Cannot join Windows Domain

Hi,

I am struggling to join one of my test computers to my Windows 2022 domain. I already have succeeded to join another one with apparently exact same configuration, but this one makes me mad.

I have tested 25.04 and the join works. I have then tested 25.10 and I receive a error when trying to join regarding a base64 encoded issue (I do not wrote down it) so I decided to go directly to 26 (tried beta 1, 2 and now 3) using a fresh install and configuration upload.

I have “Clear Config” using the UI, deleted both Kerberos Advance Settings, deleted the computer account in the AD. If I try to join, I have such error

CallError

[EFAULT] [EFAULT] Aug 31 16:03:16 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:16 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.
Aug 31 16:03:16 systemd[1]: Starting winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: Started winbind.service - Samba Winbind Daemon.
Aug 31 16:03:26 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:26 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:26 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.

View Details
Error Name: EFAULT
Error Code: 14
Reason:

[EFAULT] [EFAULT] Aug 31 16:03:16 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:16 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.
Aug 31 16:03:16 systemd[1]: Starting winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: Started winbind.service - Samba Winbind Daemon.
Aug 31 16:03:26 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:26 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:26 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.

Error Class: CallError
Trace:
Hide

Traceback (most recent call last):
File “/usr/lib/python3/dist-packages/middlewared/api/base/server/ws_handler/rpc.py”, line 375, in process_method_call
result = await method.call(app, id_, params)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3/dist-packages/middlewared/api/base/server/method.py”, line 76, in call
result = await result.wait(raise_error=True, raise_error_forward_classes=(Exception,))
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3/dist-packages/middlewared/job.py”, line 518, in wait
raise self.exc_info[1]
File “/usr/lib/python3/dist-packages/middlewared/job.py”, line 579, in run
await self.future
File “/usr/lib/python3/dist-packages/middlewared/job.py”, line 625, in _run_body
rv = await self.middleware.run_in_thread(self.method, *args)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3/dist-packages/middlewared/main.py”, line 810, in run_in_thread
return await self.run_in_executor(io_thread_pool_executor, method, *args, **kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3/dist-packages/middlewared/main.py”, line 807, in run_in_executor
return await loop.run_in_executor(pool, functools.partial(method, *args, **kwargs))
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3.13/concurrent/futures/thread.py”, line 59, in run
result = self.fn(*self.args, **self.kwargs)
File “/usr/lib/python3/dist-packages/middlewared/api/base/decorator.py”, line 227, in wrapped
result = func(*args)
File "/usr/lib/python3/dist-packages/middlewared/plugins/directoryservices
/datastore.py", line 669, in update
join_resp = job.wrap_sync(join_job, raise_error_forward_classes=(WBCError, KRB5Error))
File “/usr/lib/python3/dist-packages/middlewared/job.py”, line 830, in wrap_sync
return subjob.wait_sync(raise_error=True, raise_error_forward_classes=raise_error_forward_classes)
~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File “/usr/lib/python3/dist-packages/middlewared/job.py”, line 547, in wait_sync
raise CallError(self.error)
middlewared.service_exception.CallError: [EFAULT] [EFAULT] Aug 31 16:03:16 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:16 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.
Aug 31 16:03:16 systemd[1]: Starting winbind.service - Samba Winbind Daemon…
Aug 31 16:03:16 systemd[1]: Started winbind.service - Samba Winbind Daemon.
Aug 31 16:03:26 systemd[1]: Stopping winbind.service - Samba Winbind Daemon…
Aug 31 16:03:26 systemd[1]: winbind.service: Deactivated successfully.
Aug 31 16:03:26 systemd[1]: Stopped winbind.service - Samba Winbind Daemon.

I have seen that Beta3 should have solved domain join issues, but for this computer, it is not.

Let me know what I should provide to help debugging.

Thanks

that traceback is junk, winbind bouncing is a symptom not the cause. 25.04 working and 25.10/26 dying on the same box is the samba/directoryservices rewrite.

dont upload a 25.04 config onto 26 and then join. clear config is not the same as a clean install. do a real fresh 26, set DNS to the DC only (no isp forwarders), ntp to the dc, then join. hostname has to be unique and under 15 chars.

on the box:

midclt call directoryservices.status
cat /etc/resolv.conf
timedatectl

clock skew of a couple minutes will fail kerberos and all you get is that winbind restart loop. also check /var/log/samba4/log.winbindd around the join, the real error is in there not in the UI blob.

related mess on 25.10: IPA Integration break Samba on 25.10

Here are the results of the commands:

root@nas-sauve[~]# midclt call directoryservices.status

{“type”: null, “status”: null, “status_msg”: null}

root@nas-sauve[~]# cat /etc/resolv.conf

domain local
nameserver 172.20.5.20
nameserver 172.20.5.19

root@nas-sauve[~]# timedatectl
Local time: Tue 2026-09-01 07:49:15 CEST
Universal time: Tue 2026-09-01 05:49:15 UTC
RTC time: Tue 2026-09-01 05:49:15
Time zone: Europe/Paris (CEST, +0200)
System clock synchronized: yes
NTP service: active
RTC in local TZ: no

DNS are OK, time is OK.

