Hi, I need some help with a problem. I have a linux server running Samba and Winbind (4.10.16-18). It is joined to an AD which in turn has a one way trust with a couple other ADs which contains the users. Users can login absolutely fine and there is no issue with any users. The problem I'm seeing is that when I packet capture, I see lots of logon failures to trusted ADs. Interestingly, the user it shows as failed is not the actual user but the hostname of the samba server. I have attached a screenshot of wireshark. These failed requests continue all throughout the day. Any ideas as to what could be causing this and how I could stop this? ?wbinfo --all-domains BUILTIN XXXXX-I-01479829 XXXX-LOC YYYYY YYYY-MMMM The second item above is the hostname. It tries to authenticate with the hostname repeatedly as seen in the screenshot. Thanks. Screenshot: https://ibb.co/rwGPHGm
I would start upgrading to at least 4.15.latest and check again.> -----Oorspronkelijk bericht----- > Van: samba <samba-bounces at lists.samba.org> Namens Prash via samba > Verzonden: donderdag 26 mei 2022 12:38 > Aan: samba at lists.samba.org > Onderwerp: [Samba] Failed NTLM Request > > Hi, > > > I need some help with a problem. I have a linux server running Samba and > Winbind (4.10.16-18). It is joined to an AD which in turn has a one way trust > with a couple other ADs which contains the users. Users can login absolutely > fine and there is no issue with any users. The problem I'm seeing is that > when I packet capture, I see lots of logon failures to trusted ADs. > Interestingly, the user it shows as failed is not the actual user but the > hostname of the samba server. I have attached a screenshot of wireshark. > These failed requests continue all throughout the day. > > > Any ideas as to what could be causing this and how I could stop this? > > > > wbinfo --all-domains > > BUILTIN > > XXXXX-I-01479829 > XXXX-LOC > YYYYY > YYYY-MMMM > > > The second item above is the hostname. It tries to authenticate with the > hostname repeatedly as seen in the screenshot. > > > > > Thanks. > > > > > Screenshot: > > https://ibb.co/rwGPHGm > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba
Apologies for the late reply.? This is the latest I have in Amazon's repository. On Thursday, 26 May 2022, 22:05:10 BST, L. van Belle via samba <samba at lists.samba.org> wrote: I would start upgrading to at least 4.15.latest and check again.> -----Oorspronkelijk bericht----- > Van: samba <samba-bounces at lists.samba.org> Namens Prash via samba > Verzonden: donderdag 26 mei 2022 12:38 > Aan: samba at lists.samba.org > Onderwerp: [Samba] Failed NTLM Request > > Hi, > > > I need some help with a problem. I have a linux server running Samba and > Winbind (4.10.16-18). It is joined to an AD which in turn has a one way trust > with a couple other ADs which contains the users. Users can login absolutely > fine and there is no issue with any users. The problem I'm seeing is that > when I packet capture, I see lots of logon failures to trusted ADs. > Interestingly, the user it shows as failed is not the actual user but the > hostname of the samba server. I have attached a screenshot of wireshark. > These failed requests continue all throughout the day. > > > Any ideas as to what could be causing this and how I could stop this? > > > >? wbinfo --all-domains > > BUILTIN > > XXXXX-I-01479829 > XXXX-LOC > YYYYY > YYYY-MMMM > > > The second item above is the hostname. It tries to authenticate with the > hostname repeatedly as seen in the screenshot. > > > > > Thanks. > > > > > Screenshot: > > https://ibb.co/rwGPHGm > > -- > To unsubscribe from this list go to the following URL and read the > instructions:? https://lists.samba.org/mailman/options/samba-- To unsubscribe from this list go to the following URL and read the instructions:? https://lists.samba.org/mailman/options/samba