I have set "auth_audit" log level = 1 auth_audit:3@/var/log/samba/print.log And I have tons of these: [2021/10/25 10:38:44.484840, 3] ../../auth/auth_log.c:653(log_authentication_event_human_readable) Auth: [DCE/RPC,(null)] user [DOMAIN-02]\[user] at [Mon, 25 Oct 2021 10:38:44.484815 CEST] with [NTLMv2] status [NT_STATUS_OK] workstation [BR-HOST] remote host [ipv4:X.X.X.X:59409] became [DOMAIN-02]\[user] [S-1-5-21-xxx-xxx-xxx-xxx]. local host [ipv4:X.X.X.X:445] Thanks for testing. Am 25.10.21 um 10:18 schrieb L.P.H. van Belle via samba:> I've set in smb.conf > > log level = 1 full_audit:3@/var/log/samba_audit.log > > Printed.. ( point and print setup with cups ) > What do you want to see? Because, ive printed multiple prints now, > as did some collega's. > > 0 messages in my logs. > Well, 1 message then, that i've successfully printed with cups (in cups log). > > Greetz, > > Louis > > > > >> -----Oorspronkelijk bericht----- >> Van: samba [mailto:samba-bounces at lists.samba.org] Namens >> cn--- via samba >> Verzonden: maandag 25 oktober 2021 9:28 >> Aan: samba at lists.samba.org >> Onderwerp: Re: [Samba] Printserver after latest MS updates >> >> Hi Louis, >> could you test at "auth_audit:3"? I would be really >> interested to know >> if something is wrong at my side. >> >> Regards >> >> Christian >> >> Am 20.10.21 um 16:59 schrieb L.P.H. van Belle via samba: >>> Log level 1 >>> Ah,, so that explains a lot. >>> >>> Ps. Full config is posted : 19-10-2021 16:28 >>> I just closing everything on the pc. >>> >>> Time to go home. >>> Untill tomorrow, >>> >>> Greetz, >>> >>> Louis >>> >>> >>>> -----Oorspronkelijk bericht----- >>>> Van: samba [mailto:samba-bounces at lists.samba.org] Namens >>>> cn--- via samba >>>> Verzonden: woensdag 20 oktober 2021 16:40 >>>> Aan: samba at lists.samba.org >>>> Onderwerp: Re: [Samba] Printserver after latest MS updates >>>> >>>> Am 20.10.21 um 16:11 schrieb L.P.H. van Belle via samba: >>>>> Hmm, so your DNS is same as mine. >>>> That is what I work really hard to achieve... :-) >>>> >>>>> >>>>> You see these messages in the logs and i dont. >>>> >>>> What is your loglevel? They start to appear at "auth_audit:3" >>>> below they >>>> are not there as they are successful auths. >>>> >>>> >>>> Regards >>>> >>>> -- >>>> Dr. Christian Naumer >>>> Vice President >>>> Unit Head Bioprocess Development >>>> >>>> BRAIN Biotech AG >>>> Darmstaedter Str. 34-36, D-64673 Zwingenberg >>>> e-mail cn at brain-biotech.com, homepage www.brain-biotech.com >>>> phone +49-6251-9331-30 / fax +49-6251-9331-11 >>>> >>>> Sitz der Gesellschaft: Zwingenberg/Bergstrasse >>>> Registergericht AG Darmstadt, HRB 24758 >>>> Vorstand: Adriaan Moelker (Vorstandsvorsitzender), >>>> Lukas Linnig >>>> Aufsichtsratsvorsitzender: Dr. Georg Kellinghusen >>>> >>>> -- >>>> To unsubscribe from this list go to the following URL and read the >>>> instructions: https://lists.samba.org/mailman/options/samba >>>> >>>> >>> >>> >> >> -- >> Dr. Christian Naumer >> Vice President >> Unit Head Bioprocess Development >> >> BRAIN Biotech AG >> Darmstaedter Str. 34-36, D-64673 Zwingenberg >> e-mail cn at brain-biotech.com, homepage www.brain-biotech.com >> phone +49-6251-9331-30 / fax +49-6251-9331-11 >> >> Sitz