[root@fsdm01/etc/pam.d$] net ads join -U Administrator
Enter Administrator's password:
Using short domain name -- HOME
Joined 'FSDM01' to dns domain 'home.test-server.lan'
DNS Update for fsdm01.home.test-server.lan failed: ERROR_DNS_UPDATE_FAILED
DNS update failed: NT_STATUS_UNSUCCESSFUL
Looks like your DC does not manage the DNS role.
Make sure all domain members use the same DNS controlled by you.
Then create the proper A/AAAA/PTR records on the DNS server.
; <<>> DiG 9.16.15-Debian <<>> -x 10.0.0.19
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50729
;; flags: qr aa rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;19.0.0.10.in-addr.arpa. IN PTR
;; ANSWER SECTION:
19.0.0.10.in-addr.arpa. 900 IN PTR home.test-server.lan.
;; AUTHORITY SECTION:
0.0.10.in-addr.arpa. 3600 IN SOA DC01.home.test-server.lan. hostmaster.home.test-server.lan. 3 900 600 86400 3600
;; Query time: 3 msec
;; SERVER: 10.0.0.19#53(10.0.0.19)
;; WHEN: Sun Oct 31 21:18:44 EDT 2021
;; MSG SIZE rcvd: 126
[root@DC01/var/log/samba$] dig home.test-server.lan ANY +noall +answer
home.test-server.lan. 3600 IN SOA DC01.home.test-server.lan. hostmaster.home.test-server.lan. 179 900 600 86400 3600
home.test-server.lan. 900 IN NS dc01.home.test-server.lan.
home.test-server.lan. 900 IN A 10.0.0.19
Full disclosure. I created 2 Debian vms and 1 Fedora vm and all I did was setup Samba. I didn’t do any DNS configuration. I set one Debian as the DC and the other two are members. The Debian member joined with no problem. Fedora, not so much. I got this:
[root@fsdm01~$] net ads join -U Administrator
Enter Administrator's password:
Using short domain name -- HOME
Joined 'FSDM01' to dns domain 'home.test-server.lan'
DNS Update for fsdm01.home.test-server.lan failed: ERROR_DNS_UPDATE_FAILED
DNS update failed: NT_STATUS_UNSUCCESSFUL
The Debian server joined w/o the DNS errors. So I don’t know if it is the Debian DC or the Fedora DM. The above makes me feel the issue is with Fedora since the Debian DM didn’t give this error. However, those previous DNS errors were from the Debian DC.