No AD authentication after demoting FreeNAS Domain Controller

swarm32

Cadet
Joined
Jan 2, 2019
Messages
2
I've been running FreeNAS 11.2-U8 system as a domain controller for quite a while and due to some other issues decided to take the plunge to migrate the domain elsewhere this weekend. I followed the directions in the 11.3 release blog to migrate the domain over to a pair of Debian based samba 4 domain controllers instead and things went smoothly, all FSMO roles, users and policies transferred over. My windows 7 RSAT VM does everything just fine when connected to the new DCs as well. However, things went sideways once I demoted the FreeNAS box from being a domain controller, I can no longer see any AD user information from the FreeNAS box and my SMB shares are no longer authenticating.
  • wbinfo -t reports the RPC calls succeeded
  • wbinfo -u comes back empty
  • wbingo -g comes back empty
  • using the host command returns the expected results
  • manually requesting a Kerberos ticket works
Any suggestions as to where I should look next?
 
Top