Displaying 20 results from an estimated 153 matches for "neg_token_init".
2015 Apr 09
3
After Update Member Server not working
...ress>, I can/must authenticate with administrator, normal domain users do not work anymore. When I hit \\<Servername>, nothing is working. There is only a message, I am not authorized to use the resource.
Here your are a log of smbd:
grep LOGON /var/log/samba/log.smbd
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
smbd_smb2_request_error_ex: idx[1] status[NT_STATUS_LOGON_FAILURE] || at ../source3/smbd/smb2_sesssetup.c:131
smbd_smb2_request_done_ex: idx[1] status[NT_STATUS_LOGON_FAILURE] body[8] dyn[yes:1] at ../source3/smbd...
2016 Nov 02
1
winbind trust account password management
....
Every 3-4 days, I see log messages from winbind saying
"winbind_samlogon_retry_loop: sam_logon returned ACCESS_DENIED".
Sometimes this corresponds to a trust password change, but not always.
Today, new connections to Samba were failing with the error
"SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed:
NT_STATUS_INTERNAL_ERROR" for an hour. I restored service by re-running
"net rpc join" and restarting winbindd.
I search bugzilla for any issues like this, and I looked at the release
notes for versions newer than v4.4.4. I don't see anything specifically
related t...
2015 Apr 09
2
After Update Member Server not working
...more. When I hit \\<Servername>, nothing is
>>> working. There is only a message, I am not authorized to use
>>> the resource.
>>>
>>>
>>> Here your are a log of smbd:
>>> grep LOGON /var/log/samba/log.smbd
>>> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
>>> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
>>> smbd_smb2_request_error_ex: idx[1]
>>> status[NT_STATUS_LOGON_FAILURE] || at
>>> ../source3/smbd/smb2_sesssetup.c:131
>>> smbd_smb2_request_done_ex: idx[1]
>...
2015 Apr 09
0
After Update Member Server not working
...ith administrator, normal domain users
>do not work anymore. When I hit \\<Servername>, nothing is
>working. There is only a message, I am not authorized to use
>the resource.
>
>
>Here your are a log of smbd:
>grep LOGON /var/log/samba/log.smbd
> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
> smbd_smb2_request_error_ex: idx[1]
>status[NT_STATUS_LOGON_FAILURE] || at
>../source3/smbd/smb2_sesssetup.c:131
> smbd_smb2_request_done_ex: idx[1]
>status[NT_STATUS_LOGON_FAILURE] body[8] dy...
2015 Apr 09
0
After Update Member Server not working
...name>, nothing is
>>>> working. There is only a message, I am not authorized to use
>>>> the resource.
>>>>
>>>>
>>>> Here your are a log of smbd:
>>>> grep LOGON /var/log/samba/log.smbd
>>>> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
>>>> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
>>>> smbd_smb2_request_error_ex: idx[1]
>>>> status[NT_STATUS_LOGON_FAILURE] || at
>>>> ../source3/smbd/smb2_sesssetup.c:131
>>>> smbd_smb2_reque...
2016 Oct 05
0
Winbind Preauthentication failed
...gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/fs1.domain.local at DOMAIN.LOCAL(kvno 2) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
[2016/10/02 06:10:34.884404, 1] ../auth/gensec/spnego.c:541(ge
nsec_spnego_parse_negTokenInit)
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:10:34.884433, 2] ../auth/gensec/spnego.c:716(ge
nsec_spnego_server_negTokenTarg)
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:13:07.177316, 2] ../source3/smbd/server.c:467(r
emove_child_pid)
Could not find child 24041 -- ignoring
[...
2019 Jan 14
2
Samba shares no longer visible
...o longer accessible. After working on it for a while, I finally turned up logging and found the following in the client connection logs:
[2019/01/14 14:59:21.384622, 1] ../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: ntlmssp: parsing NEG_TOKEN_INIT content failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
[2019/01/14 14:59:21.396728, 2] ../auth/ntlmssp/ntlmssp.c:119(gensec_ntlmssp_update_find)
Failed to parse NTLMSSP packet: zero length
[2019/01/14 14:59:21.396777, 1] ../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)...
