'net ads join -U username' failing with an error 'NT_STATUS_IO_TIMEOUT'











up vote
2
down vote

favorite












I am attempting to provide access to Ubuntu shared directories using Active Directory users and group using Samba. I am following this article to install and configure AD and Unix so that access can be provided:



Summary




  1. As a part of the installation, I have installed ntp krb5-user samba(v4.1.6) samba-common smbclient winbind


  2. I followed the configuration settings as provided in the above article. I have configured ntp.conf, resolv.conf, krb5.conf, nsswitch.conf and smb.conf.



  3. After restarting all of the services and while joining the domain using sudo net ads join -U administrator, I am getting the following error:



    Failed to join domain: failed to lookup DC info for domain 'CELESTIAL1' over rpc: NT_STATUS_IO_TIMEOUT




Testing




  1. I tried to execute kinit username, the ticket got generated successfully and I was able to verify from command 'klist'.


  2. I am able to ping the Ubuntu server's IP and the Windows server's IP as well as the domain from both the sides.


  3. The services winbind, nmbd, and smbd are running as expected.


  4. I rebooted the Ubuntu machine and AD server, but same error is showing while performing the domain join operation.



Questions




  1. What does the NT_STATUS_IO_TIMEOUT error indicate? Are there any issues on the Windows Server or on Ubuntu machine?


  2. How can I join the Ubuntu machine to Active Directory? Are there any steps that I missed that need to be performed to join the domain successfully?











share|improve this question




























    up vote
    2
    down vote

    favorite












    I am attempting to provide access to Ubuntu shared directories using Active Directory users and group using Samba. I am following this article to install and configure AD and Unix so that access can be provided:



    Summary




    1. As a part of the installation, I have installed ntp krb5-user samba(v4.1.6) samba-common smbclient winbind


    2. I followed the configuration settings as provided in the above article. I have configured ntp.conf, resolv.conf, krb5.conf, nsswitch.conf and smb.conf.



    3. After restarting all of the services and while joining the domain using sudo net ads join -U administrator, I am getting the following error:



      Failed to join domain: failed to lookup DC info for domain 'CELESTIAL1' over rpc: NT_STATUS_IO_TIMEOUT




    Testing




    1. I tried to execute kinit username, the ticket got generated successfully and I was able to verify from command 'klist'.


    2. I am able to ping the Ubuntu server's IP and the Windows server's IP as well as the domain from both the sides.


    3. The services winbind, nmbd, and smbd are running as expected.


    4. I rebooted the Ubuntu machine and AD server, but same error is showing while performing the domain join operation.



    Questions




    1. What does the NT_STATUS_IO_TIMEOUT error indicate? Are there any issues on the Windows Server or on Ubuntu machine?


    2. How can I join the Ubuntu machine to Active Directory? Are there any steps that I missed that need to be performed to join the domain successfully?











    share|improve this question


























      up vote
      2
      down vote

      favorite









      up vote
      2
      down vote

      favorite











      I am attempting to provide access to Ubuntu shared directories using Active Directory users and group using Samba. I am following this article to install and configure AD and Unix so that access can be provided:



      Summary




      1. As a part of the installation, I have installed ntp krb5-user samba(v4.1.6) samba-common smbclient winbind


      2. I followed the configuration settings as provided in the above article. I have configured ntp.conf, resolv.conf, krb5.conf, nsswitch.conf and smb.conf.



      3. After restarting all of the services and while joining the domain using sudo net ads join -U administrator, I am getting the following error:



        Failed to join domain: failed to lookup DC info for domain 'CELESTIAL1' over rpc: NT_STATUS_IO_TIMEOUT




      Testing




      1. I tried to execute kinit username, the ticket got generated successfully and I was able to verify from command 'klist'.


      2. I am able to ping the Ubuntu server's IP and the Windows server's IP as well as the domain from both the sides.


      3. The services winbind, nmbd, and smbd are running as expected.


      4. I rebooted the Ubuntu machine and AD server, but same error is showing while performing the domain join operation.



      Questions




      1. What does the NT_STATUS_IO_TIMEOUT error indicate? Are there any issues on the Windows Server or on Ubuntu machine?


      2. How can I join the Ubuntu machine to Active Directory? Are there any steps that I missed that need to be performed to join the domain successfully?











      share|improve this question















      I am attempting to provide access to Ubuntu shared directories using Active Directory users and group using Samba. I am following this article to install and configure AD and Unix so that access can be provided:



      Summary




      1. As a part of the installation, I have installed ntp krb5-user samba(v4.1.6) samba-common smbclient winbind


      2. I followed the configuration settings as provided in the above article. I have configured ntp.conf, resolv.conf, krb5.conf, nsswitch.conf and smb.conf.



