search for: lookup_groupmem

Displaying 20 results from an estimated 26 matches for "lookup_groupmem".

2007 Jun 26
1
winbind authentication performance: lookup_groupmem in large sites
...tgroups(1017) [ 0]: getgroups sergeyf ... internal_get_id_from_sid: ID_GROUPID fetching record S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxx -> GID 10513 ... (more than 50 groups) 3) Per group list all members of that group -> BOTTLENECK [2007/06/25 17:18:02, 10] nsswitch/winbindd_cache.c:lookup_groupmem(1665) lookup_groupmem: [Cached] - doing backend query for info for domain XXXX [2007/06/25 17:18:02, 10] nsswitch/winbindd_ads.c:lookup_groupmem(879) ads: lookup_groupmem POST sid=S-1-5-21-xxxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx ... Step 3 is the one causing the delay because each group has about...
2007 Jul 06
1
winbindd running amok
...d: fetching record GID 22066 -> S-1-5-21-1895577662-1677200029-1617787245-301210 idmap_sid_to_gid: gid = [22066] got gid 22066 for group 301210 group SID S-1-5-21-1895577662-1677200029-1617787245-301210 refresh_sequence_number: TUE time ok refresh_sequence_number: TUE seq number is now 697668363 lookup_groupmem: [Cached] - doing backend query for info for domain TUE ads: lookup_groupmem TUE sid=S-1-5-21-1895577662-1677200029-1617787245-301210 Current tickets expire at 1183781357, time is now 1183745371 Searching for attrs[0] = member, attrs[1] = usnChanged Search for (objectSid=\01\05\00\00\00\00\00\05\15...
2017 Dec 15
1
Samba 4.6.11 member server group resolution not working
...ers from 4.6.7 to 4.6.11. Since then, "getent group" has been failing to return groups properly after winbind's been running for a couple of days. We have a lot of entries in log.wb-<DOMAIN> like this: [2017/12/15 11:39:47.959368,  1] ../source3/winbindd/winbindd_ads.c:1236(lookup_groupmem)   lsa_lookupsids call failed with NT_STATUS_RPC_PROTOCOL_ERROR - retrying... [2017/12/15 11:39:47.962929,  1] ../source3/rpc_client/cli_pipe.c:568(cli_pipe_validate_current_pdu)   ../source3/rpc_client/cli_pipe.c:568: RPC fault code DCERPC_NCA_S_PROTO_ERROR received from host dc-04.samba.thed...
2007 Jul 10
3
winbind + samba limits with large AD?
Hi, a few months ago I tried to setup samba + winbind (debian etch, amd64, samba 3.0.24). I followed the howto and got the authentication running. But I had not much success with winbind. I disabled the user/group enumeration, but this didn't change it. A simple 'ls -l' in a directory with 10-20 files took minutes to return the list and most of the time winbindd just stopped working
2003 Dec 02
2
Problem with , in Common Name when running samba3 as ADS Member (Problem with Group-Contents)
...switch/winbindd_cache.c:refresh_sequence_number(342) refresh_sequence_number: TOPALISWORLD time ok [2003/12/02 12:24:24, 10] nsswitch/winbindd_cache.c:refresh_sequence_number(367) refresh_sequence_number: TOPALISWORLD seq number is now 4263604 [2003/12/02 12:24:24, 10] nsswitch/winbindd_cache.c:lookup_groupmem(1236) lookup_groupmem: [Cached] - doing backend query for info for domain TOPALISWORLD [2003/12/02 12:24:24, 10] nsswitch/winbindd_ads.c:lookup_groupmem(697) ads: lookup_groupmem TOPALISWORLD sid=S-1-5-21-525015883-470239122-8547516-513 [2003/12/02 12:24:24, 5] libads/ldap_utils.c:ads_do_search...
2016 Feb 10
1
Connect Samba File-Share
...b-COMPANY <== [2016/02/10 14:39:52.771093, 1] ../source3/rpc_client/cli_pipe.c:482(cli_pipe_validate_current_pdu) ../source3/rpc_client/cli_pipe.c:482: RPC fault code WERR_BADFUNC received from host dc2.company.internal! [2016/02/10 14:39:52.771261, 1] ../source3/winbindd/winbindd_ads.c:1297(lookup_groupmem) lsa_lookupsids call failed with NT_STATUS_RPC_CALL_FAILED - retrying... [2016/02/10 14:39:52.774548, 1] ../source3/rpc_client/cli_pipe.c:482(cli_pipe_validate_current_pdu) ../source3/rpc_client/cli_pipe.c:482: RPC fault code WERR_BADFUNC received from host dc2.company.internal! Anyone knows...
