Displaying 19 results from an estimated 19 matches for "dcesrv_drsuapi_dswriteaccountspn".
2012 Dec 17
1
S4 AD Domain Up; but lots of NTLMSSP NTLM2 errors
...6(ntlmssp_check_packet)
NTLMSSP NTLM2 packet check failed due to invalid signature!
[2012/12/17 07:58:31,
0] ../auth/ntlmssp/ntlmssp_sign.c:236(ntlmssp_check_packet)
NTLMSSP NTLM2 packet check failed due to invalid signature!
[2012/12/17 08:10:11,
0] ../source4/rpc_server/drsuapi/writespn.c:237(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on CN=pc02541,OU=Industries
Workstations,DC=micore,DC=us: error in module acl: Constraint violation
(19)
[2012/12/17 08:26:00,
0] ../auth/ntlmssp/ntlmssp_sign.c:236(ntlmssp_check_packet)
NTLMSSP NTLM2 packet check failed due to invalid signature!
[2012/12/17 08:37:30,
0]...
2012 Nov 20
1
problems with windows 2000 terminal server in AD with samba4rc5 (on Ubuntu 12.04.1 64bit) DC
...rk like expecting, except the mentioned windows
2000 terminal server, see excerpt from log.samba file:
...
[2012/11/18 13:09:26, 0] ../source4/smbd/server.c:475(binary_smbd_main)
samba: using 'standard' process model
[2012/11/18 14:56:10, 0]
../source4/rpc_server/drsuapi/writespn.c:237(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on CN=W2000,CN=Computers,DC=xxx,DC=lan: error
in module acl: insufficient access rights (50)
[2012/11/18 14:56:19, 0]
../auth/ntlmssp/ntlmssp_sign.c:236(ntlmssp_check_packet)
NTLMSSP NTLM2 packet check failed due to invalid signature!
[2012/11/18 15:04:41, 0]
../auth/nt...
2014 Apr 18
2
log.samba failure messages
...ource4/dsdb/common/util_samr.c:331(dsdb_add_domain_group)
Failed to create group record
CN=NC_S_ISLCK,CN=Users,DC=my,DC=ad,DC=dom,DC=com: dsdb_access: Access
check failed on CN=Users,DC=my,DC=ad,DC=dom,DC=com
*** 3 ***
[2014/04/18 09:10:21.464080, 0]
../source4/rpc_server/drsuapi/writespn.c:237(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on
CN=HOST01,CN=Computers,DC=my,DC=ad,DC=dom,DC=com: error in module acl:
Constraint violation (19)
What implications do these failures have? I'd appreciate any help on
how to troublehoot this.
Best regards
Andreas
2017 Jul 11
2
Samba ADS-member-server: FQDNs in /etc/hosts
...Other users on other PCs are mapped correctly and
files are created correctly (= get correct owner and group in linux fs).
For the PC with the problematic issue I see on the DC:
Jul 11 17:16:25 pre01svdeb02 samba[4657]: [2017/07/11 17:16:25.913628,
0]
../source4/rpc_server/drsuapi/writespn.c:235(dcesrv_drsuapi_DsWriteAccountSpn)
Jul 11 17:16:25 pre01svdeb02 samba[4657]: Failed to modify SPNs on
CN=PC-2016-03,OU=secret-Computer,DC=secret,DC=at: acl: spn validation
failed for spn[TERMSRV/PC-2016-03.secret.at] uac[0x1000]
account[PC-2016-03$] hostname[PC-2016-03.BUERO] nbname[BUERO]
ntds[(null)] forest[secret.at] domain[se...
2018 May 07
0
spn validation failed for spn MSSQLSvc
...kfurt.de at KerberosRealm
MSSQLSvc/tz115.testzentrum.uni-frankfurt.de:8ED4F51D-31C3-4F
MSSQLSvc/tz115.testzentrum.uni-frankfurt.de:1433
If user foo is a normal member of the domain-users, I get this failures:
[2018/05/03 14:47:28.996941, 0]
../source4/rpc_server/drsuapi/writespn.c:235(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on
CN=tz115,CN=Computers,DC=testzentrum,DC=uni-frankfurt,DC=de: acl: spn
validation failed for
spn[MSSQLSvc/tz115.testzentrum.uni-frankfurt.de:SQLEXPRESS] uac[0x1000]
account[tz115$] hostname[tz115.testzentrum.uni-frankfurt.de]
nbname[TESTZENTRUM] ntds[(null)] forest[...
2016 Mar 24
2
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
...rap_debug)
[...]
ldb: ldb_asprintf/set_errstring: error in module acl: Constraint violation
during LDB_MODIFY (19)
[...]
ldb: ldb_trace_next_request: (tdb)->del_transaction
[2016/03/24 01:01:45.077191, 0, pid=32023, effective(0, 0), real(0, 0)] ../
source4/rpc_server/drsuapi/writespn.c:234(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on CN=PCNAME,CN=Computers,DC=DOMAIN,DC=...: error in
module acl: Constraint violation during LDB_MODIFY (19)
[2016/03/24 01:01:45.079992, 1, pid=32023, effective(0, 0), real(0, 0)] ../
librpc/ndr/ndr.c:439(ndr_print_function_debug)
drsuapi_DsWriteAccountSpn: struct...
