Displaying 20 results from an estimated 26 matches for "lookup_groupmem".
2007 Jun 26
1
winbind authentication performance: lookup_groupmem in large sites
...tgroups(1017)
[ 0]: getgroups sergeyf
...
internal_get_id_from_sid: ID_GROUPID fetching record S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxx -> GID 10513
... (more than 50 groups)
3) Per group list all members of that group -> BOTTLENECK
[2007/06/25 17:18:02, 10] nsswitch/winbindd_cache.c:lookup_groupmem(1665)
lookup_groupmem: [Cached] - doing backend query for info for domain XXXX
[2007/06/25 17:18:02, 10] nsswitch/winbindd_ads.c:lookup_groupmem(879)
ads: lookup_groupmem POST sid=S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx
...
Step 3 is the one causing the delay because each group has about...
2007 Jul 06
1
winbindd running amok
...d: fetching record GID 22066 ->
S-1-5-21-1895577662-1677200029-1617787245-301210
idmap_sid_to_gid: gid = [22066]
got gid 22066 for group 301210
group SID S-1-5-21-1895577662-1677200029-1617787245-301210
refresh_sequence_number: TUE time ok
refresh_sequence_number: TUE seq number is now 697668363
lookup_groupmem: [Cached] - doing backend query for info for domain TUE
ads: lookup_groupmem TUE
sid=S-1-5-21-1895577662-1677200029-1617787245-301210
Current tickets expire at 1183781357, time is now 1183745371
Searching for attrs[0] = member, attrs[1] = usnChanged
Search for
(objectSid=\01\05\00\00\00\00\00\05\15...
2017 Dec 15
1
Samba 4.6.11 member server group resolution not working
...ers from 4.6.7 to 4.6.11.
Since then, "getent group" has been failing to return groups properly
after winbind's been running for a couple of days. We have a lot of
entries in log.wb-<DOMAIN> like this:
[2017/12/15 11:39:47.959368, 1]
../source3/winbindd/winbindd_ads.c:1236(lookup_groupmem)
lsa_lookupsids call failed with NT_STATUS_RPC_PROTOCOL_ERROR -
retrying...
[2017/12/15 11:39:47.962929, 1]
../source3/rpc_client/cli_pipe.c:568(cli_pipe_validate_current_pdu)
../source3/rpc_client/cli_pipe.c:568: RPC fault code
DCERPC_NCA_S_PROTO_ERROR received from host dc-04.samba.thed...
2007 Jul 10
3
winbind + samba limits with large AD?
Hi,
a few months ago I tried to setup samba + winbind (debian etch,
amd64, samba 3.0.24). I followed the howto and got the authentication
running. But I had not much success with winbind. I disabled the
user/group enumeration, but this didn't change it. A simple 'ls -l' in
a directory with 10-20 files took minutes to return the list and most
of the time winbindd just stopped working
2003 Dec 02
2
Problem with , in Common Name when running samba3 as ADS Member (Problem with Group-Contents)
...switch/winbindd_cache.c:refresh_sequence_number(342)
refresh_sequence_number: TOPALISWORLD time ok
[2003/12/02 12:24:24, 10] nsswitch/winbindd_cache.c:refresh_sequence_number(367)
refresh_sequence_number: TOPALISWORLD seq number is now 4263604
[2003/12/02 12:24:24, 10] nsswitch/winbindd_cache.c:lookup_groupmem(1236)
lookup_groupmem: [Cached] - doing backend query for info for domain TOPALISWORLD
[2003/12/02 12:24:24, 10] nsswitch/winbindd_ads.c:lookup_groupmem(697)
ads: lookup_groupmem TOPALISWORLD sid=S-1-5-21-525015883-470239122-8547516-513
[2003/12/02 12:24:24, 5] libads/ldap_utils.c:ads_do_search...
