joining works fine with non-admin user, as long as the machine account doesn't exist already in the domain (which in your logs, is the case).

Can you delete the old machine account and retry?
Comment 6 Feroz Ahmed (dead mail address) 2008-10-07 09:30:20 UTC
Created attachment 3667 [details]
Network capture

Network capture between vista and 2k8
Comment 7 Guenther Deschner 2008-10-30 18:56:40 UTC
(In reply to comment #6)
> Created an attachment (id=3667) [edit]
> Network capture
> Network capture between vista and 2k8

Hm, this trace did not have any DCERPC packets in it, just some CLDAP and Mailslot and DNS traffic. Can you send us the correct trace ?

And was this failed join attempt from a pre-recreated machine account ?
Comment 8 Guenther Deschner 2009-06-11 17:20:41 UTC
Could not reproduce and got no additional info, so closing.

Please reopen if you still see an issue here.