2005 Apr 14
2
Using idmap_rid backend, cannot browse home directory from XP
...amp;#9565;l) [2005/04/14 10:15:46, 3] lib/charcnv.c:convert_string_allocate(567) convert_string_allocate: Conversion error: Incomplete multibyte sequence(&#9565;l) [2005/04/14 10:15:46, 3] nsswitch/winbindd_ads.c:dn_lookup(339) ads: dn_lookup [2005/04/14 10:15:46, 3] nsswitch/winbindd_ads.c:lookup_groupmem(777) ads lookup_groupmem for sid=S-1-5-21-725345543-1677128483-839522115-513 [2005/04/14 10:15:46, 3] lib/charcnv.c:convert_string_allocate(567) convert_string_allocate: Conversion error: Incomplete multibyte sequence(Éá) [2005/04/14 10:15:46, 3] lib/charcnv.c:convert_string_allocate(567) con...
2004 Aug 31
0
Overloaded winbind
...ree(): invalid pointer 0xbfffab28! kerberos_kinit_password HOST/walifile@PSFINC.COM failed: Cannot allocate memory [2004/08/30 17:44:01, 1] libads/ldap_utils.c:ads_do_search_retry(77) ads_search_retry: failed to reconnect (Cannot allocate memory) [2004/08/30 17:44:01, 1] nsswitch/winbindd_ads.c:lookup_groupmem(702) ads: lookup_groupmem ads_search: Cannot allocate memory [2004/08/30 17:44:01, 1] nsswitch/winbindd_group.c:fill_grent_mem(133) could not lookup membership for group rid S-1-5-21-1482476501-261478967-1177238915-1336 in domain PSFINC (error: NT_STATUS_UNSUCCESSFUL) [2004/08/30 17:44:01, 1] n...
2009 Apr 01
1
[Announce] Samba 3.3.3 Available for Download
...o Andy Kelk <andy@mopoke.co.uk> * Add dirsort module. o Steve Langasek <vorlon@debian.org> * BUG 6147: Fix detection of the GNU ld version. o Volker Lendecke <vl@samba.org> * BUG 6097: Fix smbd segfault. * BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped members. * BUG 6139: Add missing whitespace in mount.cifs error message. * Fix a malloc/talloc mismatch when cli_initialise() fails. * Fix a valgrind error. * Speed up "net conf list". * Add sorted subkey cache. * Use StrCaseCmp in the dirsort m...
2009 Apr 01
1
[Announce] Samba 3.3.3 Available for Download
...o Andy Kelk <andy@mopoke.co.uk> * Add dirsort module. o Steve Langasek <vorlon@debian.org> * BUG 6147: Fix detection of the GNU ld version. o Volker Lendecke <vl@samba.org> * BUG 6097: Fix smbd segfault. * BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped members. * BUG 6139: Add missing whitespace in mount.cifs error message. * Fix a malloc/talloc mismatch when cli_initialise() fails. * Fix a valgrind error. * Speed up "net conf list". * Add sorted subkey cache. * Use StrCaseCmp in the dirsort m...
2004 Aug 04
3
Winbind being flakey
...seem to indicate any problem. Heres the output of winbindd anyway, with debug level 3 after a failed login attempt from windows: [ 2627]: getgrnam QG+TEST rpc: name_to_sid name=TEST name_to_sid [rpc] TEST for domain QG ads: dn_lookup ads: dn_lookup ads: dn_lookup ads: dn_lookup ads: dn_lookup ads lookup_groupmem for sid=S-1-5-21-842925246-1647877149-1417001333-57015 [ 2627]: getgrnam QG+TEST [ 2627]: getgrnam QG+TEST [ 2629]: request interface version [ 2629]: request location of privileged pipe [ 2629]: domain_info [QG.COM] [ 2629]: getpwnam qg+jzillera rpc: name_to_sid name=jzillera name_to_sid [rpc] jzi...
2009 Nov 22
0
Samba 3.3.9 IDMAP problem
...is restarted. After restart SIDs are mapped to exacts UIDs and GIDs, so my ACLs are not messed up. But I think it is difficult to restart Samba server every time Windows restarts. When problem (restart) occurs I find following messages in my logs: [2009/11/22 17:51:02, 1] winbindd/winbindd_ads.c:lookup_groupmem(1137) lsa_lookupsids call failed with NT_STATUS_PIPE_BROKEN - retrying... [2009/11/22 17:51:02, 0] lib/util_sock.c:write_data(1139) write_data: write failure. Error = Broken pipe [2009/11/22 17:51:02, 0] rpc_client/cli_pipe.c:rpc_api_pipe(930) rpc_api_pipe: write_data returned Broken pipe...
2013 Jan 14
0
Solaris 11.1 + Samba 3.6.6 + ads + getent group - a bug, perhaps?
...ads/ldap_utils.c:134(ads_do_search_retry_internal) ads reopen failed after error Timelimit exceeded [2013/01/14 20:03:36.835209, 1, pid=788] libads/ldap_utils.c:315(ads_ranged_search_internal) ads_search: Timelimit exceeded [2013/01/14 20:03:36.835261, 0, pid=788] winbindd/winbindd_ads.c:1084(lookup_groupmem) ads_ranged_search failed with: Timelimit exceeded Can't help but think after searching the lists that this might be a bug. Apparently there was a bug in the 3.5.x series (I think?) where, if there were > 1000 groups (or was it users in a group?) there were issues like this. Can someone...