2018 Feb 08
2
Bad DSA objectGUID ed8970e5-84cc-43dd-89f1-4af8d6ab675a for sid S-1-5-21-570971082-1333357699-3675202899-1375
...samba[32137]: UpdateRefs failed with WERR_DS_DRA_ACCESS_DENIED/NT code 0xc0002105 for ed8970e5-84cc-43dd-89f1-4af8d6ab675a._msdcs.adagene.cn CN=Configuration,DC=adagene,DC=cn
Feb 08 22:07:00 dc1.adagene.cn samba[32129]: [2018/02/08 22:07:00.803258, 0] ../source4/rpc_server/drsuapi/writespn.c:238(dcesrv_drsuapi_DsWriteAccountSpn)
the sid S-1-5-21-570971082-1333357699-3675202899-1375 should be DC1 and sid S-1-5-21-570971082-1333357699-3675202899-1689 should be DC2.
The Directory Replication failed and when I ping dc1.adagene.cn or dc2.adagene.cn in the DC1 host, the same IP address of the DC1 is retruned....
2019 Jul 22
6
replication stuck?
Am 22.07.19 um 10:39 schrieb Stefan G. Weichinger via samba:
> Am 20.07.19 um 11:54 schrieb Joachim Lindenberg via samba:
>> I figured it out myself. The kerberos configuration on the old dc cobra was bad ? no clue why it worked at all until yesterday.
>>
>> After fixing it, testing with kinit, and restarting the dc processes it resumed replication.
>
> pls show how you
2016 Mar 29
2
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
...t; violation
> > during LDB_MODIFY (19)
> > [...]
> >
> > ldb: ldb_trace_next_request: (tdb)->del_transaction
> >
> > [2016/03/24 01:01:45.077191, 0, pid=32023, effective(0, 0), real(0, 0)]
> > ../
> > source4/rpc_server/drsuapi/writespn.c:234(dcesrv_drsuapi_DsWriteAccountSpn
> > )
> >
> > Failed to modify SPNs on CN=PCNAME,CN=Computers,DC=DOMAIN,DC=...: error
> >
> > in
> > module acl: Constraint violation during LDB_MODIFY (19)
> > [2016/03/24 01:01:45.079992, 1, pid=32023, effective(0, 0), real(0, 0)]
> > ../
>...
2017 Jul 11
0
Samba ADS-member-server: FQDNs in /etc/hosts
...rectly and
> files are created correctly (= get correct owner and group in linux
> fs).
>
> For the PC with the problematic issue I see on the DC:
>
> Jul 11 17:16:25 pre01svdeb02 samba[4657]: [2017/07/11 17:16:25.913628,
> 0]
> ../source4/rpc_server/drsuapi/writespn.c:235(dcesrv_drsuapi_DsWriteAccountSpn)
> Jul 11 17:16:25 pre01svdeb02 samba[4657]: Failed to modify SPNs on
> CN=PC-2016-03,OU=secret-Computer,DC=secret,DC=at: acl: spn validation
> failed for spn[TERMSRV/PC-2016-03.secret.at] uac[0x1000]
> account[PC-2016-03$] hostname[PC-2016-03.BUERO] nbname[BUERO]
> ntds[(null)] fo...
2013 May 02
0
"Failed to modify SPNs on … error in module acl: insufficient access rights" error
My samba4 (latest git, @ 5f826415) logs seem to be littered with this error:
[2013/05/02 13:10:39, 0]
../source4/rpc_server/drsuapi/writespn.c:237(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on
CN=AIO6,CN=Computers,DC=corp,DC=example,DC=com: error in module acl:
insufficient access rights (50)
Any thoughts on debugging this / fixing this issue?
It's only this one machine CN (AIO6). None of the other ~15 identical
machines show up in the logs, only this...
2016 Mar 24
0
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
...tf/set_errstring: error in module acl: Constraint
> violation
> during LDB_MODIFY (19)
> [...]
> ldb: ldb_trace_next_request: (tdb)->del_transaction
> [2016/03/24 01:01:45.077191, 0, pid=32023, effective(0, 0), real(0, 0)]
> ../
> source4/rpc_server/drsuapi/writespn.c:234(dcesrv_drsuapi_DsWriteAccountSpn)
> Failed to modify SPNs on CN=PCNAME,CN=Computers,DC=DOMAIN,DC=...: error
> in
> module acl: Constraint violation during LDB_MODIFY (19)
> [2016/03/24 01:01:45.079992, 1, pid=32023, effective(0, 0), real(0, 0)]
> ../
> librpc/ndr/ndr.c:439(ndr_print_function_debug)
>...
