Rowland Penny
2017-Apr-21 16:50 UTC
[Samba] Fwd: Unable to change passwords from Win XP Pro clients
On Fri, 21 Apr 2017 12:00:59 -0400 Eleuterio Contracampo via samba <samba at lists.samba.org> wrote:> [2017/04/21 12:47:55.219297, 0] > ../auth/gensec/gensec.c:257(gensec_verify_dcerpc_auth_level) > > Did not manage to negotiate mandetory feature SIGN for dcerpc > auth_level 6 >I think you may be running into an artefact of the badlock patches, for which Win7 will have received patches, but there are no patches for XP as it is no longer supported. Try setting 'client ipc signing =' to 'auto' or 'disabled', but note this will affect win7 as well. See here, for more info: https://wiki.samba.org/index.php/Samba_4.3_Features_added/changed#CVE-2016-2115: Rowland
Eleuterio Contracampo
2017-Apr-21 17:50 UTC
[Samba] Fwd: Unable to change passwords from Win XP Pro clients
Thank you once again! I'll research that link, and let everyone interested know about the results. EC On Fri, Apr 21, 2017 at 12:50 PM, Rowland Penny via samba < samba at lists.samba.org> wrote:> On Fri, 21 Apr 2017 12:00:59 -0400 > Eleuterio Contracampo via samba <samba at lists.samba.org> wrote: > > > [2017/04/21 12:47:55.219297, 0] > > ../auth/gensec/gensec.c:257(gensec_verify_dcerpc_auth_level) > > > > Did not manage to negotiate mandetory feature SIGN for dcerpc > > auth_level 6 > > > > I think you may be running into an artefact of the badlock patches, for > which Win7 will have received patches, but there are no patches for XP > as it is no longer supported. > > Try setting 'client ipc signing =' to 'auto' or 'disabled', but note > this will affect win7 as well. > > See here, for more info: > > https://wiki.samba.org/index.php/Samba_4.3_Features_added/ > changed#CVE-2016-2115: > > Rowland > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba >
Eleuterio Contracampo
2017-Apr-25 16:14 UTC
[Samba] Fwd: Unable to change passwords from Win XP Pro clients
Just a follow-up. Still, no resolution. I've tried different combinations with "client ipc signing" without luck. A traffic dump shows the problem as: i) windows XP client sends a DCE/RPC SAMR command GetDomPwInfo ii) samba DC responds with DCE/RPC Fault nca_proto_error I've also tried fiddling with Local Security Policy registry values at the Win XP machine, but got nothing good out of it. Any more ideas to explore? Thanks in advance -EC On Fri, Apr 21, 2017 at 1:50 PM, Eleuterio Contracampo < econtracampo at gmail.com> wrote:> Thank you once again! I'll research that link, and let everyone interested > know about the results. > > EC > > On Fri, Apr 21, 2017 at 12:50 PM, Rowland Penny via samba < > samba at lists.samba.org> wrote: > >> On Fri, 21 Apr 2017 12:00:59 -0400 >> Eleuterio Contracampo via samba <samba at lists.samba.org> wrote: >> >> > [2017/04/21 12:47:55.219297, 0] >> > ../auth/gensec/gensec.c:257(gensec_verify_dcerpc_auth_level) >> > >> > Did not manage to negotiate mandetory feature SIGN for dcerpc >> > auth_level 6 >> > >> >> I think you may be running into an artefact of the badlock patches, for >> which Win7 will have received patches, but there are no patches for XP >> as it is no longer supported. >> >> Try setting 'client ipc signing =' to 'auto' or 'disabled', but note >> this will affect win7 as well. >> >> See here, for more info: >> >> https://wiki.samba.org/index.php/Samba_4.3_Features_added/ch >> anged#CVE-2016-2115: >> >> Rowland >> >> -- >> To unsubscribe from this list go to the following URL and read the >> instructions: https://lists.samba.org/mailman/options/samba >> > >
Possibly Parallel Threads
- Fwd: Unable to change passwords from Win XP Pro clients
- Fwd: Unable to change passwords from Win XP Pro clients
- Fwd: Unable to change passwords from Win XP Pro clients
- Fwd: Unable to change passwords from Win XP Pro clients
- Fwd: Unable to change passwords from Win XP Pro clients