search for: gse_get_client_auth_token

Displaying 20 results from an estimated 20 matches for "gse_get_client_auth_token".

2016 Jun 16
0
wbinfo -g stops after some hours
...using samba 4.2.10+dfsg-0+deb8u3 and have winbind running and joined to a windows AD. When starting winbind everthing works, wbinfo -u, wbinfo -g returns all stuff correct. But after an hour or so this is being shown in the logs: [2016/06/14 19:15:02.239460, 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) gss_init_sec_context failed with [ Miscellaneous failure (see text): Message stream modified] [2016/06/14 19:15:02.239604, 0] ../source3/libads/sasl.c:764(ads_sasl_spnego_bind) kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: An internal error occurred. [2016/06/14 19:25:01.37073...
2016 Oct 19
3
auth problems with samba 4.4.6 (winbind) *(suppected bug)
...urce3/winbindd/winbindd.c:280(winbindd_sig_term_handler)   Got sig[15] terminate (is_parent=0) [2016/10/18 15:35:41.931491,  0] ../source3/winbindd/winbindd.c:280(winbindd_sig_term_handler)   Got sig[15] terminate (is_parent=0) [2016/10/19 01:39:57.249786,  0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token)   gss_init_sec_context failed with [ The caontext has expired: Success] ( the last line was and restart of winbind.)   after ( 4.4.6 ) log.winbindd-idmap [2016/10/18 15:35:41.931491,  0] ../source3/winbindd/winbindd.c:280(winbindd_sig_term_handler)   Got sig[15] terminate (is_parent=0) [20...
2016 Oct 19
0
auth problems with samba 4.4.6 (winbind) *(suppected bug)
...ndler) > >   Got sig[15] terminate (is_parent=0) > > [2016/10/18 15:35:41.931491,  0] > ../source3/winbindd/winbindd.c:280(winbindd_sig_term_handler) > >   Got sig[15] terminate (is_parent=0) > > [2016/10/19 01:39:57.249786,  0] > ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) > >   gss_init_sec_context failed with [ The caontext has expired: Success] > > ( the last line was and restart of winbind.) > > > > after ( 4.4.6 ) log.winbindd-idmap > > [2016/10/18 15:35:41.931491,  0] > ../source3/winbindd/winbindd.c:280(winbindd_sig_term...
2016 Jul 11
2
Testing a forest trusts in Samba 4.4.5 AD environment
...ts I'm struggling to get working. On member servers (file servers in my case), even with an ID mapping set up in smb.conf, wbinfo -u --domain=<other domain> returns nothing, and I see errors in log.wb-<domain>: [2016/07/11 13:48:25.449458, 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) gss_init_sec_context failed with [ Miscellaneous failure (see text): Key version is not available] [2016/07/11 13:48:25.449700, 0] ../source3/libads/sasl.c:773(ads_sasl_spnego_bind) kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: An internal error occurred. [2016/07/11 13:4...
2016 Jul 11
0
Testing a forest trusts in Samba 4.4.5 AD environment
...get working. On member servers > (file servers in my case), even with an ID mapping set up in smb.conf, > wbinfo -u --domain=<other domain> returns nothing, and I see errors in > log.wb-<domain>: > > [2016/07/11 13:48:25.449458, 0] > ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) > gss_init_sec_context failed with [ Miscellaneous failure (see text): > Key version is not available] > [2016/07/11 13:48:25.449700, 0] > ../source3/libads/sasl.c:773(ads_sasl_spnego_bind) > kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: An > internal error o...
2016 Jul 12
2
Testing a forest trusts in Samba 4.4.5 AD environment
...> > (file servers in my case), even with an ID mapping set up in smb.conf, > > wbinfo -u --domain=<other domain> returns nothing, and I see errors in > > log.wb-<domain>: > > > > [2016/07/11 13:48:25.449458, 0] > > ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) > > gss_init_sec_context failed with [ Miscellaneous failure (see text): > > Key version is not available] > > [2016/07/11 13:48:25.449700, 0] > > ../source3/libads/sasl.c:773(ads_sasl_spnego_bind) > > kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed:...
