Cannot Log onto Domain Member Workstation After Joining Domain
After successfully joining the domain, user logons fail with one of two messages: one to the
effect that the domain controller cannot be found; the other claims that the account does not
exist in the domain or that the password is incorrect. This may be due to incompatible
settings between the Windows client and the Samba-3 server for
schannel
(secure channel) settings or
smb signing
settings. Check your Samba
settings for
client schannel
,
server schannel
,
client signing
,
server signing
by executing:
testparm -v | grep channel
and looking for the value of these parameters.
Also use the MMC Local Security Settings. This tool is available from the
Control Panel. The Policy settings are found in the Local Policies/Security Options area and are prefixed by
Secure Channel:..., and Digitally sign...
.
It is important that these be set consistently with the Samba-3 server settings.
|