2008 Nov 27
1
[Announce] Samba 3.3.0rc1 Available for Download
...delay New 100 winbind reconnect delay New 30 Changes since 3.3.0pre2: - ------------------------ o Michael Adam <obnox@samba.org> * Fix eventlog crash. * Make keytab filename argument mandatory to "net rpc vampire keytab". * Add domain prefix to username in lookup_groupmem(). * Honour "winbind use default domain" in lookup_groupmem(). * Sanely handle NULL domain in add_member(). * Don''t list the domain twice when expanding internal aliases. * Prevent negative GM/ cache entries due to broken connections. * Use the reconnect metho...
2008 Nov 27
1
[Announce] Samba 3.3.0rc1 Available for Download
...delay New 100 winbind reconnect delay New 30 Changes since 3.3.0pre2: - ------------------------ o Michael Adam <obnox@samba.org> * Fix eventlog crash. * Make keytab filename argument mandatory to "net rpc vampire keytab". * Add domain prefix to username in lookup_groupmem(). * Honour "winbind use default domain" in lookup_groupmem(). * Sanely handle NULL domain in add_member(). * Don''t list the domain twice when expanding internal aliases. * Prevent negative GM/ cache entries due to broken connections. * Use the reconnect metho...
2011 Dec 21
1
Winbind authentication and wbinfo -i user no longer work after uprading to 3.6.1
...------------------------------ This morning, I recreated the error by restarting Samba/winbind at 07:47. The only suspicious level 10 log entries found from that timeframe are: <syslog> Dec 21 07:47:25 debinsp3200 winbindd[3489]: [2011/12/21 07:47:25.660769, 0] winbindd/winbindd_ads.c:1068(lookup_groupmem) Dec 21 07:47:25 debinsp3200 winbindd[3489]: ads_ranged_search failed with: Time limit exceeded <smbd> [2011/12/21 07:47:10.102879, 1] lib/serverid.c:197(serverid_deregister) Deleting serverid.tdb record failed: NT_STATUS_NOT_FOUND [2011/12/21 07:47:10.103603, 1] smbd/server.c:303(rem...
2009 Mar 31
1
[Announce] Samba 3.2.9 Maintenance Release Available
...kkukk <linux@kukkukk.com> * Don''t try and delete a default ACL from a file. o Jeff Layton <jlayton@redhat.com> * Initialize rc to 0 in main. o Volker Lendecke <vl@sernet.de> * BUG 6100: Complete fix. * BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped members. * BUG 6097: Fix smbd segfault. * Fix remotely adding a share via MMC. * Fix resume handle for _samr_EnumDomainGroups. * Fix Coverity IDs 742, 744, 745, 879, 880. * Fix a buffer handling bug when adding lots of registry keys. * Fix a O(n^2) algori...
2009 Mar 31
1
[Announce] Samba 3.2.9 Maintenance Release Available
...kkukk <linux@kukkukk.com> * Don''t try and delete a default ACL from a file. o Jeff Layton <jlayton@redhat.com> * Initialize rc to 0 in main. o Volker Lendecke <vl@sernet.de> * BUG 6100: Complete fix. * BUG 6130: Don''t crash in winbindd_rpc lookup_groupmem() on unmapped members. * BUG 6097: Fix smbd segfault. * Fix remotely adding a share via MMC. * Fix resume handle for _samr_EnumDomainGroups. * Fix Coverity IDs 742, 744, 745, 879, 880. * Fix a buffer handling bug when adding lots of registry keys. * Fix a O(n^2) algori...
2012 Jul 30
1
'x' bit always set?
...zuccato:rwx default:group::--x default:group:100013:--x default:mask::rwx default:other::--- Another strange thing is that, with this last command, it stopped resolving 100013 to PERSONALE\domain_users ... any possible reason? I can see [2012/07/30 09:29:23.572740, 0] winbindd/winbindd_ads.c:1039(lookup_groupmem) ads_ranged_search failed with: Invalid DN syntax in log.wb-PERSONALE . Before that, it was correctly resolved: # id diego.zuccato uid=108036(diego.zuccato) gid=100013(domain_users) gruppi=100013(domain_users),[...] but now: # id diego.zuccato uid=108036(diego.zuccato) gid=100013 gruppi=100013,[...
2006 May 30
0
Samba 3.0.22 w2k3 ad+sfu working but ls shows only uidNumber and not uid
...3554 1 2 2 3 ads_sasl_spnego_bind: got OID=1 3 6 1 4 1 311 2 2 10 ads_sasl_spnego_bind: got server principal name =ewt-master$@META.XXX.XX ads_krb5_mk_req: krb5_cc_get_principal failed (No such file or directory) Ticket in ccache[MEMORY:winbind_ccache] expiration Tue, 30 May 2006 19:17:30 CEST ads lookup_groupmem for sid=S-1-5-21-2857693109-2026923775-3634067142-1366 And a wbinfo -s S-1-5-21-2857693109-2026923775-3634067142-1366 gives: test:/var/server# wbinfo -s S-1-5-21-2857693109-2026923775-3634067142-1366 METADS\dmg 2 As you can see, the conversion sid to gid works ! I 've also tried playing wit...