I have tried several combinations (fresh install of 25 and 26, upgrade from 25.04). The issue also occurs with an upgrade, I have to rejoin the domain.
I am a bit worried about “dont upload a 25.04 config onto 26”: I have also 25.10 backups (which I use), I can reinject my 25.10 configuration to 26 ? I would really like to keep my configuration (even if I would have spent less time than looking for a resolution, but maybe it could help someone else).

I do not have IPA, only an Active Directory.

I checked the mention /var/log but none of the files were updated today (all dated yesterday). I have only “domain_testjoin_1788247012.799802.log” in which I find Samba configuration and a few errors at the end:

ldb: ltdb: tdb(/var/lib/truenas-samba/private/secrets.ldb): tdb_open_ex: could not open file /var/lib/truenas-samba/private/secrets.ldb: No such file or directory

ldb: Unable to open tdb ‘/var/lib/truenas-samba/private/secrets.ldb’: No such file or directory
ldb: Failed to connect to ‘/var/lib/truenas-samba/private/secrets.ldb’ with backend ‘tdb’: Unable to open tdb ‘/var/lib/truenas-samba/private/secrets.ldb’: No such file or directory
Could not find machine account in secrets database: Failed to fetch machine account password for NTSIEGE_DOM from both secrets.ldb (Could not open secrets.ldb) and from /var/lib/truenas-samba/private/secrets.tdb: NT_STATUS_CANT_ACCESS_DOMAIN_INFO
net_ads_join_ok: Failed to get machine credentials
Join to domain is not valid: {Access Denied} A process has requested access to an object but has not been granted those access rights.
return code = -1
Freeing parametrics:

The last line is the last line of the file.

I do not find a reason for which this file fails, and maybe this is the root cause of the issue? Could it be in the source code that I am running into an exception? In that case, I do not understand why the other computer succeeded to join.

I have made de bunch of tests and each time I fail, whatever I do (even silly IA things)

yeah that secrets.ldb missing line usually shows up when the join never finished writing the machine account, so winbind has nothing to read.

id try leaving the domain (or clear ds config again), then as root:
rm -rf /var/lib/truenas-samba/private
(or at least the half-broken secrets.ldb / secrets.tdb)
then restart middlewared / winbind and join again with a domain admin that can create computer objects.

also make sure the computer name is still under 15 chars and unique on the DC. uploading a 25.10 config onto 26 might be fine for shares/apps, but id still redo directory services from scratch on that box rather than restoring the AD bits. if the other host joined clean, compare midclt call smb.config and DNS order between them.

paste the last 30 lines of /var/log/samba4/log.wb-* (or log.winbindd) from a fresh join attempt if it still fails.

I fully removed the private folder and restarted both moddulewared/winbindd. I also cleaned up the log folder. I was not able to clear as I do not have anything in the Directory Services menu (even in the advanced settings).
I tried again and after the error message, in the log folder I have 3 files:

  • log.wb-NAS-SAUVE: empty file
  • log.winbindd:

[2026/09/05 10:41:20.046568, 0] ../../source3/winbindd/winbindd.c:1456(main)
winbindd version 4.24.3-truenas started.
Copyright Andrew Tridgell and the Samba Team 1992-2026
[2026/09/05 10:42:36.717545, 0, traceid=1] ../../source3/winbindd/winbindd_dual.c:2013(winbindd_sig_term_handler)
Got sig[15] terminate (is_parent=1)