      3. After restarting all of the services and while joining the domain using sudo net ads join -U administrator, I am getting the following error:



        Failed to join domain: failed to lookup DC info for domain 'CELESTIAL1' over rpc: NT_STATUS_IO_TIMEOUT




      Testing




      1. I tried to execute kinit username, the ticket got generated successfully and I was able to verify from command 'klist'.


      2. I am able to ping the Ubuntu server's IP and the Windows server's IP as well as the domain from both the sides.


      3. The services winbind, nmbd, and smbd are running as expected.


      4. I rebooted the Ubuntu machine and AD server, but same error is showing while performing the domain join operation.



      Questions




      1. What does the NT_STATUS_IO_TIMEOUT error indicate? Are there any issues on the Windows Server or on Ubuntu machine?


      2. How can I join the Ubuntu machine to Active Directory? Are there any steps that I missed that need to be performed to join the domain successfully?








      ubuntu samba active-directory ntp kerberos






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited Feb 7 '16 at 21:33









      Karl Richter

      91421639




      91421639










      asked Oct 6 '15 at 13:44









      Amit Baswa

      1114




      1114






















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          The issue was that there was no entry in /etc/resolv.conf for AD DNS and hence the machine was pinging to the actual global registered domain. On each reboot, the resolv.conf entries gets reset hence we have to provide entry once the system is rebooted.






          share|improve this answer























          • Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
            – edhurtig
            Jun 25 '16 at 3:51













          Your Answer








          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "3"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f982951%2fnet-ads-join-u-username-failing-with-an-error-nt-status-io-timeout%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes








          up vote
          0
          down vote













          The issue was that there was no entry in /etc/resolv.conf for AD DNS and hence the machine was pinging to the actual global registered domain. On each reboot, the resolv.conf entries gets reset hence we have to provide entry once the system is rebooted.






          share|improve this answer























          • Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
            – edhurtig
            Jun 25 '16 at 3:51

















          up vote
          0
          down vote













          The issue was that there was no entry in /etc/resolv.conf for AD DNS and hence the machine was pinging to the actual global registered domain. On each reboot, the resolv.conf entries gets reset hence we have to provide entry once the system is rebooted.






          share|improve this answer























          • Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
            – edhurtig
            Jun 25 '16 at 3:51















          up vote
          0
          down vote










          up vote
          0
          down vote









          The issue was that there was no entry in /etc/resolv.conf for AD DNS and hence the machine was pinging to the actual global registered domain. On each reboot, the resolv.conf entries gets reset hence we have to provide entry once the system is rebooted.






          share|improve this answer














          The issue was that there was no entry in /etc/resolv.conf for AD DNS and hence the machine was pinging to the actual global registered domain. On each reboot, the resolv.conf entries gets reset hence we have to provide entry once the system is rebooted.







          share|improve this answer














          share|improve this answer



          share|improve this answer








          edited Feb 7 '16 at 18:54









          Karl Richter

          91421639




          91421639










          answered Oct 9 '15 at 8:26









          Amit Baswa

          1114




          1114












          • Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
            – edhurtig
            Jun 25 '16 at 3:51




















          • Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
            – edhurtig
            Jun 25 '16 at 3:51


















          Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
          – edhurtig
          Jun 25 '16 at 3:51






          Alternatively, you can provide a dns-nameservers in /etc/network/interfaces or use some other persistent way of storing preferred DNS servers
          – edhurtig
          Jun 25 '16 at 3:51




















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Super User!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.





          Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


          Please pay close attention to the following guidance:


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f982951%2fnet-ads-join-u-username-failing-with-an-error-nt-status-io-timeout%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          flock() on closed filehandle LOCK_FILE at /usr/bin/apt-mirror

          Mangá

          Eduardo VII do Reino Unido