Displaying 20 results from an estimated 41 matches for "kerberos_decode_pac".
2017 Oct 16
2
Samba 4.6.2 member server errors
...6 10:11:21.392982, 10, pid=1440, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd.c:734(process_request)
process_request: Handling async request 58217:PAM_AUTH_CRAP
[2017/10/16 10:11:21.912764, 5, pid=1440, effective(0, 0), real(0, 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac)
PAC Decode: Failed to verify the service signature: Invalid argument
[2017/10/16 10:11:21.912829, 5, pid=1440, effective(0, 0), real(0, 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac)
PAC Decode: Failed to verify the service signature: Invalid argument
[2017/10/16 10:11:21.9128...
2017 Oct 16
1
Samba 4.6.2 member server errors
...440, effective(0, 0),
> real(0, 0), class=winbind]
> ../source3/winbindd/winbindd.c:734(process_request)
> process_request: Handling async request 58217:PAM_AUTH_CRAP
> [2017/10/16 10:11:21.912764, 5, pid=1440, effective(0, 0),
> real(0, 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac)
> PAC Decode: Failed to verify the service signature:
> Invalid argument
> [2017/10/16 10:11:21.912829, 5, pid=1440, effective(0, 0),
> real(0, 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac)
> PAC Decode: Failed to verify the service signature:
> Invalid a...
2017 Oct 16
0
Samba 4.6.2 member server errors
..., 10, pid=1440, effective(0, 0), real(0, 0),
> class=winbind] ../source3/winbindd/winbindd.c:734(process_request)
> process_request: Handling async request 58217:PAM_AUTH_CRAP
> [2017/10/16 10:11:21.912764, 5, pid=1440, effective(0, 0), real(0,
> 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac) PAC
> Decode: Failed to verify the service signature: Invalid argument
> [2017/10/16 10:11:21.912829, 5, pid=1440, effective(0, 0), real(0,
> 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac) PAC
> Decode: Failed to verify the service signature: Invalid argument
> [2017/...
2017 Oct 15
4
Samba 4.6.2 member server errors
On Sat, 14 Oct 2017, Rowland Penny via samba wrote:
> On Sat, 14 Oct 2017 05:33:31 -0400 (EDT)
> me at tdiehl.org wrote:
>
>> On Fri, 13 Oct 2017, Rowland Penny via samba wrote:
>>
>>> On Fri, 13 Oct 2017 11:45:43 +0200
>>> "L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:
>>>
>>>> Hai,
>>>>
2017 Oct 20
2
Samba 4.6.2 member server errors
...effective(0, 0), real(0, 0),
>> class=winbind] ../source3/winbindd/winbindd.c:734(process_request)
>> process_request: Handling async request 58217:PAM_AUTH_CRAP
>> [2017/10/16 10:11:21.912764, 5, pid=1440, effective(0, 0), real(0,
>> 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac) PAC
>> Decode: Failed to verify the service signature: Invalid argument
>> [2017/10/16 10:11:21.912829, 5, pid=1440, effective(0, 0), real(0,
>> 0)] ../auth/kerberos/kerberos_pac.c:347(kerberos_decode_pac) PAC
>> Decode: Failed to verify the service signature: Invalid argu...
2020 Jan 05
3
delayed write files errors
...om errors.
Any idea ?
----- samba.log -----
020/01/04 23:59:55.691908,? 2]
../source3/smbd/close.c:802(close_normal_file)
? EXAMPLE\myuser closed file
.system/Thunderbird/profile-release/panacea.dat (numopen=13) NT_STATUS_OK
[2020/01/04 23:59:55.697718,? 3]
../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
? Found account name from PAC: MYPC$ []
[2020/01/04 23:59:55.697764,? 3]
../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
? Kerberos ticket principal name is [MYPC$@EXAMPLE.DOMAIN.FR]
[2020/01/04 23:59:55.699792,? 3]
../source3/auth/user_krb5.c:164(get_user_from_kerberos_info)
? ge...
2014 Jul 21
1
Domain member (2k8R2) server, problem mapping Kerberos/NSS users
.../21 13:17:30.645510, 3]
../source3/smbd/negprot.c:671(reply_negprot)
Selected protocol SMB 2.???
[2014/07/21 13:17:30.645912, 3]
../source3/smbd/smb2_negprot.c:243(smbd_smb2_request_process_negprot)
Selected protocol SMB2_10
[2014/07/21 13:17:30.650719, 3]
../auth/kerberos/kerberos_pac.c:386(kerberos_decode_pac)
Found account name from PAC: kxmjd01 [Doe, John]
[2014/07/21 13:17:30.650802, 3]
../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
Kerberos ticket principal name is [kxmjd01 at MY-DOMAIN.TLD]
[2014/07/21 13:17:30.651176, 1]
../source3/auth/user_krb5.c:164(get_user_from_kerberos_inf...