2018 Jun 30
2
DM 3.6.25 -> 4.x
additional note:
# kinit sgw
Password for sgw at customer.INTRA:
# smbclient \\\\u1customer\\IT -U sgw -k
SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/u1customer failed
(next[(null)]): NT_STATUS_INVALID_PARAMETER
SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT
session setup failed: NT_STATUS_INVALID_PARAMETER
(krb5.conf already reduced to minimum, btw)
Does that point to some mismatching encryption stuff?
I repeat: the s...
2016 Oct 04
0
Fwd: Winbind Preauthentication failed
...gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/fs1.domain.local at DOMAIN.LOCAL(kvno 2) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
[2016/10/02 06:10:34.884404, 1] ../auth/gensec/spnego.c:541(
gensec_spnego_parse_negTokenInit)
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:10:34.884433, 2] ../auth/gensec/spnego.c:716(
gensec_spnego_server_negTokenTarg)
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:13:07.177316, 2] ../source3/smbd/server.c:467(
remove_child_pid)
Could not find child 24041 -- ignoring
[...
2012 Jan 20
1
Samba 4 Cannot contact any KDC for requested realm
...8
After starting samba -i -d3,
wbinfo -i someuser
gives this:
ldb_wrap open of secrets.ldb
using SPNEGO
Selected protocol [8][NT LANMAN 1.0]
Cannot reach a KDC we require to contact cifs/hh3.site at SITE : kinit for
HH3$@SITE failed (Cannot contact any KDC for requested realm)
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS
ldb_wrap open of secrets.ldb
schannel_fetch_session_key_tdb: restored schannel info key
SECRETS/SCHANNEL/HH3
Cannot reach a KDC we require to contact host/hh3.site at SITE : kinit for
HH3$@SITE failed (Cannot contact any KDC for requested realm)
SPNEGO(gssapi_...
2018 Apr 19
4
Share authentication problem
...e 42.3 as domain member
in a debian based Samba4 AD. The join seems to be ok, as I can get
/wbinfo -u/ and /-g/, and /getent group/ and /passwd/.
I can also list all browsable shares with /smbclient -L \\SambaFS
-Uusername/, but when i add -k, I get following errors :
/SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/Samba1 failed
(next[(null)]): NT_STATUS_INVALID_PARAMETER//
//SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT//
//session setup failed: NT_STATUS_INVALID_PARAMETER/
/----------------------------------------------------------------------------------------/
So bought a book ...
2019 Feb 26
5
gpo not applied a boot computer
...ailure (see
text): Failed to find SAMBA4$@FSS.LAN (kvno 2) in keytab FILE:
/var/lib/samba/private/secrets.keytab (arcfour -hmac-md5)
[2019/02/20 11: 20: 33.013351, 1]
../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: gssapi_krb5: parsing
NEG_TOKEN_INIT content failed (next [(null)]): NT_STATUS_LOGON_FAILURE
[2019/02/20 11: 20: 33.041913, 1]
../source4/auth/gensec/gensec_gssapi.c:790(gensec_gssapi_update_internal)
thank you again for your participation.
2017 Aug 11
2
NT_STATUS_INTERNAL_ERROR and cannot join windows 7 samba4-ad-dc fresh install, get NT_STATUS_INTERNAL_ERROR
...Aug 2017 05:56:36 +1200
Andrew Bartlett via samba <samba at lists.samba.org> wrote:
> On Fri, 2017-08-11 at 08:02 -0400, Ing. Luis Felipe Domínguez Vega via
> samba wrote:
> > gss_init_sec_context failed with [ The context has expired: Success]
> > SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed:
> > NT_STATUS_INTERNAL_ERROR
>
> Can you please show me your smb.conf?
>
> I gse_krb5 shouldn't run on an AD DC, so I think the smb.conf is
> somehow set up as a file server.
>
> Andrew Bartlett
>
Hi Andrew,
He has already posted it in his first post...
2009 Dec 04
1
smbtorture config issue?
...rror returned from params.c:parse().
