Displaying 20 results from an estimated 10000 matches similar to: "Samba 3.0.2a with ADS w2k3 Active Directory, enctypes"
2004 Apr 20
1
RES: Samba 3.0.2a with ADS w2k3 Active Directory, enctype s
Hi Jim,
I did what the doc says but the problem is the same.
Does anybody saw this work ? I mean, is the Samba 3.0.2a+Kerberos MIT 1.3.3
able to be accessed by a WXP, W2K or W2K3 machine, using Kerberos tickets
generated in a Windows 2003 KDC (W2K3 AD) ?
Thanks
-----Mensagem original-----
De: Jim McDonough [mailto:jmcd@us.ibm.com]
Enviada em: segunda-feira, 19 de abril de 2004 17:07
Para:
2009 May 04
2
bad encryption type in AD domain authentication
Hello,
I'm trying to access a samba share using an ADS user credentials. I always
get an error, and the debug traces (log level = 5) are giving me the output
in the follow.
I have searched the samba ML archives, and I have found the thread
http://lists.samba.org/archive/samba/2004-April/084545.html
but, before asking the system admin to apply the eventual KB fixes, I would
like to know if the
2006 Sep 21
1
Unable to connect samba server using hostname [2]
Hi,
I've got th same problem than in this tread (no solution found) :
http://lists.samba.org/archive/samba/2005-November/113914.html
except I've got the problem on all stations.
I am unable to connect to samba server using it's hostname, whereas it's
work with IP address. When I use the hostname, Samba always request for
login/password.
[2006/09/21 12:59:04, 3]
2012 May 04
1
s3 connect to s4 ads woes, need guidance..
I'm beating my head up against the wall here.. Need some extra eyes!!!
Setup -- Samba4 Domain Controller and samba3 print server.. DNS
FlatFile,, All dns works..
Issue, When I browse to the print Server vi \\IP-Address I am able to
connect just fine.. When I browse using \\netbios-name I connect to the
server but it opens up a username/pass dialog box and no name or
passwords will work..
2005 Apr 16
1
Problems with ADS membership in win2k domain
I'm having problems with ADS membership for samba. I had a "mostly"
working version with RHES v2.1, krb5 v1.2, samba v3.0.5.
I knew to get to a fully functioning version I would need krb5 v1.3
or later. So finally I had an opertunity to junk RH's crufty krb5
and build from scratch with:
RHES v2.1
MIT krb5 v1.4
samba v3.0.13
This works fine on another server. Now to the
2003 Dec 11
4
Windows 2000 and krb5 tickets.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
OK. I've done some more research, and here's what I get.
smbd --version
Version 3.0.0
strings libkrb5.so.3.2 | grep BRAND
KRB5_BRAND: krb5-1-3-1-final 1.3.1 20030730
Everything seems to work, but trying to access the Samba server results in:
[2003/12/11 14:54:19, 3] libads/kerberos_verify.c:ads_verify_ticket(308)
~ ads_verify_ticket: enc
2004 Aug 10
2
Kerberos verfy ticket failed
Hello list.
I've got a problem using samba-3.0.4 (RedHat AS 3.0)
the server is member of a Win2003 Active directory domain
All stuff about krb5 seems to work correctly
kinit user@REALM
klist
etc...
net ads join -U administrator has worked well too
But when any Windows client member of the domain try to connect to the
server it asks me for a user/pass.
here is the log.
[2004/08/10
2004 May 27
3
Any ideas ?
Hints or check lists for that type or error ?
[2004/05/27 14:11:06.627563, 10, pid=23616]
libads/kerberos_verify.c:ads_verify_ticket(185)
ads_verify_ticket: enc type [1] failed to decrypt with error Bad
encryption type
[2004/05/27 14:11:06.627589, 10, pid=23616]
passdb/secrets.c:secrets_named_mutex_release(716)
secrets_named_mutex: released mutex for replay cache mutex
[2004/05/27
2004 Mar 31
9
failing to browse unix shares with samba 3.0.2a
We upgraded our Solaris 9 samba server to version 3.0.2a and configured
Kerberos MIT 1.3.2.
I was able to run kinit and join samba to our windows 2003 domain as a
domain member, but when I am trying to browse the samba shares from a
windows XP machine it is failing. When I am looking at the samba logs this
is what I am getting:
[2004/03/30 11:15:26, 3]
2004 May 04
3
samba 3.0.2a & Win2003 AD controler
Hello samba experts !
