On Thu, 17 Jul 2025 10:55:55 +0200
"Pluess, Tobias via samba" <samba at lists.samba.org> wrote:
> Good day,
> since today, I have the following problem with SAMBA and WINBIND.
> It looks like users can no longer authenticate against Active
> Directory. I constantly get
>
> session setup failed: NT_STATUS_LOGON_FAILURE
>
> but I have also winbind working correctly:
>
> # wbinfo -t
> checking the trust secret for domain CAMPUS via RPC calls succeeded
>
> and users, and groups can also be listed:
>
> wbinfo -u, as well as wbinfo -g, both return very long lists of users
> and groups. So somehow, it looks like it works. But still, the access
> through winbind seems to fail. I have heard rumors that a recent
> update on Windows or on SAMBA (I don't know which one) caused the
> problem, I wonder how I can fix it now?
It is not a rumour, it is a fact that if you are using Samba with the
'ad' idmap config backend against Windows, it may not work if the
Windows server(s) got updated a week ago last Tuesday.
The fix ? Update Samba to a patched version (no idea which version,
because you haven't told us anything).
Rowland