Displaying 20 results from an estimated 159 matches for "neg_token_init".
2015 Apr 09
3
After Update Member Server not working
...ress>, I can/must authenticate with administrator, normal domain users do not work anymore. When I hit \\<Servername>, nothing is working. There is only a message, I am not authorized to use the resource.
Here your are a log of smbd:
grep LOGON /var/log/samba/log.smbd
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
smbd_smb2_request_error_ex: idx[1] status[NT_STATUS_LOGON_FAILURE] || at ../source3/smbd/smb2_sesssetup.c:131
smbd_smb2_request_done_ex: idx[1] status[NT_STATUS_LOGON_FAILURE] body[8] dyn[yes:1] at ../source3/smbd...
2016 Nov 02
1
winbind trust account password management
....
Every 3-4 days, I see log messages from winbind saying
"winbind_samlogon_retry_loop: sam_logon returned ACCESS_DENIED".
Sometimes this corresponds to a trust password change, but not always.
Today, new connections to Samba were failing with the error
"SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed:
NT_STATUS_INTERNAL_ERROR" for an hour. I restored service by re-running
"net rpc join" and restarting winbindd.
I search bugzilla for any issues like this, and I looked at the release
notes for versions newer than v4.4.4. I don't see anything specifically
related t...
2015 Apr 09
2
After Update Member Server not working
...more. When I hit \\<Servername>, nothing is
>>> working. There is only a message, I am not authorized to use
>>> the resource.
>>>
>>>
>>> Here your are a log of smbd:
>>> grep LOGON /var/log/samba/log.smbd
>>> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
>>> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
>>> smbd_smb2_request_error_ex: idx[1]
>>> status[NT_STATUS_LOGON_FAILURE] || at
>>> ../source3/smbd/smb2_sesssetup.c:131
>>> smbd_smb2_request_done_ex: idx[1]
>...
2024 Oct 25
0
Could not find a suitable mechtype in NEG_TOKEN_INIT error in libsmbclient 4.19.4
...d 'ntlmssp_resume_ccache' registered
GENSEC backend 'http_basic' registered
GENSEC backend 'http_ntlm' registered
GENSEC backend 'http_negotiate' registered
Starting GENSEC mechanism spnego
gensec_spnego_client_negTokenInit_step: Could not find a suitable mechtype
in NEG_TOKEN_INIT
Regards,
Manu
2024 Oct 25
0
Could not find a suitable mechtype in NEG_TOKEN_INIT error in libsmbclient 4.19.4
> gensec_spnego_client_negTokenInit_step: Could not find a suitable mechtype
> in NEG_TOKEN_INIT
Turns out that this error comes up when gnutls enforces fips mode.
Behaviour of gnutls when fips mode is enabled is different in Centos7 vs
Almalinux 9.4. With updated gnutls, samba fails when fips mode is enabled.
Workaround is to use the GNUTLS_FORCE_FIPS_MODE environment variable to
set/unset f...
2015 Apr 09
0
After Update Member Server not working
...ith administrator, normal domain users
>do not work anymore. When I hit \\<Servername>, nothing is
>working. There is only a message, I am not authorized to use
>the resource.
>
>
>Here your are a log of smbd:
>grep LOGON /var/log/samba/log.smbd
> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
> smbd_smb2_request_error_ex: idx[1]
>status[NT_STATUS_LOGON_FAILURE] || at
>../source3/smbd/smb2_sesssetup.c:131
> smbd_smb2_request_done_ex: idx[1]
>status[NT_STATUS_LOGON_FAILURE] body[8] dy...
2015 Apr 09
0
After Update Member Server not working
...name>, nothing is
>>>> working. There is only a message, I am not authorized to use
>>>> the resource.
>>>>
>>>>
>>>> Here your are a log of smbd:
>>>> grep LOGON /var/log/samba/log.smbd
>>>> SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
>>>> SPNEGO login failed: NT_STATUS_LOGON_FAILURE
>>>> smbd_smb2_request_error_ex: idx[1]
>>>> status[NT_STATUS_LOGON_FAILURE] || at
>>>> ../source3/smbd/smb2_sesssetup.c:131
>>>> smbd_smb2_reque...