2016 Feb 10
1
Connect Samba File-Share
...b-COMPANY <==
[2016/02/10 14:39:52.771093, 1] ../source3/rpc_client/cli_pipe.c:482(cli_pipe_validate_current_pdu)
../source3/rpc_client/cli_pipe.c:482: RPC fault code WERR_BADFUNC received from host dc2.company.internal!
[2016/02/10 14:39:52.771261, 1] ../source3/winbindd/winbindd_ads.c:1297(lookup_groupmem)
lsa_lookupsids call failed with NT_STATUS_RPC_CALL_FAILED - retrying...
[2016/02/10 14:39:52.774548, 1] ../source3/rpc_client/cli_pipe.c:482(cli_pipe_validate_current_pdu)
../source3/rpc_client/cli_pipe.c:482: RPC fault code WERR_BADFUNC received from host dc2.company.internal!
Anyone knows...
2005 Apr 14
2
Using idmap_rid backend, cannot browse home directory from XP
...amp;#9565;l)
[2005/04/14 10:15:46, 3]
lib/charcnv.c:convert_string_allocate(567)
convert_string_allocate: Conversion error:
Incomplete multibyte sequence(╝l)
[2005/04/14 10:15:46, 3]
nsswitch/winbindd_ads.c:dn_lookup(339)
ads: dn_lookup
[2005/04/14 10:15:46, 3]
nsswitch/winbindd_ads.c:lookup_groupmem(777)
ads lookup_groupmem for
sid=S-1-5-21-725345543-1677128483-839522115-513
[2005/04/14 10:15:46, 3]
lib/charcnv.c:convert_string_allocate(567)
convert_string_allocate: Conversion error:
Incomplete multibyte sequence(Éá)
[2005/04/14 10:15:46, 3]
lib/charcnv.c:convert_string_allocate(567)
con...
2004 Aug 31
0
Overloaded winbind
...ree(): invalid pointer 0xbfffab28!
kerberos_kinit_password HOST/walifile@PSFINC.COM failed: Cannot allocate memory
[2004/08/30 17:44:01, 1] libads/ldap_utils.c:ads_do_search_retry(77)
ads_search_retry: failed to reconnect (Cannot allocate memory)
[2004/08/30 17:44:01, 1] nsswitch/winbindd_ads.c:lookup_groupmem(702)
ads: lookup_groupmem ads_search: Cannot allocate memory
[2004/08/30 17:44:01, 1] nsswitch/winbindd_group.c:fill_grent_mem(133)
could not lookup membership for group rid S-1-5-21-1482476501-261478967-1177238915-1336 in domain PSFINC (error: NT_STATUS_UNSUCCESSFUL)
[2004/08/30 17:44:01, 1] n...
2009 Apr 01
1
[Announce] Samba 3.3.3 Available for Download
...o Andy Kelk <andy@mopoke.co.uk>
* Add dirsort module.
o Steve Langasek <vorlon@debian.org>
* BUG 6147: Fix detection of the GNU ld version.
o Volker Lendecke <vl@samba.org>
* BUG 6097: Fix smbd segfault.
* BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped
members.
* BUG 6139: Add missing whitespace in mount.cifs error message.
* Fix a malloc/talloc mismatch when cli_initialise() fails.
* Fix a valgrind error.
* Speed up "net conf list".
* Add sorted subkey cache.
* Use StrCaseCmp in the dirsort m...
2009 Apr 01
1
[Announce] Samba 3.3.3 Available for Download
...o Andy Kelk <andy@mopoke.co.uk>
* Add dirsort module.
o Steve Langasek <vorlon@debian.org>
* BUG 6147: Fix detection of the GNU ld version.
o Volker Lendecke <vl@samba.org>
* BUG 6097: Fix smbd segfault.
* BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped
members.
* BUG 6139: Add missing whitespace in mount.cifs error message.
* Fix a malloc/talloc mismatch when cli_initialise() fails.
* Fix a valgrind error.
* Speed up "net conf list".