I have tried both ads and ADS, it doesn't seem to like either
2) smbtorture proceeds to complain as such:
Server is not registered with our KDC: Miscellaneous failure (see
text): Server (cifs/cictest.cic.iu.edu at ADS.IU.EDU) unknown
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed to parse:
NT_STATUS_INVALID_PARAMETER
Got challenge flags:
Got NTLMSSP neg_flags=0x60898215
NTLMSSP: Set final flags:
Got NTLMSSP neg_flags=0x60088215
Server is not registered with our KDC: Miscellaneous failure (see
text): Server (cifs/cictest.cic.iu.edu at ADS.IU.EDU) unknown
SPNEGO(g...
2013 Jan 27
2
Samba Authentication With Kerberos
...-L localhost -k
The error message from Samba is:
using SPNEGO
Selected protocol [8][NT LANMAN 1.0]
GSS server Update(krb5)(1) Update failed: Miscellaneous failure (see text): Decrypt integrity check failed for checksum type hmac-sha1-96-aes256, key type aes256-cts-hmac-sha1-96
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
Any help will be appreciated.
Thanks and regards,
2019 Oct 09
2
Failed to find cifs/fs-share@dom.corp (kvno 109) in keytab
Rowland, it is not a problem of mount but of kerberso ticket:
[2019/10/08 10:58:09.626059, 1]
../../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: gse_krb5: parsing NEG_TOKEN_INIT
content failed (next[(null)]): NT_STATUS_LOGON_FAILURE
[2019/10/08 10:58:09.634532, 1]
../../source3/librpc/crypto/gse.c:660(gse_get_server_auth_token)
gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/dom.corp at DOM.CORP(kvno 109) in keytab
MEMORY:cifs_...
2016 Nov 04
3
smbclient and Kerberos
...desktop clients, but when I use smbclient with a valid ticket with the -k flag I get a KDC lookup failure
kev at client:/home/testuser$ smbclient -k -L //fileserver
gss_init_sec_context failed with [ Miscellaneous failure (see text): unable to reach any KDC in realm LAN]
SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_INTERNAL_ERROR
session setup failed: NT_STATUS_INTERNAL_ERROR
I've noticed that if I configure the KDC server in the [realm] section of my /etc/krb5.conf everything works fine.
Does smbclient not use the DNS for KDC lookup?
I am using version Version 4.3.11-Ubuntu on Ubuntu...
2017 Jan 12
2
Difficulties with Windows XP: failed to find cifs/fileserver.y.z@Y.Z in keytab (arcfour-hmac-md5)
...ss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/hg004.humgen.0zone at HUMGEN.0ZONE(kvno 1) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
[2017/01/11 16:42:34.522095, 1]
../auth/gensec/spnego.c:541(gensec_spnego_parse_negTokenInit)
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
[2017/01/11 16:42:34.525704, 1]
../lib/param/loadparm.c:1629(lpcfg_do_global_parameter)
WARNING: The "syslog only" option is deprecated
[2017/01/11 16:42:34.525743, 1]
../lib/param/loadparm.c:1629(lpcfg_do_global_parameter)
WARNING: The "syslog&q...
2018 Apr 14
3
smbclient kerberos auth fails
...Valid starting Expires Service principal
04/14/2018 13:49:22 04/14/2018 23:49:22 krbtgt/FOO.COM at FOO.COM
renew until 04/15/2018 13:49:21
At this point I think it should work, but I get:
$ smbclient //foo.com/share -k
SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/foo.com failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT
session setup failed: NT_STATUS_INVALID_PARAMETER
I've attached a network trace with SMB, DNS and kerberos traffic.
-------------- next part --------------...
2017 Nov 07
3
after DCs migration to 4.7, two things
...)(1) Update failed: Miscellaneous failure (see text): Failed to find DC4$@SAMBA.COMPANY.COM(kvno 1) in keytab FILE:/var/lib/samba/private/secrets.keytab (arcfour-hmac-md5)
> [2017/11/07 18:23:25.114456, 1] ../auth/gensec/spnego.c:411(gensec_spnego_parse_negTokenInit)
> SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
That one worries me a bit more than the DNS thing...
Have a nice evening everyone!
MJ