2020 Jan 03
2
delayed write files errors
Hello,
First of all : Happy New Year to you all :-)
I need your help for a problem.
I've 2 servers on CentOS 7: a Samba DC+AD and a Samba Files Sharing.
In the Samba file sharing server, all data is store in a RAID Disk
partition wich is mounted in /data/ (fstab :
UUID=a47ea879-7072-4e8f-a668-3f5a86e58ef2 /data ext4
defaults,user_xattr,acl,barrier=1?? ?1 2).
Under Windows each user has
2019 Jun 24
2
setting up a new ADS infrastructure
...ssh(1) to it
and work at the CLI. But if I want to connect to a share:
| ~# smbclient //herakles/profiles/ -Utest
| Enter SYNTHESIS\test's password:
| session setup failed: NT_STATUS_ACCESS_DENIED
The log file contains:
| [2019/06/24 09:28:03.876063, 3] ../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
| Found account name from PAC: test [Max Mustermann]
| [2019/06/24 09:28:03.876091, 3] ../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
| Kerberos ticket principal name is [test at SYNTHESIS.SYNTH.INTERN]
| [2019/06/24 09:28:03.877874, 3] ../source3/auth/user_krb5.c:164(get_user_f...
2019 Jun 11
1
Samba + sssd deployment: success and failure
...ba# smbd --version
Version 4.7.6-Ubuntu
It appears there were some major changes between Samba 4.7.6 and Samba
4.8.3 ? On the functional CentOS system, when I try to map a share I
see something like this in the log files:
[2019/06/11 13:09:35.088714, 3]
../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
Found account name from PAC: pgoetz [Goetz, Patrick G]
On the Ubuntu system I see
[2019/06/11 13:58:47.535611, 3]
../auth/ntlmssp/ntlmssp_server.c:454(ntlmssp_server_preauth)
Got user=[pgoetz] domain=[austin] workstation=[CNS-VM-PGOETZ1]
len1=24 len2=332
What then happens is it looks...
2015 May 27
2
check password script for samba 4 ad dc
Hi everyone,
A quick question: Is check password script option working for ad dc setup?
I believe, ad on it's own cannot provide password protection against
dictionaries.
2015 May 27
1
check password script for samba 4 ad dc
...> [2015/05/27 10:09:07.633707, 3]
> ../source4/smbd/process_single.c:114(single_terminate)
> single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv()
> - NT_STATUS_CONNECTION_DISCONNECTED]
> [2015/05/27 10:09:07.642900, 3]
> ../auth/kerberos/kerberos_pac.c:386(kerberos_decode_pac)
> Found account name from PAC: Administrator []
> [2015/05/27 10:09:07.660999, 3]
> ../source4/kdc/kpasswdd.c:375(kpasswd_process_request)
> KURSK\Administrator (S-1-5-21-1939327600-330022255-2124521309-500) is
> changing password of xviewsion at kursk.mtt
> [2015/05/27 10:0...
2020 Jan 07
2
delayed write files errors
...4 23:59:55.714015,? 2]
../source3/smbd/close.c:802(close_normal_file)
? EXAMPLE\myuser closed file
.system/Thunderbird/profile-release/favicons.sqlite-shm (numopen=13)
NT_STATUS_OK
On the other hand, is this error? normal ?
[2020/01/04 23:59:55.719198,? 3]
../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
? Found account name from PAC: MYPC$ []
[2020/01/04 23:59:55.719241,? 3]
../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
? Kerberos ticket principal name is [MYPC$@EXAMPLE.DOMAIN.FR]
[2020/01/04 23:59:55.721193,? 3]
../source3/auth/user_krb5.c:164(get_user_from_kerberos_info)
? ge...
2013 Oct 28
1
How winbindd is working on DC/member? It ignores rfc2703 on DC, and not showing all users on member server... Where is a error?
...smbd/sesssetup.c:138(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2013/10/28 15:32:44.525773, 3]
../source3/smbd/sesssetup.c:179(reply_sesssetup_and_X_spnego)
NativeOS=[Unix] NativeLanMan=[Samba] PrimaryDomain=[]
[2013/10/28 15:32:44.538199, 3]
../auth/kerberos/kerberos_pac.c:386(kerberos_decode_pac)
Found account name from PAC: Wakizashi [Alex Wakizashi]
[2013/10/28 15:32:44.538250, 3]
../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
Kerberos ticket principal name is [wakizashi at SAMBA.LOCAL.NET]
[2013/10/28 15:32:44.538419, 3] ../source3/param/loadparm.c:4838(lp_load_ex)...