2017 May 04
0
winbind errors for trusted domain (of a one-way trust)
...samba server that is joined to A.COM on which users of B.COM need access. We have samba and winbind configured and it seems to be working correctly except for the following message that keeps on appearing in the log.wb-B logfile: [2017/05/04 14:42:53.727050, 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) gss_init_sec_context failed with [Unspecified GSS failure. Minor code may provide more information: Server not found in Kerberos database] ( I've increased the log level of winbindd to 8 and it shows the following output (sensored to have the domain names replaced): [2017/05/04 13:09:53.8...
2020 May 17
4
Upgrade from 4.11.6 to 4.12.2 created authentication issues
On 5/17/2020 1:43 PM, Rowland penny via samba wrote: > On 17/05/2020 16:54, James Atwell wrote: >> >> Strange results on a domain member >> >> jatwell at osticket:~$ net ads user info administrator -U administrator >> Enter administrator's password: >> create_local_private_krb5_conf_for_domain: smb_mkstemp failed, for >> file
2016 Oct 03
3
Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED
...libads/sasl.c:733(ads_sasl_spnego_bind) ads_sasl_spnego_bind: got OID=1.2.840.113554.1.2.2 [2016/10/03 17:50:03.350238, 3] ../source3/libads/sasl.c:733(ads_sasl_spnego_bind) ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.10 [2016/10/03 17:50:03.379973, 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) gss_init_sec_context failed with [ The context has expired: Success] [2016/10/03 17:50:03.380079, 1] ../auth/gensec/spnego.c:623(gensec_spnego_create_negTokenInit) SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_INTERNAL_ERROR [2016/10/03 17:50:03.380131, 0] ../source3/libads/sasl...
2016 Oct 15
0
Bug 12369 - Downgrade to 4.4.5?
...seeing numerous errors as described in bug 12369: [2016/10/15 10:20:01.911168, 0] ../source3/libads/sasl.c:785(ads_sasl_spnego_bind) kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: An internal error occurred. [2016/10/15 10:20:01.942716, 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) gss_init_sec_context failed with [ The context has expired: Success] [2016/10/15 10:20:01.942846, 0] ../source3/libads/sasl.c:785(ads_sasl_spnego_bind) kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed: An internal error occurred. [2016/10/15 10:23:49.250197, 0] ../source3/wi...
2016 Oct 04
1
Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED
...ads_sasl_spnego_bind: got OID=1.2.840.113554.1.2.2 [2016/10/03 >> 17:50:03.350238, >> 3] ../source3/libads/sasl.c:733(ads_sasl_spnego_bind) >> ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.10 [2016/10/03 >> 17:50:03.379973, >> 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) >> gss_init_sec_context failed with [ The context has expired: Success] >> [2016/10/03 17:50:03.380079, >> 1] ../auth/gensec/spnego.c:623(gensec_spnego_create_negTokenInit) >> SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: >> NT_STATUS_INTERNAL_ERROR [2016/10/03 17:...
2018 Jun 30
2
DM 3.6.25 -> 4.x
...ind use default domain = yes # new lines dedicated keytab file = /etc/krb5.keytab kerberos method = secrets and keytab winbind refresh tickets = Yes created keytab, restarted etc - smbclient worked, right now I get: # smbclient \\\\u1mycustomer\\IT -U sgw Enter mycustomer\sgw's password: gse_get_client_auth_token: gss_init_sec_context failed with [Unspecified GSS failure. Minor code may provide more information: The ticket isn't for us](2529638947) SPNEGO(gse_krb5) login failed: NT_STATUS_LOGON_FAILURE session setup failed: NT_STATUS_LOGON_FAILURE - [2018/06/30 20:53:32.297500, 1] ../source3/librp...
2016 Oct 03
0
Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED
...sl_spnego_bind) > ads_sasl_spnego_bind: got OID=1.2.840.113554.1.2.2 [2016/10/03 > 17:50:03.350238, > 3] ../source3/libads/sasl.c:733(ads_sasl_spnego_bind) > ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.10 [2016/10/03 > 17:50:03.379973, > 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) > gss_init_sec_context failed with [ The context has expired: Success] > [2016/10/03 17:50:03.380079, > 1] ../auth/gensec/spnego.c:623(gensec_spnego_create_negTokenInit) > SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: > NT_STATUS_INTERNAL_ERROR [2016/10/03 17:50:03.380131, > 0...