2016 Oct 05
0
Winbind Preauthentication failed
...gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/fs1.domain.local at DOMAIN.LOCAL(kvno 2) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
[2016/10/02 06:10:34.884404, 1] ../auth/gensec/spnego.c:541(ge
nsec_spnego_parse_negTokenInit)
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:10:34.884433, 2] ../auth/gensec/spnego.c:716(ge
nsec_spnego_server_negTokenTarg)
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:13:07.177316, 2] ../source3/smbd/server.c:467(r
emove_child_pid)
Could not find child 24041 -- ignoring
[...
2019 Jan 14
2
Samba shares no longer visible
...o longer accessible. After working on it for a while, I finally turned up logging and found the following in the client connection logs:
[2019/01/14 14:59:21.384622, 1] ../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: ntlmssp: parsing NEG_TOKEN_INIT content failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
[2019/01/14 14:59:21.396728, 2] ../auth/ntlmssp/ntlmssp.c:119(gensec_ntlmssp_update_find)
Failed to parse NTLMSSP packet: zero length
[2019/01/14 14:59:21.396777, 1] ../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)...
2018 Jun 30
2
DM 3.6.25 -> 4.x
additional note:
# kinit sgw
Password for sgw at customer.INTRA:
# smbclient \\\\u1customer\\IT -U sgw -k
SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/u1customer failed
(next[(null)]): NT_STATUS_INVALID_PARAMETER
SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT
session setup failed: NT_STATUS_INVALID_PARAMETER
(krb5.conf already reduced to minimum, btw)
Does that point to some mismatching encryption stuff?
I repeat: the s...
2016 Oct 04
0
Fwd: Winbind Preauthentication failed
...gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/fs1.domain.local at DOMAIN.LOCAL(kvno 2) in keytab
MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
[2016/10/02 06:10:34.884404, 1] ../auth/gensec/spnego.c:541(
gensec_spnego_parse_negTokenInit)
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:10:34.884433, 2] ../auth/gensec/spnego.c:716(
gensec_spnego_server_negTokenTarg)
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
[2016/10/02 06:13:07.177316, 2] ../source3/smbd/server.c:467(
remove_child_pid)
Could not find child 24041 -- ignoring
[...
2012 Jan 20
1
Samba 4 Cannot contact any KDC for requested realm
...8
After starting samba -i -d3,
wbinfo -i someuser
gives this:
ldb_wrap open of secrets.ldb
using SPNEGO
Selected protocol [8][NT LANMAN 1.0]
Cannot reach a KDC we require to contact cifs/hh3.site at SITE : kinit for
HH3$@SITE failed (Cannot contact any KDC for requested realm)
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS
ldb_wrap open of secrets.ldb
schannel_fetch_session_key_tdb: restored schannel info key
SECRETS/SCHANNEL/HH3
Cannot reach a KDC we require to contact host/hh3.site at SITE : kinit for
HH3$@SITE failed (Cannot contact any KDC for requested realm)
SPNEGO(gssapi_...
2018 Apr 19
4
Share authentication problem
...e 42.3 as domain member
in a debian based Samba4 AD. The join seems to be ok, as I can get
/wbinfo -u/ and /-g/, and /getent group/ and /passwd/.
I can also list all browsable shares with /smbclient -L \\SambaFS
-Uusername/, but when i add -k, I get following errors :
/SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/Samba1 failed
(next[(null)]): NT_STATUS_INVALID_PARAMETER//
//SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT//
//session setup failed: NT_STATUS_INVALID_PARAMETER/
/----------------------------------------------------------------------------------------/
So bought a book ...
2024 Jun 26
2
Kerberos issues
...ttp_basic', 'http_ntlm'
> 'krb5', 'fake_gssapi_krb5' registered
> Password for [MYDOMAIN\administrator]:
> Wrong username or password: kinit for administrator at MYDOMAIN.LAN failed
> (Client not found in Kerberos database)
> SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT for ldap/DC1 failed
> (next[ntlmssp]): NT_STATUS_LOGON_FAILURE
> ...
> resolve_lmhosts: Attempting lmhosts lookup for name DC2<0x20>
> Wrong username or password: kinit for administrator at MYDOMAIN.LAN failed
> (Client not found in Kerberos database)
> SPNEGO(gssapi_krb5)...