- domain_testjoin_1788597758.4026256.log

INFO: Current debug levels:
all: 5
tdb: 5
printdrivers: 5
lanman: 5
smb: 5
rpc_parse: 5
rpc_srv: 5
rpc_cli: 5
passdb: 5
sam: 5
auth: 5
winbind: 5
vfs: 5
idmap: 5
quota: 5
acls: 5
locking: 5
msdfs: 5
dmapi: 5
registry: 5
scavenger: 5
dns: 5
ldb: 5
tevent: 5
auth_audit: 5
auth_json_audit: 5
kerberos: 5
drs_repl: 5
smb2: 5
smb2_credits: 5
dsdb_audit: 5
dsdb_json_audit: 5
dsdb_password_audit: 5
dsdb_password_json_audit: 5
dsdb_transaction_audit: 5
dsdb_transaction_json_audit: 5
dsdb_group_audit: 5
dsdb_group_json_audit: 5
ldapsrv: 5
lp_load_ex: refreshing parameters
Initialising global parameters
rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
INFO: Current debug levels:
all: 5
tdb: 5
printdrivers: 5
lanman: 5
smb: 5
rpc_parse: 5
rpc_srv: 5
rpc_cli: 5
passdb: 5
sam: 5
auth: 5
winbind: 5
vfs: 5
idmap: 5
quota: 5
acls: 5
locking: 5
msdfs: 5
dmapi: 5
registry: 5
scavenger: 5
dns: 5
ldb: 5
tevent: 5
auth_audit: 5
auth_json_audit: 5
kerberos: 5
drs_repl: 5
smb2: 5
smb2_credits: 5
dsdb_audit: 5
dsdb_json_audit: 5
dsdb_password_audit: 5
dsdb_password_json_audit: 5
dsdb_transaction_audit: 5
dsdb_transaction_json_audit: 5
dsdb_group_audit: 5
dsdb_group_json_audit: 5
ldapsrv: 5
Processing section “[global]”
doing parameter disable spoolss = True
doing parameter dns proxy = False
doing parameter load printers = False
doing parameter max log size = 5120
doing parameter printcap = /dev/null
doing parameter bind interfaces only = True
doing parameter fruit:nfs_aces = False
doing parameter fruit:zero_file_id = False
doing parameter restrict anonymous = 2
doing parameter winbind request timeout = 2
doing parameter passdb backend = tdbsam:/var/run/samba-cache/private/passdb.tdb
doing parameter workgroup = NTSIEGE_DOM
doing parameter netbios name = NAS-SAUVE
doing parameter netbios aliases =
doing parameter guest account = nobody
doing parameter obey pam restrictions = False
doing parameter create mask = 0664
doing parameter directory mask = 0775
doing parameter ntlm auth = False
doing parameter server multichannel support = False
doing parameter unix charset = UTF-8
doing parameter local master = False
doing parameter server string = FreeNAS Server
doing parameter log level = 1
doing parameter logging = file
doing parameter server smb encrypt = default
doing parameter idmap config * : backend = tdb
doing parameter idmap config * : range = 90000001 - 90010001
doing parameter idmap config * : read only = True
doing parameter smb3 directory leases = no
doing parameter state directory = /var/lib/truenas-samba
doing parameter private directory = /var/lib/truenas-samba/private
doing parameter rpc_daemon:mdssd = disabled
doing parameter rpc_server:mdssvc = disabled
doing parameter case sensitive = yes
doing parameter preserve case = yes
doing parameter zfs_core:zfs_integrity_streams = False
doing parameter zfs_core:zfs_block_cloning = False
doing parameter registry shares = True
doing parameter include = registry
doing parameter registry shares = yes
process_registry_service: service name global
pm_process() returned Yes
added interface enp0s25 ip=192.168.200.14 bcast=192.168.203.255 netmask=255.255.252.0
Registering messaging pointer for type 2 - private_data=(nil)
register_msg_pool_usage: Registered MSG_REQ_POOL_USAGE
Registering messaging pointer for type 11 - private_data=(nil)
Registering messaging pointer for type 12 - private_data=(nil)
Registered MSG_REQ_DMALLOC_MARK and LOG_CHANGED
Registering messaging pointer for type 1 - private_data=(nil)
Registering messaging pointer for type 5 - private_data=(nil)
Registering messaging pointer for type 51 - private_data=(nil)
added interface enp0s25 ip=192.168.200.14 bcast=192.168.203.255 netmask=255.255.252.0
ldb: ltdb: tdb(/var/lib/truenas-samba/private/secrets.ldb): tdb_open_ex: could not open file /var/lib/truenas-samba/private/secrets.ldb: No such file or directory

ldb: Unable to open tdb ‘/var/lib/truenas-samba/private/secrets.ldb’: No such file or directory
ldb: Failed to connect to ‘/var/lib/truenas-samba/private/secrets.ldb’ with backend ‘tdb’: Unable to open tdb ‘/var/lib/truenas-samba/private/secrets.ldb’: No such file or directory
Could not find machine account in secrets database: Failed to fetch machine account password for NTSIEGE_DOM from both secrets.ldb (Could not open secrets.ldb) and from /var/lib/truenas-samba/private/secrets.tdb: NT_STATUS_CANT_ACCESS_DOMAIN_INFO
net_ads_join_ok: Failed to get machine credentials
Join to domain is not valid: {Access Denied} A process has requested access to an object but has not been granted those access rights.
return code = -1
Freeing parametrics:

The midclt call smb.config is very similar to the working one, I have not seen what could cause an issue:

midclt call smb.config
{“id”: 1, “netbiosname”: “NAS-SAUVE”, “netbiosalias”: , “workgroup”: “NTSIEGE_DOM”, “description”: “FreeNAS Server”, “minimum_protocol”: “SMB2”, “unixcharset”: “UTF-8”, “localmaster”: false, “syslog”: false, “aapl_extensions”: false, “search_protocols”: , “admin_group”: null, “guest”: “nobody”, “filemask”: “DEFAULT”, “dirmask”: “DEFAULT”, “ntlmv1_auth”: false, “multichannel”: false, “encryption”: “DEFAULT”, “bindip”: , “server_sid”: “S-1-5-21-1273437818-2222193560-2694931889”, “smb_options”: “case sensitive = yes\npreserve case = yes”, “debug”: false, “stateful_failover”: false}

Note: the strange squares in the quote may come from the forum because I do not have them in the result

One last thing: when I import the configuration, I cannot choose what I would like to import

I made a bunch of screenshots (and I was missing some), reset the whole config, manually pushed the config and the join went smoothly. I have absolutely no idea what caused issue in the stored configuration. I think it could be interesting to be able to retrieve only parts of the configuration rather than the whole configuration, it could help in such debug.
The topic can be closed without answer