Ryan.Worthington@westam.com
2005-Jan-13 17:03 UTC
[Samba] Kerberos negotion error? reply_spnego_kerberos(250)
Good morning everyone, I have had Samba 3.0.9 running on Solaris, connected to a Windows AD domain for a couple of weeks now, and i've suddenly started getting the following errors: [2005/01/07 11:31:55, 1] smbd/sesssetup.c:reply_spnego_kerberos(250) Username <domain>\IT075$ is invalid on this system It looks like some sort of issue with Kerberos, but I'm able to connect to shares with no problem. I've gone though the list archives and seen this error in various logs, but no one has addressed it specifically. Any idea what this means? -- Ryan Worthington Systems and Network Analyst "Difficile est satiram non scribere." This message is confidential and may be privileged. It is intended solely for the named addressee. If you are not the intended recipient please inform us. Any unauthorised dissemination, distribution or copying hereof is prohibited. As we cannot guarantee the genuineness or completeness of the information contained in this message, the statements set forth above are not legally binding.
Andrew Bartlett
2005-Jan-14 02:51 UTC
[Samba] Kerberos negotion error? reply_spnego_kerberos(250)
On Thu, 2005-01-13 at 11:04 -0600, Ryan.Worthington@westam.com wrote:> Good morning everyone, > > I have had Samba 3.0.9 running on Solaris, connected to a Windows AD > domain for a couple of weeks now, and i've suddenly started getting the > following errors: > > [2005/01/07 11:31:55, 1] smbd/sesssetup.c:reply_spnego_kerberos(250) > Username <domain>\IT075$ is invalid on this system > > It looks like some sort of issue with Kerberos, but I'm able to connect to > shares with no problem. I've gone though the list archives and seen this > error in various logs, but no one has addressed it specifically. Any idea > what this means?So, are you running winbindd, and is it really Samba 3.0.9? These are requests for machine accounts, as the local system service is performing a network activity. Winbindd has been providing these accounts for a number of versions now. If you don't run winbindd, then it's your responsibility to provide all the equivalent accounts. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Student Network Administrator, Hawker College http://hawkerc.net -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part Url : http://lists.samba.org/archive/samba/attachments/20050114/7c96b738/attachment.bin
Ryan.Worthington@westam.com
2005-Jan-14 15:40 UTC
[Samba] Kerberos negotion error? reply_spnego_kerberos(250)
On Thu, 2005-01-13 at 11:04 -0600, Ryan.Worthington@westam.com wrote:>> Good morning everyone, >> >> I have had Samba 3.0.9 running on Solaris, connected to a Windows AD >> domain for a couple of weeks now, and i've suddenly started getting the>> following errors: >> >> [2005/01/07 11:31:55, 1] smbd/sesssetup.c:reply_spnego_kerberos(250) >> Username <domain>\IT075$ is invalid on this system >>>So, are you running winbindd, and is it really Samba 3.0.9? These are >requests for machine accounts, as the local system service is performing >a network activity. Winbindd has been providing these accounts for a >number of versions now. If you don't run winbindd, then it's your >responsibility to provide all the equivalent accounts. > >Andrew BartlettYes, this is really version 3.0.9 according to wbinfo -V As it turns out, winbindd wasn't running. Doesn't it start automatically? If not, how would I ensure that it does? Also, I've been reading on winbindd, and I'm wondering if its really necessary for what I want to accomplish. All I'm trying to do is allow Windows hosts to access files on a Unix (Solaris) server. I don't want my users logging on to the servers with their Windows credentials. With this in mind, is it necessary to configure nsswitch.conf? When you mention machine accounts, are you saying its necessary to create accounts for each machine in smbpasswd? Please forgive my ignorance, Samba is brand new to me. -- Ryan Worthington Systems and Network Analyst "Difficile est satiram non scribere." This message is confidential and may be privileged. It is intended solely for the named addressee. If you are not the intended recipient please inform us. Any unauthorised dissemination, distribution or copying hereof is prohibited. As we cannot guarantee the genuineness or completeness of the information contained in this message, the statements set forth above are not legally binding.
Reasonably Related Threads
- password synch with Active Directory and v. 2.0.9
- Joining ADS errors when using net ads join command
- reply_spnego_kerberos in log file
- smbd/sesssetup.c:reply_spnego_kerberos(173) Failedtoverify incoming ticket!
- smbd/sesssetup.c:reply_spnego_kerberos(173) Failed toverify incoming ticket!