Displaying 7 results from an estimated 7 matches for "nt_status_downgrade_detected".
2020 Oct 05
3
Upgrade to Samba 4.12 question
...CNC machines with some embedded Windows like 95, so
upgrade of OS is impossible.
While that machines communicate with fileserver, I can see this message
in log.samba on DC:
? Auth: [NETLOGON,ServerAuthenticate] user [SVMETAL]\[TCL3030$] at
[Mon, 05 Oct 2020 10:31:40.762795 CEST] with [DES] status
[NT_STATUS_DOWNGRADE_DETECTED] workstation [(null)] remote host
[ipv4:192.168.1.28:1076] mapped to [(null)]\[(null)]. local host
[ipv4:192.168.1.1:139] NETLOGON computer [TCL3030] trust account
[(null)]?.
Does it mean, when I upgrade to Samba 4.12, that machine communications
will be refused?
So we have to stay (stuck) on Sa...
2020 Oct 05
0
Upgrade to Samba 4.12 question
...ed Windows like 95, so
> upgrade of OS is impossible.
> While that machines communicate with fileserver, I can see this message
> in log.samba on DC:
> ? Auth: [NETLOGON,ServerAuthenticate] user [SVMETAL]\[TCL3030$] at
> [Mon, 05 Oct 2020 10:31:40.762795 CEST] with [DES] status
> [NT_STATUS_DOWNGRADE_DETECTED] workstation [(null)] remote host
> [ipv4:192.168.1.28:1076] mapped to [(null)]\[(null)]. local host
> [ipv4:192.168.1.1:139] NETLOGON computer [TCL3030] trust account
> [(null)]?.
>
> Does it mean, when I upgrade to Samba 4.12, that machine communications
> will be refused?
>...
2016 May 11
0
winbind trusted domain regression after upgrade to samba 4.2.10
...connect to our PDC (still samba 3.6.25) to list the
trusted domains.
Also I in the winbind logfile I found:
Unwilling to make SAMR connection to domain EXAMPLEwithout connection
level security, must set 'winbind sealed pipes = false' and 'require
strong key = false' to proceed: NT_STATUS_DOWNGRADE_DETECTED
So I added these options...but still no luck, the users of the trusted
domain are gone...
BTW, samba-4.2.9 is ok, wbinfo --domain=EXAMPLE -u
lists the users, wbinfo -t works for both domains.
Well, that's it for now,
Oliver
2018 Sep 02
3
winbindd crashing -- how to auto-heal?
El 2/9/18 a les 10:39, Rowland Penny via samba ha escrit:
> All of this is just a sticking plaster on the problem, if winbind is
> crashing on a regular basis, we need to know this and will need
> level 10 logs, debug info etc. Without this info, it will never get
> fixed.
Meanwhile, I need my server to keep running, so the plaster looks fine.
Besides, winbind isn't crashing,
2016 May 16
1
Synology NAS Samba Upgrade breaks "Classic" domain membership
On both the synology (samba 4.1.20) and PDC (samba 3.6.25) testparm showed
client schannel = Auto
server schannel = Auto
I don't know if the server even supports schannel. Maybe it
doesn't any all the clients successfully negotiated not to use it. On
the synology, I set
client schannel = no
This fixed my domain membership issue. Although
2016 Apr 12
0
[Announce] Samba 4.4.2, 4.3.8 and 4.2.11 Available for Download
...oblems. You can indentify the
bug by debug messages at log level 1 in log.wb-* similar to:
Unwilling to make connection to domain OTHERDOMAIN without
connection level security, must set "winbind sealed pipes = false"
and "require strong key = false" to proceed: NT_STATUS_DOWNGRADE_DETECTED
Note that there is a workaround by changing the configuration:
The workaround consists in adding the following to the [global]
section of the smb.conf on the domain member server.
In the example you would have "workgroup = PRIMARYDOMAIN".
winbind sealed pipes = false
r...
2016 Apr 12
0
[Announce] Samba 4.4.2, 4.3.8 and 4.2.11 Available for Download
...oblems. You can indentify the
bug by debug messages at log level 1 in log.wb-* similar to:
Unwilling to make connection to domain OTHERDOMAIN without
connection level security, must set "winbind sealed pipes = false"
and "require strong key = false" to proceed: NT_STATUS_DOWNGRADE_DETECTED
Note that there is a workaround by changing the configuration:
The workaround consists in adding the following to the [global]
section of the smb.conf on the domain member server.
In the example you would have "workgroup = PRIMARYDOMAIN".
winbind sealed pipes = false
r...