2018 Jun 16
2
DM 3.6.25 -> 4.x
Am 2018-06-15 um 17:19 schrieb Rowland Penny via samba: > On Fri, 15 Jun 2018 15:53:09 +0200 > "Stefan G. Weichinger via samba" <samba at lists.samba.org> wrote: > >> Am 2018-06-15 um 15:16 schrieb Stefan G. Weichinger via samba: >>> Am 2018-06-15 um 14:44 schrieb Stefan G. Weichinger via samba: >>> >>>> on my way now ... glibc new,
2016 Oct 05
0
Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED
...13554.1.2.2 [2016/10/03 >>>> 17:50:03.350238, >>>> 3] ../source3/libads/sasl.c:733(ads_sasl_spnego_bind) >>>> ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.10 [2016/10/03 >>>> 17:50:03.379973, >>>> 0] ../source3/librpc/crypto/gse.c:341(gse_get_client_auth_token) >>>> gss_init_sec_context failed with [ The context has expired: Success] >>>> [2016/10/03 17:50:03.380079, >>>> 1] ../auth/gensec/spnego.c:623(gensec_spnego_create_negTokenInit) >>>> SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: >>>>...
2019 Apr 12
1
Joining Ubuntu Server to Domain - "kinit succeeded but ads_sasl_spnego_gensec_bind failed"
...seems to work until "Configuring Samba" and the steps that follow. There are several sets of errors I believe to be most important, first from "net ads join:" <----------------------- root at samba:/etc/samba# net ads join -U administrator Enter administrator's password: gse_get_client_auth_token: gss_init_sec_context failed with [ Miscellaneous failure (see text): Message stream modified](______) kinit succeeded but ads_sasl_spnego_gensec_bind(KRB5) failed for ldap/dc0 with user[administrator] realm[CORP.COMPANY.INTERNAL]: The attempted logon is invalid. This is either due to a bad usernam...
2016 Sep 30
2
Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED
On Fri, 30 Sep 2016 14:31:06 +0200 Oliver Werner <oliver.werner at kontrast.de> wrote: > Hi rowland, > > is pam really need? > > Users should not login via terminal to this system. this is only as > Samba File-Server > Lets put it this way, to connect to the domain member your users must be known to the underlying OS. The domain member I am typing this on, uses a
2017 Mar 07
5
[Announce] Samba 4.6.0 Available for Download
...ego: Add debug message for the failed principal. * BUG 12605: s3:winbindd: Fix endless forest trust scan. * BUG 12612: winbindd: Find the domain based on the sid within wb_lookupusergroups_send(). o Andreas Schneider <asn at samba.org> * BUG 12557: s3:librpc: Handle gss_min in gse_get_client_auth_token() correctly. * BUG 12582: idmap_hash: Add a deprecation message, improve the idmap_hash manpage. * BUG 12592: Fix several issues found by covscan. o Martin Schwenke <martin at meltin.net> * BUG 12592: ctdb-logging: CID 1396883 Dereference null return value (NULL_RETU...
2017 Mar 07
5
[Announce] Samba 4.6.0 Available for Download
...ego: Add debug message for the failed principal. * BUG 12605: s3:winbindd: Fix endless forest trust scan. * BUG 12612: winbindd: Find the domain based on the sid within wb_lookupusergroups_send(). o Andreas Schneider <asn at samba.org> * BUG 12557: s3:librpc: Handle gss_min in gse_get_client_auth_token() correctly. * BUG 12582: idmap_hash: Add a deprecation message, improve the idmap_hash manpage. * BUG 12592: Fix several issues found by covscan. o Martin Schwenke <martin at meltin.net> * BUG 12592: ctdb-logging: CID 1396883 Dereference null return value (NULL_RETU...
2017 Mar 07
0
[Announce] Samba 4.6.0 Available for Download
...failed principal. > * BUG 12605: s3:winbindd: Fix endless forest trust scan. > * BUG 12612: winbindd: Find the domain based on the sid within > wb_lookupusergroups_send(). > > o Andreas Schneider <asn at samba.org> > * BUG 12557: s3:librpc: Handle gss_min in gse_get_client_auth_token() > correctly. > * BUG 12582: idmap_hash: Add a deprecation message, improve the > idmap_hash > manpage. > * BUG 12592: Fix several issues found by covscan. > > o Martin Schwenke <martin at meltin.net> > * BUG 12592: ctdb-logging: CID 1396883 Deref...