we've got a Samba 3 server up and running with AD integration via winbind. Everything is working nicely but there is this persistent message on my console that pops up at least 1x per hour, sometimes more frequently. Apr 27 23:01:02 ebi-prod01 winbindd[5456]: [2009/04/27 23:01:02, 0] libads/sasl.c:ads_sasl_spnego_bind(330) Apr 27 23:01:02 ebi-prod01 winbindd[5456]: kinit succeeded but ads_sasl_spnego_krb5_bind failed: Strong(er) authentication required winbind is definitely talking to the domain controller and is able to retrieve user/group info so I can't tell what is causing the message or what the impact might be. plus, it's cluttering up my log. the messages are found in /var/log/samba/wb-UC.log where "UC" is the name of our forest. this is Samba/Winbind 3.0.33-3.7-el5 as shipped with RHEL5. has anyone else see this? thanks Adam -- Adam Cohen / IT Manager Energy Biosciences Institute / UC Berkeley 109 Calvin Lab / 510-642-7709
On Tue, Apr 28, 2009 at 07:50:11AM -0700, Adam Cohen wrote:> we've got a Samba 3 server up and running with AD integration via > winbind. Everything is working nicely but there is this persistent > message on my console that pops up at least 1x per hour, sometimes more > frequently. > > Apr 27 23:01:02 ebi-prod01 winbindd[5456]: [2009/04/27 23:01:02, 0] > libads/sasl.c:ads_sasl_spnego_bind(330) > Apr 27 23:01:02 ebi-prod01 winbindd[5456]: kinit succeeded but > ads_sasl_spnego_krb5_bind failed: Strong(er) authentication requiredYou need to upgrade to 3.2 which has LDAP signing in winbind. Volker -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.samba.org/archive/samba/attachments/20090429/27bffdd6/attachment.bin
Maybe Matching Threads
- ads_sasl_spnego_krb5_bind failed: Ticket not yet valid
- winbind - wbinfo problem - SOLVED
- Compiling SAMBA on Solaris 10 to use AD on Windows 2008 server
- kinit succeeded but ads_sasl_spnego_krb5_bind failed: The context has expired : Success
- Server not found in kerberos database (with net ads join)