Sunny
2007-Sep-13 19:12 UTC
[Samba] NT4 domain authentication password expires, but is set not to
Hi, I have OpenSuse 10.2 authenticating against NT 4 domain. OS: OpenSuse 10.2 i386 samba-3.0.23d-19.7 samba-winbind-3.0.23d-19.7 samba-client-3.0.23d-19.7 kernel: 2.6.18.8-0.5-default #1 SMP Everything was fine, until 2 days ago, when it started showing that my password will expire in 3 days. The problem is, that for sure on the domain controller this account is set with no password expiration. There is no such a warning when I log in to a windows machine connected to that domain controller. In the past I had this happen, and then I let the this time to expire, and it locked me out of the machine - i.e. it reported that the password has expied, and would not let me log in. At the same time, I was able to log in on a windows (2000 and XP) workstation, using the same account. After an advice on IRC, I just went to the DC, and changed the password there (i.e. I put the same password again). And it let me log in again on the opensuse machine. Now it happens again, and I would like find a more permanent solution to this problem, or if it is considered a bug, to help and provide whatever log files are needed. Cheers -- Svetoslav Milenov (Sunny) Even the most advanced equipment in the hands of the ignorant is just a pile of scrap.
Sunny
2007-Sep-14 15:21 UTC
[Samba] Re: NT4 domain authentication password expires, but is set not to
On 9/13/07, Sunny <sloncho@gmail.com> wrote:> I have OpenSuse 10.2 authenticating against NT 4 domain. >Here is my smb.conf file: [global] workgroup = ICEBERG printing = cups printcap name = cups printcap cache time = 750 cups options = raw map to guest = Bad User include = /etc/samba/dhcp.conf logon path = \\%L\profiles\.msprofile logon home = \\%L\%U\.9xprofile logon drive = P: usershare allow guests = No idmap gid = 10000-20000 idmap uid = 10000-20000 security = domain template shell = /bin/bash usershare max shares = 100 domain logons = No domain master = No password server = * winbind enum users = Yes winbind enum groups = Yes [homes] comment = Home Directories valid users = %S, %D%w%S browseable = No read only = No inherit acls = Yes [profiles] comment = Network Profiles Service path = %H read only = No store dos attributes = Yes create mask = 0600 directory mask = 0700 [users] comment = All users path = /home read only = No inherit acls = Yes veto files = /aquota.user/groups/shares/ [groups] comment = All groups path = /home/groups read only = No inherit acls = Yes -- Svetoslav Milenov (Sunny) Even the most advanced equipment in the hands of the ignorant is just a pile of scrap.
Hi, I have a fresh install of Fedora 7 and Samba (Version 3.0.26a-0.fc7). Trying to set up ADS authentication. I try "net ads join -U Administrator" and receive the following error "net: relocation error: net: symbol krb5_get_init_creds_opt_alloc, version krb5_3_MIT not defined in file libkrb5.so.3 with link time reference" Does anyone know how to fix this? -Kevin
On Fri, 2007-09-14 at 11:39 -0400, Kevin R. Gutch wrote:> Hi, > > I have a fresh install of Fedora 7 and Samba (Version 3.0.26a-0.fc7). > Trying to set up ADS authentication. I try "net ads join -U > Administrator" and receive the following error > > "net: relocation error: net: symbol krb5_get_init_creds_opt_alloc, > version krb5_3_MIT not defined in file libkrb5.so.3 with link time > reference" > > Does anyone know how to fix this?Have you updated the MIT libraries as well ? Simo. -- Simo Sorce Samba Team GPL Compliance Officer email: idra@samba.org http://samba.org