2019 Feb 26
5
gpo not applied a boot computer
...ailure (see
text): Failed to find SAMBA4$@FSS.LAN (kvno 2) in keytab FILE:
/var/lib/samba/private/secrets.keytab (arcfour -hmac-md5)
[2019/02/20 11: 20: 33.013351, 1]
../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: gssapi_krb5: parsing
NEG_TOKEN_INIT content failed (next [(null)]): NT_STATUS_LOGON_FAILURE
[2019/02/20 11: 20: 33.041913, 1]
../source4/auth/gensec/gensec_gssapi.c:790(gensec_gssapi_update_internal)
thank you again for your participation.
2017 Aug 11
2
NT_STATUS_INTERNAL_ERROR and cannot join windows 7 samba4-ad-dc fresh install, get NT_STATUS_INTERNAL_ERROR
...Aug 2017 05:56:36 +1200
Andrew Bartlett via samba <samba at lists.samba.org> wrote:
> On Fri, 2017-08-11 at 08:02 -0400, Ing. Luis Felipe Domínguez Vega via
> samba wrote:
> > gss_init_sec_context failed with [ The context has expired: Success]
> > SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed:
> > NT_STATUS_INTERNAL_ERROR
>
> Can you please show me your smb.conf?
>
> I gse_krb5 shouldn't run on an AD DC, so I think the smb.conf is
> somehow set up as a file server.
>
> Andrew Bartlett
>
Hi Andrew,
He has already posted it in his first post...
2009 Dec 04
1
smbtorture config issue?
...rror returned from params.c:parse().
I have tried both ads and ADS, it doesn't seem to like either
2) smbtorture proceeds to complain as such:
Server is not registered with our KDC: Miscellaneous failure (see
text): Server (cifs/cictest.cic.iu.edu at ADS.IU.EDU) unknown
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed to parse:
NT_STATUS_INVALID_PARAMETER
Got challenge flags:
Got NTLMSSP neg_flags=0x60898215
NTLMSSP: Set final flags:
Got NTLMSSP neg_flags=0x60088215
Server is not registered with our KDC: Miscellaneous failure (see
text): Server (cifs/cictest.cic.iu.edu at ADS.IU.EDU) unknown
SPNEGO(g...
2013 Jan 27
2
Samba Authentication With Kerberos
...-L localhost -k
The error message from Samba is:
using SPNEGO
Selected protocol [8][NT LANMAN 1.0]
GSS server Update(krb5)(1) Update failed: Miscellaneous failure (see text): Decrypt integrity check failed for checksum type hmac-sha1-96-aes256, key type aes256-cts-hmac-sha1-96
SPNEGO(gssapi_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
SPNEGO login failed: NT_STATUS_LOGON_FAILURE
Any help will be appreciated.
Thanks and regards,
2019 Oct 09
2
Failed to find cifs/fs-share@dom.corp (kvno 109) in keytab
Rowland, it is not a problem of mount but of kerberso ticket:
[2019/10/08 10:58:09.626059, 1]
../../auth/gensec/spnego.c:1218(gensec_spnego_server_negTokenInit_step)
gensec_spnego_server_negTokenInit_step: gse_krb5: parsing NEG_TOKEN_INIT
content failed (next[(null)]): NT_STATUS_LOGON_FAILURE
[2019/10/08 10:58:09.634532, 1]
../../source3/librpc/crypto/gse.c:660(gse_get_server_auth_token)
gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/dom.corp at DOM.CORP(kvno 109) in keytab
MEMORY:cifs_...
2016 Nov 04
3
smbclient and Kerberos
...desktop clients, but when I use smbclient with a valid ticket with the -k flag I get a KDC lookup failure
kev at client:/home/testuser$ smbclient -k -L //fileserver
gss_init_sec_context failed with [ Miscellaneous failure (see text): unable to reach any KDC in realm LAN]
SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_INTERNAL_ERROR
session setup failed: NT_STATUS_INTERNAL_ERROR
I've noticed that if I configure the KDC server in the [realm] section of my /etc/krb5.conf everything works fine.
Does smbclient not use the DNS for KDC lookup?
I am using version Version 4.3.11-Ubuntu on Ubuntu...