I have a big problem with my samba 3.0.2a on debian. I use winbindd, which
seems to work (getent passwd/group and wbinfo -u works), and the net ads
join worked too, but the authentication with the AD controler, hosted on
Win2003 Server, fails.
Sample of the level 3 log file :
...
[2004/05/04 08:47:20, 3] smbd/process.c:switch_message(685)
switch message SMBsesssetupX
2013 Oct 09
1
URGENT - production server stops working (v3.6)
Hello,
i need some help. A samba3 (3.6.9-151.el6_4.1) ADS member (WIN 2008 AD
Master) Server did his work for years. Since hours some Clients can not
connect to the name (\\fileserver)
connecting to \\192... sometimes work.
Log say:
2013/10/09 09:54:27.735101, 3] smbd/sesssetup.c:660(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1638
[2013/10/09 09:54:27.735423, 3]
2006 Sep 18
1
username map change = samba failure
Since I haven't gotten any responses from the segfault log I posted
earlier, I will try another approach. Below is what happens when a
client tries to connect. Again, this all started after I changed a
username mapping entry from root = DOMAIN\Administrator to root =
@"DOMAIN\Domain Admins". This is in a security = ADS setup. wbinfo -u
and -g return the correct information.
2017 Nov 09
3
Slow Kerberos Authentication
Hai,
You may need to add the the following in krb5.conf
[libdefaults]
allow_weak_crypto = true
; for Windows 2003
; default_tgs_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; default_tkt_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; permitted_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; for Windows 2008 with AES
default_tgs_enctypes = aes128-cts-hmac-sha1-96
2005 Jun 13
4
Kerberos enc type [xx] failed
Hi All,
I am getting Kerberos "enc type" problem that I can't explain:
[2005/06/11 11:41:29, 1, pid=29355]
libads/kerberos_verify.c:ads_keytab_verify_ticket(61)
ads_keytab_verify_ticket: krb5_kt_start_seq_get failed (No such file
or directory)
[2005/06/11 11:41:29, 3, pid=29355]
libads/kerberos_verify.c:ads_secrets_verify_ticket(193)
ads_secrets_verify_ticket: enc type [16]
2006 Mar 22
2
Authentication problems with win2k3 domain controller
Hi
I'm having problems with samba-3.0.21b and Windows Server 2003 domain
controllers.
When I try to access the samba server from a client (\\sambasrv) I
only get a login prompt, no username/password combination works.
Accessing the samba server through its IP-number instead of
using the netbios name works.
This together with the log message "Failed to verify incoming ticket!"
2009 Jan 29
1
Samba 3.2.7 and XP authentication error
List,
Long and confusing message follows...
I'm facing a frustrating problem. XP clients can use resoures on the
samba server by IP-address, but not by name. So, "net view \\servername"
gives "access denied" but "net view \\ipaddress" gives list of shared
resources.
Samba server (3.2.7 sernet rpm) is a member server in W2003 domain.
I emphasise that with
2017 Nov 10
2
Slow Kerberos Authentication
No, no idee, but really, upgrade to samba, best option, in my opinion.
If thats not possible, it happens..
A timeout option can be set in krb5.conf
for example : kdc_timeout = 5000
You have these for krb5.conf to try out also.
the complete list.
des-hmac-sha1
DES with HMAC/sha1 (weak)
aes256-cts-hmac-sha1-96 aes256-cts AES-256
CTS mode with 96-bit SHA-1 HMAC
2003 Aug 22
3
more problems with rc1 + ADS: smbd sigsegv
here's the tail end of the -d 10 log.host. It seems to not like the
encryption type. Which should I be using, and where should I change it?
-dave
[2003/08/22 09:45:29, 3] smbd/process.c:switch_message(685)
switch message SMBsesssetupX (pid 6310)
[2003/08/22 09:45:29, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2003/08/22 09:45:29, 5]
2003 Sep 29
4
bad encryption type when accessing AD member server
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
I'm trying to access a Samba 3.0 server (running on Debian unstable) in an
Active Directory environment. I successfully joined the domain, klist shows
my Kerberos ticket(s) and I can use smbclient -k to access a Windows 2000
server. However, when I try to access a share on the Samba machine from a
Windows 2000 client, I'm being asked
2009 Mar 11
1
Samba PDC - Kerberised CIFS access
Hi All,
I have machine M1 hosting Samba PDC. It stores only user information.
I have machine M2 acting as KDC server.
I have machine M3 hosting CIFS shares and it joins into the domain hosted
by PDC M1.
I have machine M4 used as CIFS client.
On M2, I have added users and cifs/host service principals for M3. Also
added service principal in keytab file.
I have added all the user and service