der Gesellschaft: Zwingenberg/Bergstrasse >> Registergericht AG Darmstadt, HRB 24758 >> Vorstand: Adriaan Moelker (Vorstandsvorsitzender), >> Lukas Linnig >> Aufsichtsratsvorsitzender: Dr. Georg Kellinghusen >> >> -- >> To unsubscribe from this list go to the following URL and read the >> instructions: https://lists.samba.org/mailman/options/samba >> >> > >-- Dr. Christian Naumer Vice President Unit Head Bioprocess Development BRAIN Biotech AG Darmstaedter Str. 34-36, D-64673 Zwingenberg e-mail cn at brain-biotech.com, homepage www.brain-biotech.com phone +49-6251-9331-30 / fax +49-6251-9331-11 Sitz der Gesellschaft: Zwingenberg/Bergstrasse Registergericht AG Darmstadt, HRB 24758 Vorstand: Adriaan Moelker (Vorstandsvorsitzender), Lukas Linnig Aufsichtsratsvorsitzender: Dr. Georg Kellinghusen
Am 25.10.21 um 10:40 schrieb cn--- via samba:> I have set "auth_audit" > > log level = 1 auth_audit:3@/var/log/samba/print.log > > And I have tons of these: > > > [2021/10/25 10:38:44.484840,? 3] ../../auth/auth_log.c:653(log_authentication_event_human_readable) > ? Auth: [DCE/RPC,(null)] user [DOMAIN-02]\[user] at [Mon, 25 Oct 2021 10:38:44.484815 CEST] with [NTLMv2] status [NT_STATUS_OK] workstation [BR-HOST] remote host [ipv4:X.X.X.X:59409] became [DOMAIN-02]\[user] [S-1-5-21-xxx-xxx-xxx-xxx]. local host [ipv4:X.X.X.X:445] > > Thanks for testing. > > > Am 25.10.21 um 10:18 schrieb L.P.H. van Belle via samba: >> I've set in smb.conf >> >> ? log level = 1 full_audit:3@/var/log/samba_audit.log >> >> Printed.. ( point and print setup with cups ) >> What do you want to see? Because, ive printed multiple prints now, >> as did some collega's. >> >> 0 messages in my logs. >> Well, 1 message then, that i've successfully printed with cups (in cups log). >> >> Greetz, >> >> LouisHello Christian and Louis, I assume both of you use domain accounts for testing. Does printing and connecting new printers also work with local non domain accounts? Here this (local account printing) works with Windows 11 but not with Windows 10 LTSC ( I assume windows server 2019 will be affected as well). I did not release the Oktober Update on our WSUS servers here, but last Friday an work colleague called because he could no longer print to the office from his home office pc (Windows 10 Pro, local account). Afterwards I started testing and posted results here a few days ago for comparison. Thanks in advance, Achim
On Mon, 2021-10-25 at 10:40 +0200, cn--- via samba wrote:> I have set "auth_audit" > > log level = 1 auth_audit:3@/var/log/samba/print.log > > And I have tons of these: > > > [2021/10/25 10:38:44.484840, 3] > ../../auth/auth_log.c:653(log_authentication_event_human_readable) > Auth: [DCE/RPC,(null)] user [DOMAIN-02]\[user] at [Mon, 25 Oct > 2021 > 10:38:44.484815 CEST] with [NTLMv2] status [NT_STATUS_OK] > workstation > [BR-HOST] remote host [ipv4:X.X.X.X:59409] became [DOMAIN-02]\[user] > [S-1-5-21-xxx-xxx-xxx-xxx]. local host [ipv4:X.X.X.X:445] > >Try changing the 3 in 'auth_audit' to 2, what you are receiving in the logs is just Samba telling you that authentication was successful. Rowland
