Hi all, Hi all, I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous amount of kerberos errors in DC event. Event id- 4768(Audit Failure) A Kerberos authentication ticket (TGT) was requested. Account Information: Account Name: root Supplied Realm Name: TEST.LOCAL User ID: NULL SID Service Information: Service Name: krbtgt/TEST.LOCAL Service ID: NULL SID There is no user as root in my DC and there is no functionality breakup. It is getting correct user name .But, by default first kerberos ticket requested by root. whenever samba is restarted or communicating with my system. Audit failure logs are dumped. I think it might be a regression issue from samba while fixing badlock. could anyone help regarding this issue?
On 06/08/2016 06:38 PM, VigneshDhanraj G wrote:> Hi all, > > Hi all, > > I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous > amount of kerberos errors in DC event. Event id- 4768(Audit Failure) > > A Kerberos authentication ticket (TGT) was requested. > Account Information: > Account Name: root > Supplied Realm Name: TEST.LOCAL > User ID: NULL SID > Service Information: > Service Name: krbtgt/TEST.LOCAL > Service ID: NULL SID > > There is no user as root in my DC and there is no functionality breakup. It > is getting correct user name .But, by default first kerberos ticket > requested by root. whenever samba is restarted or communicating with my > system. Audit failure logs are dumped. > > I think it might be a regression issue from samba while fixing badlock. > > could anyone help regarding this issue? >Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled Heimdal), but have zero time to work on it at the moment. If none gets there first I'll fix it in a couple of weeks (or at least look into it). Haven't seen any functional impact until you mentioned that audit log. Thanks, Uri.
Thanks uri, make that happen. On Wed, Jun 8, 2016 at 11:58 PM, Uri Simchoni <uri at samba.org> wrote:> On 06/08/2016 06:38 PM, VigneshDhanraj G wrote: > > Hi all, > > > > Hi all, > > > > I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous > > amount of kerberos errors in DC event. Event id- 4768(Audit Failure) > > > > A Kerberos authentication ticket (TGT) was requested. > > Account Information: > > Account Name: root > > Supplied Realm Name: TEST.LOCAL > > User ID: NULL SID > > Service Information: > > Service Name: krbtgt/TEST.LOCAL > > Service ID: NULL SID > > > > There is no user as root in my DC and there is no functionality breakup. > It > > is getting correct user name .But, by default first kerberos ticket > > requested by root. whenever samba is restarted or communicating with my > > system. Audit failure logs are dumped. > > > > I think it might be a regression issue from samba while fixing badlock. > > > > could anyone help regarding this issue? > > > > Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled > Heimdal), but have zero time to work on it at the moment. If none gets > there first I'll fix it in a couple of weeks (or at least look into it). > Haven't seen any functional impact until you mentioned that audit log. > > Thanks, > Uri. >