* Add sorted subkey cache.
* Use StrCaseCmp in the dirsort m...
2004 Aug 04
3
Winbind being flakey
...seem to indicate any
problem. Heres the output of winbindd anyway, with debug level 3 after
a failed login attempt from windows:
[ 2627]: getgrnam QG+TEST
rpc: name_to_sid name=TEST
name_to_sid [rpc] TEST for domain QG
ads: dn_lookup
ads: dn_lookup
ads: dn_lookup
ads: dn_lookup
ads: dn_lookup
ads lookup_groupmem for
sid=S-1-5-21-842925246-1647877149-1417001333-57015
[ 2627]: getgrnam QG+TEST
[ 2627]: getgrnam QG+TEST
[ 2629]: request interface version
[ 2629]: request location of privileged pipe
[ 2629]: domain_info [QG.COM]
[ 2629]: getpwnam qg+jzillera
rpc: name_to_sid name=jzillera
name_to_sid [rpc] jzi...
2009 Nov 22
0
Samba 3.3.9 IDMAP problem
...is restarted.
After restart SIDs are mapped to exacts UIDs and GIDs, so my ACLs are not
messed up. But I think it is difficult to restart Samba server every time
Windows restarts.
When problem (restart) occurs I find following messages in my logs:
[2009/11/22 17:51:02, 1] winbindd/winbindd_ads.c:lookup_groupmem(1137)
lsa_lookupsids call failed with NT_STATUS_PIPE_BROKEN - retrying...
[2009/11/22 17:51:02, 0] lib/util_sock.c:write_data(1139)
write_data: write failure. Error = Broken pipe
[2009/11/22 17:51:02, 0] rpc_client/cli_pipe.c:rpc_api_pipe(930)
rpc_api_pipe: write_data returned Broken pipe...
2013 Jan 14
0
Solaris 11.1 + Samba 3.6.6 + ads + getent group - a bug, perhaps?
...ads/ldap_utils.c:134(ads_do_search_retry_internal)
ads reopen failed after error Timelimit exceeded
[2013/01/14 20:03:36.835209, 1, pid=788] libads/ldap_utils.c:315(ads_ranged_search_internal)
ads_search: Timelimit exceeded
[2013/01/14 20:03:36.835261, 0, pid=788] winbindd/winbindd_ads.c:1084(lookup_groupmem)
ads_ranged_search failed with: Timelimit exceeded
Can't help but think after searching the lists that this might be a bug. Apparently there was a bug in the 3.5.x series (I think?) where, if there were > 1000 groups (or was it users in a group?) there were issues like this.
Can someone...
2008 Nov 27
1
[Announce] Samba 3.3.0rc1 Available for Download
...delay New 100
winbind reconnect delay New 30
Changes since 3.3.0pre2:
- ------------------------
o Michael Adam <obnox@samba.org>
* Fix eventlog crash.
* Make keytab filename argument mandatory to "net rpc vampire keytab".
* Add domain prefix to username in lookup_groupmem().
* Honour "winbind use default domain" in lookup_groupmem().
* Sanely handle NULL domain in add_member().
* Don''t list the domain twice when expanding internal aliases.
* Prevent negative GM/ cache entries due to broken connections.
* Use the reconnect metho...
2008 Nov 27
1
[Announce] Samba 3.3.0rc1 Available for Download
...delay New 100
winbind reconnect delay New 30
Changes since 3.3.0pre2:
- ------------------------
o Michael Adam <obnox@samba.org>
* Fix eventlog crash.
* Make keytab filename argument mandatory to "net rpc vampire keytab".
* Add domain prefix to username in lookup_groupmem().
* Honour "winbind use default domain" in lookup_groupmem().
* Sanely handle NULL domain in add_member().
* Don''t list the domain twice when expanding internal aliases.
* Prevent negative GM/ cache entries due to broken connections.
* Use the reconnect metho...