> -----Oorspronkelijk bericht----- > Van: samba [mailto:samba-bounces at lists.samba.org] Namens > Achim Gottinger via samba > Verzonden: maandag 25 oktober 2021 11:02 > Aan: samba at lists.samba.org > Onderwerp: Re: [Samba] Printserver after latest MS updates > > Am 25.10.21 um 10:40 schrieb cn--- via samba: > > I have set "auth_audit" > > > > log level = 1 auth_audit:3@/var/log/samba/print.log > > > > And I have tons of these: > > > > > > [2021/10/25 10:38:44.484840,? 3] > ../../auth/auth_log.c:653(log_authentication_event_human_readable) > > ? Auth: [DCE/RPC,(null)] user [DOMAIN-02]\[user] at [Mon, > 25 Oct 2021 10:38:44.484815 CEST] with [NTLMv2] status > [NT_STATUS_OK] workstation [BR-HOST] remote host > [ipv4:X.X.X.X:59409] became [DOMAIN-02]\[user] > [S-1-5-21-xxx-xxx-xxx-xxx]. local host [ipv4:X.X.X.X:445] > > > > Thanks for testing. > > > > > > Am 25.10.21 um 10:18 schrieb L.P.H. van Belle via samba: > >> I've set in smb.conf > >> > >> ? log level = 1 full_audit:3@/var/log/samba_audit.log > >> > >> Printed.. ( point and print setup with cups ) > >> What do you want to see? Because, ive printed multiple prints now, > >> as did some collega's. > >> > >> 0 messages in my logs. > >> Well, 1 message then, that i've successfully printed with > cups (in cups log). > >> > >> Greetz, > >> > >> Louis > > Hello Christian and Louis, > > I assume both of you use domain accounts for testing.Yes, that is correct.> Does printing and connecting new printers also work with local non > domain accounts?I dont have any "none domain" accounts here.> Here this (local account printing) works > with Windows 11 but not with Windows 10 LTSC ( I assume > windows server 2019 will be affected as well). I did not > release the Oktober Update on our WSUS servers here, but last > Friday an work colleague called because he could no longer > print to the office from his home office pc (Windows 10 Pro, > local account). Afterwards I started testing and posted > results here a few days ago for comparison.I do have 2 windows 11 pc's currenlty these also work as far i know. I'll let that user print some for me. All windows 10 versions i have running are 2004 or up.> > Thanks in advance, > > AchimBased on Rowland message:> Try changing the 3 in 'auth_audit' to 2, what you are receiving in the > logs is just Samba telling you that authentication was successful. > > RowlandAfter a restart, i see, ( and i ignore these ) ==> samba/log.wb-PRINT1 <=[2021/10/25 11:09:14.389132, 0] ../../source3/winbindd/winbindd_cm.c:1894(wb_open_internal_pipe) open_internal_pipe: Could not connect to dssetup pipe: NT_STATUS_RPC_INTERFACE_NOT_FOUND [2021/10/25 11:09:14.389340, 0] ../../librpc/rpc/dcesrv_core.c:3010(dcesrv_call_dispatch_local) dcesrv_call_dispatch_local: DCE/RPC fault in call lsarpc:2E - DCERPC_NCA_S_OP_RNG_ERROR ==> samba/log.smbd <=[2021/10/25 11:09:14.859963, 1] ../../source3/printing/spoolssd.c:658(start_spoolssd) Forking SPOOLSS Daemon [2021/10/25 11:09:14.863446, 1] ../../source3/printing/printer_list.c:234(printer_list_get_last_refresh) Failed to fetch record! ==> samba/log.spoolssd <=[2021/10/25 10:16:47.817622, 1] ../../source3/printing/printer_list.c:234(printer_list_get_last_refresh) Failed to fetch record! ( I did change audit to 2.) And auth_audit:2@/var/log/samba/print.log Still empty here. So far, Greetz, Louis