2016 Feb 02
2
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
Hi,
sometimes I see following in the logs:
/source4/rpc_server/drsuapi/writespn.c:234(dcesrv_drsuapi_DsWriteAccountSpn)
Failed to modify SPNs on
CN=PCNAME,CN=Computers,DC=DOMAIN,DC=NAME,DC=NAME,DC=de: error in module acl:
Constraint violation during LDB_MODIFY (19)
In the net i found this "explanation":
"LDAP_CONSTRAINT_VIOLATION
Indicates that the attribute value specified in a modify, add, or...
2018 Feb 08
0
Bad DSA objectGUID ed8970e5-84cc-43dd-89f1-4af8d6ab675a for sid S-1-5-21-570971082-1333357699-3675202899-1375
...[32137]: UpdateRefs failed with WERR_DS_DRA_ACCESS_DENIED/NT code 0xc0002105 for ed8970e5-84cc-43dd-89f1-4af8d6ab675a._msdcs.adagene.cn CN=Configuration,DC=adagene,DC=cn
> Feb 08 22:07:00 dc1.adagene.cn samba[32129]: [2018/02/08 22:07:00.803258, 0] ../source4/rpc_server/drsuapi/writespn.c:238(dcesrv_drsuapi_DsWriteAccountSpn)
>
> the sid S-1-5-21-570971082-1333357699-3675202899-1375 should be DC1 and sid S-1-5-21-570971082-1333357699-3675202899-1689 should be DC2.
> The Directory Replication failed and when I ping dc1.adagene.cn or dc2.adagene.cn in the DC1 host, the same IP address of the DC1...
2018 Feb 09
1
Bad DSA objectGUID ed8970e5-84cc-43dd-89f1-4af8d6ab675a for sid S-1-5-21-570971082-1333357699-3675202899-1375
...[32137]: UpdateRefs failed with WERR_DS_DRA_ACCESS_DENIED/NT code 0xc0002105 for ed8970e5-84cc-43dd-89f1-4af8d6ab675a._msdcs.adagene.cn CN=Configuration,DC=adagene,DC=cn
> Feb 08 22:07:00 dc1.adagene.cn samba[32129]: [2018/02/08 22:07:00.803258, 0] ../source4/rpc_server/drsuapi/writespn.c:238(dcesrv_drsuapi_DsWriteAccountSpn)
>
> the sid S-1-5-21-570971082-1333357699-3675202899-1375 should be DC1 and sid S-1-5-21-570971082-1333357699-3675202899-1689 should be DC2.
> The Directory Replication failed and when I ping dc1.adagene.cn or dc2.adagene.cn in the DC1 host, the same IP address of the DC1...
2017 Jul 11
5
Samba ADS-member-server: FQDNs in /etc/hosts
Am 2017-07-11 um 14:40 schrieb Rowland Penny:
>> Restarted winbind, did "killall -HUP" on smbd and nmbd.
>>
>> still can't login to DM via smbclient and that mentioned user.
>>
>> I assume I need to restart all the smbd daemons ... ?
>
> Well, you wouldn't be able to, would you, what with having this in
> smb.conf:
>
> template
2016 Mar 29
0
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
...9)
> > > [...]
> > >
> > > ldb: ldb_trace_next_request: (tdb)->del_transaction
> > >
> > > [2016/03/24 01:01:45.077191, 0, pid=32023, effective(0, 0), real(0,
> 0)]
> > > ../
> > >
> source4/rpc_server/drsuapi/writespn.c:234(dcesrv_drsuapi_DsWriteAccountSpn
> > > )
> > >
> > > Failed to modify SPNs on CN=PCNAME,CN=Computers,DC=DOMAIN,DC=...:
> error
> > >
> > > in
> > > module acl: Constraint violation during LDB_MODIFY (19)
> > > [2016/03/24 01:01:45.079992, 1, pid=32023, effective(...
2020 Jul 22
1
Failed to modify SPNs
Adam, you already tried my suggestions?
What do you see here:
> Failed to modify SPNs on CN=SEC-CON03,CN=Computers,DC=domain,DC=com:
> acl: spn validation failed for ...
^^^^^^
So read the links below and post your results
The event id you showed, for now can be ignored. Inrelevant (for now).
And mostlikly wil disapear when you added/fixed the "correct" spn's
On
2016 Mar 10
2
Failed to modify SPNs on error in module acl: Constraint violation during LDB_MODIFY (19)
Hi all,
SPN = servicePrincipalName
A simple search returning all servicePrincipalName declared in your AD:
ldbsearch -H $sam serviceprincipalname=* serviceprincipalname
An extract from result concerning a lambda client:
# record 41
dn: CN=win-client345,OU=Machines,DC=ad,DC=domain,DC=tld
servicePrincipalName: HOST/MB38W746-0009
servicePrincipalName: HOST/MB38W746-0009.ad.domain.tld