2013 Feb 25
7
"Samba 4" - "smbd"; "can't parse the PAC: NT_STATUS_BUFFER_TOO_SMALL" error but only for a single domain user ("Server 2008 R2" domain, "Server 2008" functional level forest).
...g is that this only affects a single user - all other
accounts work without problems.
When accessing our main server using that account, "smbd" always reports
"can't parse the PAC: NT_STATUS_BUFFER_TOO_SMALL". This has come from
"../auth/kerberos/kerberos_pac.c:149(kerberos_decode_pac)", trying to use
NDR to pull a blob from the Kerberos ticket (that's reported as
"ndr_pull_error(11): Pull bytes 34 (../librpc/ndr/ndr_string.c:591)").
I can't see any reason for the error affecting this one specific user.
As the Kerberos PAC is mainly concerned with in...
2015 May 27
0
check password script for samba 4 ad dc
...S_CONNECTION_DISCONNECTED'
[2015/05/27 10:09:07.633707, 3]
../source4/smbd/process_single.c:114(single_terminate)
single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv()
- NT_STATUS_CONNECTION_DISCONNECTED]
[2015/05/27 10:09:07.642900, 3]
../auth/kerberos/kerberos_pac.c:386(kerberos_decode_pac)
Found account name from PAC: Administrator []
[2015/05/27 10:09:07.660999, 3]
../source4/kdc/kpasswdd.c:375(kpasswd_process_request)
KURSK\Administrator (S-1-5-21-1939327600-330022255-2124521309-500) is
changing password of xviewsion at kursk.mtt
[2015/05/27 10:09:07.841347, 3]
../source4/sm...
2019 Jun 24
0
setting up a new ADS infrastructure
...ut if I want to connect to a share:
>
> | ~# smbclient //herakles/profiles/ -Utest
> | Enter SYNTHESIS\test's password:
> | session setup failed: NT_STATUS_ACCESS_DENIED
>
> The log file contains:
>
> | [2019/06/24 09:28:03.876063, 3] ../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
> | Found account name from PAC: test [Max Mustermann]
> | [2019/06/24 09:28:03.876091, 3] ../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
> | Kerberos ticket principal name is [test at SYNTHESIS.SYNTH.INTERN]
> | [2019/06/24 09:28:03.877874, 3] ../source3/auth/user_k...
2020 Jan 07
0
delayed write files errors
...mbd/close.c:802(close_normal_file)
> ? EXAMPLE\myuser closed file
> .system/Thunderbird/profile-release/favicons.sqlite-shm (numopen=13)
> NT_STATUS_OK
>
> On the other hand, is this error? normal ?
>
> [2020/01/04 23:59:55.719198,? 3]
> ../auth/kerberos/kerberos_pac.c:413(kerberos_decode_pac)
> ? Found account name from PAC: MYPC$ []
> [2020/01/04 23:59:55.719241,? 3]
> ../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
> ? Kerberos ticket principal name is [MYPC$@EXAMPLE.DOMAIN.FR]
> [2020/01/04 23:59:55.721193,? 3]
> ../source3/auth/user_krb5.c:164(get_...
2013 Aug 25
0
adding samba4 member to samba4 domain
...auth/gensec/gensec_start.c:647(gensec_start_mech)
> Starting GENSEC submechanism gse_krb5
> [2013/08/25 14:24:49.708516, 4] ../source3/smbd/sec_ctx.c:424(pop_sec_ctx)
> pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
> [2013/08/25 14:24:49.709158, 3] ../auth/kerberos/kerberos_pac.c:386(kerberos_decode_pac)
> Found account name from PAC: cht [Christian Huldt]
> [2013/08/25 14:24:49.709254, 3] ../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
> Kerberos ticket principal name is [cht at ARKITEKT.MSG83]
> [2013/08/25 14:24:49.709332, 5] ../source3/lib/username.c:181(Get_Pwnam...
2019 Jan 24
1
GPO / Sysvol problems
....local (flags 1026) [hostname nor servname provided, or not known]
[2019/01/24 10:36:40.217370, 3] ../source3/lib/util_sock.c:1187(get_mydnsfullname)
get_mydnsfullname: getaddrinfo failed for name freenas.ad.abc.local [Success]
[2019/01/24 10:36:40.220635, 3] ../auth/kerberos/kerberos_pac.c:409(kerberos_decode_pac)
Found account name from PAC: DESKTOP-AD-TEST$ []
[2019/01/24 10:36:40.220656, 3] ../source3/auth/user_krb5.c:51(get_user_from_kerberos_info)
Kerberos ticket principal name is [DESKTOP-AD-TEST$@AD.ABC.LOCAL]
[2019/01/24 10:36:40.225072, 3] ../source3/param/loadparm.c:3856(lp_load_ex)
lp_loa...