Displaying 20 results from an estimated 100 matches similar to: "Kerberos failed password not working"
2019 Dec 16
2
Failed to find [principal](kvno 4) in keytab MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
Hello everyone,
I have a FreeNAS server (9.10 running samba 4.3.11-GIT-UNKNOWN) that's recently
started emitting this error:
gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/nas01 at EXAMPLE.COM(kvno 4) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
I've looked at bug 12262 [1], which is why I've cc'd Stefan Metzmacher.
I don't
2004 Nov 30
0
Numerous errors trying to authenticate samba against w2k3
My goal is to authenticate a Windows 2003 Server user from a FreeBSD
4.10 box via samba. A week ago I had this working. I then needed to
verify the procedure and test on a fresh install. Now it doesn't work,
despite doing the same steps (I think).
I generated a Kerberos ticket on the w2k3 box and transfered it to the
FreeBSD box. I used the ktutil command to incorporate the ticket into
2017 May 25
0
Windows 2012 s4u2self followed by s4u2proxy fails against samba
Hi,
I hit the issue described in this thread
https://groups.google.com/forum/#!topic/linux.samba/VfjW9Af92Wg while
testing out s4u2self and s4u2proxy in a windows service, so I wanted
to share my setup.
So I wrote a small windows service that's running as a local system
account to impersonate an user via s4u2self (using LsaLogonUser in
win32 api than calling ImpersonateLoggedOnUser) and then
2011 Aug 18
1
can i use a variable to describe the dimension name of a data.frame?
for example:
a data.frame
data
V1 V2 V3
1 2 3
4 5 6
If I want to calculate the V2
I can get data$V2
But now I want to calculate the dimension name and then analysis the data.
for example
No=3*x ;x=1,2,3,...n
anadata=data$VNo
How could I do?
--
TANG Jie
[[alternative HTML version deleted]]
2017 Mar 18
0
kerberos issue (SPN not found) with windows Hyper-V ( samba 4.5.3 AD)
After reviewing logs I found that my previous assumption was wrong.
Situation: - i'm trying to start live migration from hyper-v host A
(BMSRV4-HYPERV) to hyper-v host B (BM-SRV-5) from host B (logged in as
user from DOMAIN ADMINS group).
Kerberos constrained delegation is set in accordnance to microsoft
instructions with proper SPN's set (well, proper as in with the
workaround I
2018 Jan 07
1
Dynamic DNS Update Error GSS failure
Hi @ all,
I try to update the DNS records from my DHCP Clients to my AD DC but there
ist an issue with the GSSAPI I don't know how to solve.
For this I followed this guide.
https://wiki.samba.org/index.php/Configure_DHCP_to_update_DNS_records_with_B
IND9
GSSAPI Error:
start_gssrequest
tkey query failed: GSSAPI error: Major = Unspecified GSS failure. Minor
code may provide more
2003 Oct 16
0
Samba 3.0.0 CVS 3.0.1pre2: "libads/kerberos_verify.c", line 77: improper member use: keyblock
This has been submitted to https://bugzilla.samba.org/ as Bug 636
I'm trying to build Samba 3.0.0 CVS 3.0.1pre2 under Solaris 8 with
MIT Kerberos 5 1.3.1
OpenLDAP 2.1.22
using the Sun Workshop 6U2 compiler
Arguments to configure are:
configured by ./configure, generated by GNU Autoconf 2.53,
with options \"'--with-readline' '--with-libiconv=/usr/local'
2018 Jun 30
0
DM 3.6.25 -> 4.x
Am 30.06.2018 um 21:37 schrieb Rowland Penny via samba:
> On Sat, 30 Jun 2018 21:02:57 +0200
> "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote:
>
>>
>> additional:
>>
>> the krb5.conf from the former admin, I assume it could or should be
>> boiled down:
>> # cat /etc/krb5.conf
>
> The standard one for Samba is
2017 Mar 19
1
kerberos issue (SPN not found) with windows Hyper-V ( samba 4.5.3 AD)
Hello,
This won't be a very helpful reply, but I can confirm I've had the exact same issue. I ran into this a few years ago and could not get HyperV migrations to work with a Samba DC. I even went so far as to install a Windows DC just to prove to myself that it is supposed to work, and it does, perfectly (with ADDC it even creates all the SPNs for you auto-magically).
