I am trying to add domain trust account for additional kerberos5 (MIT) domain in Samba AD DC with command:
net rpc trustdom add <domain_name> -UAdministrator%<administrator_password>
What happens is that the account is created into Samba ldap database and I can see it in Windows 11 machine.
the command gives an error message:
Could not set trust account password: NT_STATUS_ACCESS_DENIED
with command pdbedit -Lw <account_name>$ i see:
<account_name>$:3000052:NO PASSWORDXXXXXXXXXXXXXXXXXXXXX:2D2C9A3DC21D9CAFD008D1232D77B9D0:[NDU ]:LCT-6207FF7A:
the [NDU ] should be [I ] according to Samba Wiki documentation.
My version of samba is: Version 4.13.17-Ubuntu
There is nothing on logs I could see of related to this incident. How should I debug this?
-- Sami Hulkko