2011 Dec 21
1
Winbind authentication and wbinfo -i user no longer work after uprading to 3.6.1
...------------------------------
This morning, I recreated the error by restarting Samba/winbind at 07:47.
The only suspicious level 10 log entries found from that timeframe are:
<syslog>
Dec 21 07:47:25 debinsp3200 winbindd[3489]: [2011/12/21 07:47:25.660769, 0] winbindd/winbindd_ads.c:1068(lookup_groupmem)
Dec 21 07:47:25 debinsp3200 winbindd[3489]: ads_ranged_search failed with: Time limit exceeded
<smbd>
[2011/12/21 07:47:10.102879, 1] lib/serverid.c:197(serverid_deregister)
Deleting serverid.tdb record failed: NT_STATUS_NOT_FOUND
[2011/12/21 07:47:10.103603, 1] smbd/server.c:303(rem...
2009 Mar 31
1
[Announce] Samba 3.2.9 Maintenance Release Available
...kkukk <linux@kukkukk.com>
* Don''t try and delete a default ACL from a file.
o Jeff Layton <jlayton@redhat.com>
* Initialize rc to 0 in main.
o Volker Lendecke <vl@sernet.de>
* BUG 6100: Complete fix.
* BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped
members.
* BUG 6097: Fix smbd segfault.
* Fix remotely adding a share via MMC.
* Fix resume handle for _samr_EnumDomainGroups.
* Fix Coverity IDs 742, 744, 745, 879, 880.
* Fix a buffer handling bug when adding lots of registry keys.
* Fix a O(n^2) algori...
2009 Mar 31
1
[Announce] Samba 3.2.9 Maintenance Release Available
...kkukk <linux@kukkukk.com>
* Don''t try and delete a default ACL from a file.
o Jeff Layton <jlayton@redhat.com>
* Initialize rc to 0 in main.
o Volker Lendecke <vl@sernet.de>
* BUG 6100: Complete fix.
* BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped
members.
* BUG 6097: Fix smbd segfault.
* Fix remotely adding a share via MMC.
* Fix resume handle for _samr_EnumDomainGroups.
* Fix Coverity IDs 742, 744, 745, 879, 880.
* Fix a buffer handling bug when adding lots of registry keys.
* Fix a O(n^2) algori...
2012 Jul 30
1
'x' bit always set?
...zuccato:rwx
default:group::--x
default:group:100013:--x
default:mask::rwx
default:other::---
Another strange thing is that, with this last command, it stopped
resolving 100013 to PERSONALE\domain_users ... any possible reason? I
can see
[2012/07/30 09:29:23.572740, 0]
winbindd/winbindd_ads.c:1039(lookup_groupmem)
ads_ranged_search failed with: Invalid DN syntax
in log.wb-PERSONALE .
Before that, it was correctly resolved:
# id diego.zuccato
uid=108036(diego.zuccato) gid=100013(domain_users)
gruppi=100013(domain_users),[...]
but now:
# id diego.zuccato
uid=108036(diego.zuccato) gid=100013 gruppi=100013,[...
2006 May 30
0
Samba 3.0.22 w2k3 ad+sfu working but ls shows only uidNumber and not uid
...3554 1 2 2 3
ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10
ads_sasl_spnego_bind: got server principal name =ewt-master$@META.XXX.XX
ads_krb5_mk_req: krb5_cc_get_principal failed (No such file or directory)
Ticket in ccache[MEMORY:winbind_ccache] expiration Tue, 30 May 2006
19:17:30 CEST
ads lookup_groupmem for sid=S-1-5-21-2857693109-2026923775-3634067142-1366
And a wbinfo -s S-1-5-21-2857693109-2026923775-3634067142-1366 gives:
test:/var/server# wbinfo -s S-1-5-21-2857693109-2026923775-3634067142-1366
METADS\dmg 2
As you can see, the conversion sid to gid works ! I 've also tried
playing wit...