LINUX.ORG.RU

Сообщения masyagutovmz

 

Ввод debian 9.4 в домен Active Directory.

Здравствуйте! Имеется: 1) контроллер домена на базе Microsoft Server 2012 R2 с именем test.local; 2) тестовая машина на основе debian 9.4.

Производим настройку по следующей статье https://blog.it-kb.ru/2016/10/15/join-debian-gnu-linux-8-6-to-active-director...

И у нас возникает ошибка при вводе команды

realm join \
--verbose \
--user=администратор \
--computer-name=comp195-debian.test.local \
--user-principal="host/comp195-debian.test.local@TEST.LOCAL" \
--computer-ou="CN=Computers,DC=test,DC=local" server_dc.test.local

Вывод текста с ошибками

 * Resolving: _ldap._tcp.server_dc.test.local
 * Resolving: server_dc.test.local
 * Performing LDAP DSE lookup on: 192.168.10.2
 * Successfully discovered: test.local
 * Unconditionally checking packages
 * Resolving required packages
 * Joining using a manual netbios name: comp195-debian.test.local
 * LANG=C /usr/sbin/adcli join --verbose --domain test.local --domain-realm TEST.LOCAL --domain-controller 192.168.10.2 --computer-name comp195-debian.test.local --computer-ou CN=Computers,DC=test,DC=local --os-name Debian GNU/Linux --os-version 9.4 (Stretch) --login-type user --login-user администратор --stdin-password --user-principal=host/comp195-debian.test.local@TEST.LOCAL
 * Using domain name: test.local
 * Using computer account name: comp195-debian.test.local
 * Using domain realm: test.local
 * Sending netlogon pings to domain controller: ldap://192.168.10.2
 * Received NetLogon info from: server_dc.test.local
 * Wrote out krb5.conf snippet to /var/cache/realmd/adcli-krb5-wuuNIR/krb5.d/adcli-krb5-conf-A9h0uF
 * Authenticated as user: администратор@TEST.LOCAL
 ! Couldn't authenticate to active directory: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure.  Minor code may provide more information (Server not found in Kerberos database)
adcli: couldn't connect to test.local domain: Couldn't authenticate to active directory: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure.  Minor code may provide more information (Server not found in Kerberos database)
 ! Insufficient permissions to join the domain
realm: Не удалось присоединиться к области: Insufficient permissions to join the domain

Помогите, пожалуйста, разобраться!

 ,

masyagutovmz
()

RSS подписка на новые темы