Unfortunately at
2008 Aug 05
2
Leopard Macs using Kerberos: Failed to parse negTokenTarg
I think I've found out why MacOS 10.5.x (Leopard) clients are unable to
connect to Samba shares when authenticating with Kerberos. Basically,
the
Leopard Macs insert a few extra bytes (Padding and reqFlags,
according to
wireshark) into the security blob within the Session Setup AndX Request
packet, bytes whose start tag is 0xa1, in a spot where Samba's parser
expects 0xa2. The critical
2019 Oct 08
4
Failed to find cifs/fs-share@dom.corp (kvno 109) in keytab
hello, today the following problem occurred:
[2019/10/08 09: 57: 23.568282, 1]
../../source3/librpc/crypto/gse.c:660(gse_get_server_auth_token)
gss_accept_sec_context failed with [Miscellaneous failure (see text):
Failed to find cifs/fs-share at dom.corp (kvno 109) in keytab
MEMORY: cifs_srv_keytab (arcfour-hmac-md5)]
in my smb.conf I have the lines:
kerberos method = dedicated keytab
2017 Oct 11
2
Opensolaris-ish joins but does not seem to be valid
----- On Oct 10, 2017, at 12:02 PM, samba samba at lists.samba.org wrote:
> On Tue, 10 Oct 2017 11:28:09 -0500 (CDT)
> Andrew Martin <amartin at xes-inc.com> wrote:
>
>
Rowland-
I've been poking at this more and think the root of the problem is a Kerberos
problem.
After joining this machine to the domain, it goes through a process that it
calls "AD/Kerberos
2011 Feb 09
0
net ads keytab syntax - encryption types
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
I am working with integrating various Linux distros as domain members
with an Active Directory Domain running on Windows Server 2008 R2 native.
The Domain admins have allowed des keys for backwards (nfs)
compatibility, but prefers the default enctypes supported in 2008 r2:
http://support.microsoft.com/kb/977321
* AES256-CTS-HMAC-SHA1-96
2018 Jun 30
2
DM 3.6.25 -> 4.x
That domain member server worked fine for about 2 weeks until today.
Somehow the DNS-record didn't work anymore, I did a rejoin and added
some kerberos-related lines to smb.conf
# 2 lines old
winbind cache time = 10
winbind use default domain = yes
# new lines
dedicated keytab file = /etc/krb5.keytab
kerberos method = secrets and keytab
winbind refresh tickets = Yes
created keytab,
2014 Oct 31
0
Samba4 PDC keytab creation for NFSv4 not working
Hello everybody,
Fist a little about our setup.
We have an Debian (7) Wheezy, now upgraded to Debian (testing) Jessie
with Samba4 as PDC, Kerberos and LDAP - all provided through Samba4, and
bind9 and isc-dhcp server for DDNS and DHCP, our environment is a mix of
Linux (Debian Jessie), Mac (Maverick and Yosemite) and Windows 7 and
8.1 clients.
The Windows clients use Samba and are all part of
2004 Mar 16
3
samba 3, ADS, kerberos, keytab problem - Additional pre-authentication required
Hello List,
I am (unsuccessfully) trying to automatically get a valid kerberos
ticket for my linux box. I have - in a test environment:
- a windows 2000 server with Active directory and DNS properly set up.
- a suse linux 9.0 router with samba3.0.2.rc.1 and heimdal 0.6.-67.
- I am able to join the domain and get a valid ticket through kinit, if
I enter the Administrator's password or the
2016 Dec 19
5
Problem with keytab: "Client not found in Kerberos database"
I am trying to use a keytab for a client machine to authenticate to
Samba's own LDAP server.
The samba servers (replicated) are ubuntu 16.04 with samba 4.5.2
compiled from source.
The client machine is ubuntu 16.04 with stock samba 4.3.11. It has been
joined directly to the Samba domain ("net ads join"). I have also
extracted a keytab ("net ads keytab create -P")
2018 Jun 22
2
Domain trust and browsing users and groups problem
Hi list,
we have a forest trust of two domains. One domain in US (us.root.prv)
running exclusively on Windows 2012 R2 and one in EU
(spreadshirt.private) running exclusively Sernet Samba 4.8.2-11. Both
domains run functional level "2008 R2". The trust validates successful
using "samba-tool domain trust validate" and in "Domains and trusts".
My problem is: I
2016 Mar 31
0
NFSv4 / Krb / wildcard in keytab
On 31/03/16 10:04, Service Informatique IF wrote:
> Hi,
>
> I'm trying to use wildcard in keytab because i don't want join every
> computer, client for service NFS krb5.
>
> I add a spn like this
>
> # samba-tool spn add host/* nfs
>
> (I create user nfs before)
>
> # samba-tool spn list nfs
> nfs
> User CN=nfs,CN=Users,DC=if,DC=ujf-grenoble,DC=fr
2016 Mar 31
0
NFSv4 / Krb / wildcard in keytab
Try it like :
http/%s at DOMAIN.COM
not http/*@DOMAIN.COM
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens Service
> Informatique IF
> Verzonden: donderdag 31 maart 2016 11:04
> Aan: samba at lists.samba.org
> CC: ifinfo at ujf-grenoble.fr
> Onderwerp: [Samba] NFSv4 / Krb / wildcard in keytab
>
> Hi,