Ross, Alex
2004-Aug-09 23:43 UTC
[Samba] Samba 3.0.4 ad member, XP Pro Members cant access shares
Hi, My XP client cant access the samba share: any help would be great!!!! My environment: RH ES 3.1 + "up2date" Samba 3.0.4-6.3E Kerberos 1.2.7 I have followed the "samba3 by example book" & the "Samba3 How To Guide" It joined to ad & I can View Kerberos tickets and do the Winbind stuff: -bash-2.05b# wbinfo -t checking the trust secret via RPC calls succeeded -bash-2.05b# klist -e Ticket cache: FILE:/tmp/krb5cc_0 Default principal: srvsandysamba@DMN1DEV..FOO.COM Valid starting Expires Service principal 08/06/04 12:11:43 08/06/04 22:11:43 krbtgt/FOO.COM@DMN1DEV.FOO.COM Etype (skey, tkt): DES cbc mode with CRC-32, DES cbc mode with CRC-32 08/06/04 14:03:57 08/06/04 22:11:43 didsmro501win$@DMN1DEV..FOO.COM Etype (skey, tkt): DES cbc mode with RSA-MD5, DES cbc mode with RSA-MD5 Kerberos 4 ticket cache: /tmp/tkt0 klist: You have no tickets cached -bash-2.05b# klist -k Keytab name: FILE:/etc/krb5.keytab KVNO Principal ---- ------------------------------------------------------------------------ -- 1 host/sandy101.fmr.com@DMN1DEV..FOO.COM -bash-2.05b# . . .>From a different Linux server I can mount a drive but XP pops a promptbox, Filling it in fails.. " smbd/sesssetup.c:reply_spnego_negotiate(447) Got secblob of size 1258 [2004/08/09 13:15:21, 3] libads/kerberos_verify.c:ads_verify_ticket(185) ads_verify_ticket: enc type [3] failed to decrypt with error Decrypt integrity check failed [2004/08/09 13:15:21, 3] libads/kerberos_verify.c:ads_verify_ticket(193) ads_verify_ticket: krb5_rd_req with auth failed (Bad encryption type) [2004/08/09 13:15:21, 1] smbd/sesssetup.c:reply_spnego_kerberos(174) Failed to verify incoming ticket! [2004/08/09 13:15:21, 3] smbd/error.c:error_packet(94) error string = No such file or directory [2004/08/09 13:15:21, 3] smbd/error.c:error_packet(118) error packet at smbd/sesssetup.c(175) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE [2004/08/09 13:15:21, 5] lib/util.c:show_msg(465) [2004/08/09 13:15:21, 5] lib/util.c:show_msg(475) size=35 smb_com=0x73 smb_rcls=109 smb_reh=0 smb_err=49152 smb_flg=136 smb_flg2=51201 smb_tid=0 smb_pid=65279 smb_uid=0 smb_mid=384 smt_wct=0 smb_bcc=0 [2004/08/09 13:15:21, 3] smbd/process.c:timeout_processing(1131) timeout_processing: End of file from client (client has disconnected) Since I am enterprise, so we have to run vender supplied RPM's only.. So If the issues is Kerberos version, I cant go & install Kerberos 1.3.x on my own.. Thanks Alex
Maybe Matching Threads
- bad encryption type when accessing AD member server
- Samba on Linux + Windows Server 2003 R2 / ADS: Clients can connect using IP but no hostname
- Samba PDC - Kerberised CIFS access
- Windows 2000 and krb5 tickets...SOLVED
- Samba 3.0.2a with ADS w2k3 Active Directory, enctypes