Hi, Alexander<br><br>log from /var/log/httpd/error_log<br><br>lpcfg_load: refreshing parameters from /usr/share/ipa/smb.conf.empty<br>Processing section "[global]"<br>INFO: Current debug levels:<br>  all: 100<br>  tdb: 100<br>  printdrivers: 100<br>  lanman: 100<br>  smb: 100<br>  rpc_parse: 100<br>  rpc_srv: 100<br>  rpc_cli: 100<br>  passdb: 100<br>  sam: 100<br>  auth: 100<br>  winbind: 100<br>  vfs: 100<br>  idmap: 100<br>  quota: 100<br>  acls: 100<br>  locking: 100<br>  msdfs: 100<br>  dmapi: 100<br>  registry: 100<br>  scavenger: 100<br>  dns: 100<br>  ldb: 100<br>pm_process() returned Yes<br>Using binding ncacn_np:ipaserver.dev.example.net[,print,smb2]<br>s4_tevent: Added timed event "dcerpc_connect_timeout_handler": 0x7f1c1c0ff6b0<br>s4_tevent: Added timed event "composite_trigger": 0x7f1c1c458350<br>s4_tevent: Added timed event "composite_trigger": 0x7f1c1c45ba70<br>s4_tevent: Running timer event 0x7f1c1c458350 "composite_trigger"<br>s4_tevent: Destroying timer event 0x7f1c1c45ba70 "composite_trigger"<br>Mapped to DCERPC endpoint \pipe\lsarpc<br>added interface eth0 ip=192.168.10.241 bcast=192.168.11.255 netmask=255.255.254.0<br>added interface eth0 ip=192.168.10.241 bcast=192.168.11.255 netmask=255.255.254.0<br>resolve_lmhosts: Attempting lmhosts lookup for name ipaserver.dev.example.net<0x20><br>getlmhostsent: lmhost entry: 127.0.0.1 localhost<br>s4_tevent: Added timed event "composite_trigger": 0x7f1c1c46d740<br>s4_tevent: Ending timer event 0x7f1c1c458350 "composite_trigger"<br>s4_tevent: Running timer event 0x7f1c1c46d740 "composite_trigger"<br>s4_tevent: Ending timer event 0x7f1c1c46d740 "composite_trigger"<br>s4_tevent: Added timed event "connect_multi_timer": 0x7f1c1c242c70<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1c04d750<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1c04d750<br>s4_tevent: Destroying timer event 0x7f1c1c242c70 "connect_multi_timer"<br>Socket options:<br>        SO_KEEPALIVE = 0<br>        SO_REUSEADDR = 0<br>        SO_BROADCAST = 0<br>        TCP_NODELAY = 1<br>        TCP_KEEPCNT = 9<br>        TCP_KEEPIDLE = 7200<br>        TCP_KEEPINTVL = 75<br>        IPTOS_LOWDELAY = 0<br>        IPTOS_THROUGHPUT = 0<br>        SO_REUSEPORT = 0<br>        SO_SNDBUF = 2626560<br>        SO_RCVBUF = 1061296<br>        SO_SNDLOWAT = 1<br>        SO_RCVLOWAT = 1<br>        SO_SNDTIMEO = 0<br>        SO_RCVTIMEO = 0<br>        TCP_QUICKACK = 1<br>        TCP_DEFER_ACCEPT = 0<br>s4_tevent: Added timed event "tevent_req_timedout": 0x7f1c1c2e3430<br>s4_tevent: Schedule immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Run immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Destroying timer event 0x7f1c1c2e3430 "tevent_req_timedout"<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1c04d600<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1c04d600<br>Starting GENSEC mechanism spnego<br>Starting GENSEC submechanism gssapi_krb5<br>Ticket in credentials cache for admin@DEV.EXAMPLE.NET will expire in 84175 secs<br>s4_tevent: Added timed event "tevent_req_timedout": 0x7f1c1c42a450<br>s4_tevent: Schedule immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Run immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Destroying timer event 0x7f1c1c42a450 "tevent_req_timedout"<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1c2ad220<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1c2ad220<br>gensec_gssapi: NO credentials were delegated<br>GSSAPI Connection will be cryptographically sealed<br>s4_tevent: Added timed event "tevent_req_timedout": 0x7f1c1c3e7650<br>signed SMB2 message<br>s4_tevent: Schedule immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Run immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Destroying timer event 0x7f1c1c3e7650 "tevent_req_timedout"<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1c2ad220<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1c2ad220<br>s4_tevent: Added timed event "tevent_req_timedout": 0x7f1c1c4441c0<br>signed SMB2 message<br>s4_tevent: Schedule immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Run immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Destroying timer event 0x7f1c1c4441c0 "tevent_req_timedout"<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1c05db70<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1c05db70<br>s4_tevent: Added timed event "tevent_req_timedout": 0x7f1c1c47fd40<br>signed SMB2 message<br>s4_tevent: Schedule immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Run immediate event "tevent_queue_immediate_trigger": 0x7f1c1c2dd3d0<br>s4_tevent: Destroying timer event 0x7f1c1c47fd40 "tevent_req_timedout"<br>s4_tevent: Schedule immediate event "tevent_req_trigger": 0x7f1c1cb553c0<br>s4_tevent: Run immediate event "tevent_req_trigger": 0x7f1c1cb553c0<br>s4_tevent: Destroying timer event 0x7f1c1c0ff6b0 "dcerpc_connect_timeout_handler"<br>[Sun May 01 13:53:05.420066 2016] [:error] [pid 6995] ipa: INFO: [jsonserver_session] admin@DEV.EXAMPLE.NET: trust_add(u'examplemedia.net', trust_type=u'ad', realm_admin=u'Administrator', realm_passwd=u'********', all=False, raw=False, version=u'2.156'): RemoteRetrieveError<br><br><div><div><br></div><div><br></div><div style="font-size: 12px;font-family: Arial Narrow;padding:2px 0 2px 0;">------------------ Original ------------------</div><div style="font-size: 12px;background:#efefef;padding:8px;"><div><b>From: </b> "Alexander Bokovoy";<abokovoy@redhat.com>;</div><div><b>Date: </b> Sun, May 1, 2016 09:40 PM</div><div><b>To: </b> "Matrix"<matrix.zj@qq.com>; <wbr></div><div><b>Cc: </b> "freeipa-users"<freeipa-users@redhat.com>; <wbr></div><div><b>Subject: </b> Re: [Freeipa-users] AD Trust failed with 'CIFS server configurationdoes not allow access to \\pipe\lsarpc'</div></div><div><br></div>On Sun, 01 May 2016, Matrix wrote:<br>>Hi, list<br>><br>>I am trying to setup an integration env between IPA and AD Window 2012 R2.<br>><br>>Below error occurred while running "# echo 'RedHat1!' | ipa trust-add --type=ad examplemedia.net --admin Administrator --password"<br>><br>># echo 'RedHat1!' | ipa trust-add --type=ad examplemedia.net --admin Administrator --password<br>>ipa: ERROR: CIFS server configuration does not allow access to \\pipe\lsarpc<br>><br>><br>>IPA / Samba Version, I am running with:<br>><br>>ipa-server-4.2.0-15.el7.x86_64<br>>samba-4.2.3-12.el7_2.x86_64<br>><br>># tailf /var/log/httpd/error_log<br>>[Sun May 01 08:27:17.493412 2016] [:error] [pid 32267] ipa: INFO: [jsonserver_session] admin@DEV.EXAMPLE.NET: trust_add(u'examplemedia.net', trust_type=u'ad', realm_admin=u'Administrator', realm_passwd=u'********', all=False, raw=False, version=u'2.156'): RemoteRetrieveError<br>>[Sun May 01 08:35:00.600654 2016] [:error] [pid 32266] ipa: INFO: [jsonserver_session] admin@DEV.EXAMPLE.NET: trust_add(u'examplemedia.net', trust_type=u'ad', realm_admin=u'Administrator', realm_passwd=u'********', all=False, raw=False, version=u'2.156'): RemoteRetrieveError<br>><br>>I have also tried latest ipa-server version shipped by RHEL. the same error occurred.<br>><br>>It ssems that https://bugzilla.redhat.com/show_bug.cgi?id=1249455 did not fixed it.<br>Add 'log level = 100' to /usr/share/ipa/smb.conf.empty and re-try <br>'ipa trust-add'. You'll get more detailed debugging output in error_log.<br>-- <br>/ Alexander Bokovoy</div>