Displaying 11 results from an estimated 11 matches for "sam_logon".
2016 Nov 02
1
winbind trust account password management
I'm running Samba v4.4.4 as a domain member server in security=domain
mode. Our 3 domain controllers are Server 2012r2.
Every 3-4 days, I see log messages from winbind saying
"winbind_samlogon_retry_loop: sam_logon returned ACCESS_DENIED".
Sometimes this corresponds to a trust password change, but not always.
Today, new connections to Samba were failing with the error
"SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed:
NT_STATUS_INTERNAL_ERROR" for an hour. I restored service by re-running...
2005 Apr 04
4
NT_STATUS_ACCESS_DENIED with winbindd authentication
Hi,
We're running a print server having the following specifications:
Samba 3.0.11
Suse 9.1
Kernel 2.6.5-7.108 kernel
A few days back none of the users were able to log onto the print
server. The debug 10 logs show the following lines:
[2005/03/29 11:21:05, 5] auth/auth.c:check_ntlm_password(271)
check_ntlm_password: winbind authentication for user [**user-name**]
FAILED with error
2005 Mar 03
3
winbindd reporting "killing connections to DOMAIN"
...nbindd_misc.c:winbindd_ping(238)
[ 6364]: ping
[2005/03/03 14:56:54, 3, pid=3736]
nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(465)
[ 6364]: pam auth crap domain: MPLC user: finchm
[2005/03/03 14:56:54, 3, pid=3736]
nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556)
winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the trust
account password was changed and we didn't know it. Killing connections to
domain MPLC
[2005/03/03 14:56:54, 3, pid=3736]
nsswitch/winbindd_cm.c:cm_get_ipc_userpass(109)
IPC$ connections done anonymously
[2005/03/03 14:56:54, 3, pid=3736]
nsswitch/win...
2001 Nov 05
0
smbd cpu spin & Failed to marshall NET_R_SAM_LOGON
...es not seemed to have helped. This is a Solaris 2.6
environment. Every time the smbd goes into CPU spin, I notice the following
things:
a) truss -p on the process report nothing happening ie looks like internal loop
not stuck on some system resource).
b) there is a report that complains about sam_logon everytime I have checked
loke the following (in log.smbd):
[2001/11/05 08:36:26, 0, pid=16184, effective(60001, 60001), real(0, 0)]
rpc_server/srv_netlog.c:api_net_sam_logon(208)
api_net_sam_logon: Failed to marshall NET_R_SAM_LOGON.
[2001/11/05 08:36:26, 0, pid=16184, effective(60001, 60001),...
2005 Mar 18
0
(no subject)
...000 milliseconds
[2005/03/18 13:52:44, 3] nsswitch/winbindd_cm.c:connection_ok(703)
Connection to for domain DOMAIN (pipe \PIPE\NETLOGON) has died or was never started (fd == -1)
and
[2005/03/17 14:26:26, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556)
winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain DOMAIN
Samba-3.0.11
AD Win2003
2006 Apr 26
1
Bad Password
...witch/winbindd_dual.c:child_process_request(359)
process_request: request fn PAM_AUTH
[2006/04/26 11:09:17, 3]
nsswitch/winbindd_pam.c:winbindd_dual_pam_auth(252)
[ 8465]: pam auth NA\trimblrd
[2006/04/26 11:09:17, 3]
nsswitch/winbindd_pam.c:winbindd_dual_pam_auth(400)
winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust
account password was changed and we didn't know it. Killing connections
to domain NA
[2006/04/26 11:09:17, 8] nsswitch/winbindd_cm.c:connection_ok(806)
Connection to USTR-NADC1 for domain NA has NULL cli!
[2006/04/26 11:09:17, 3] nsswitch/winbindd_c...
2008 Jul 30
0
SAMBA + ADS + Kerberos Problem...
...e/parse_prs.c:prs_ntstatus(767)
001c status : NT_STATUS_ACCESS_DENIED
[2008/07/30 17:01:32, 10] libsmb/credentials.c:creds_client_check(325)
creds_client_check: credentials check OK.
[2008/07/30 17:01:32, 3]
nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1546)
winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust
account password was changed and we didn't know it. Killing connections
to domain DOMAIN
When i do:
wbinfo -u: Show the ADS user BUT not show the DOMAIN I mean:
Does not show: DOMAIN + ADS_USER only show ADS_USER
The same with wbinfo -g
Other think,...
2004 Nov 29
0
delay in winbindd user/group lookups with many users/groups in domain
....org/archive/samba-cvs/2004-November/052998.html
Would this help me? But then, what about a group cache?
Any hints to solve the above problem are _very_ appreciated!
Thanks in advance!
Regards, Walter
PS: No errors in the logfiles but this one in the winbind log:
"winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the
trust account password was changed and we didn't know it. Killing
connections to domain MY_DOMAIN"
Yet, 'wbinfo -t' succeeds.
I'm do not know if the error message is related to my problem above and
what is causing this (yet).
2005 Mar 03
1
OT: Is "Samba" an acronym?
...: ping
> | [2005/03/03 14:56:54, 3, pid=3736]
> | nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(465)
> | [ 6364]: pam auth crap domain: MPLC user: finchm
> | [2005/03/03 14:56:54, 3, pid=3736]
> | nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556)
> | winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED.
> | Maybe the trust account password was changed and we
> | didn't know it. Killing connections to domain MPLC
> | [2005/03/03 14:56:54, 3, pid=3736]
> | nsswitch/winbindd_cm.c:cm_get_ipc_userpass(109)
> | IPC$ connections done anonymously
> | [2...
2013 Apr 05
0
Struggling with Samba + AD member config (winbind auth failing) :(
...request returned ok.
[2013/04/06 01:04:00, 3] rpc_client/cli_pipe.c:rpc_pipe_bind(2085)
rpc_pipe_bind: Remote machine ULVDC01.Unilinedoo.local pipe \NETLOGON
fnum 0x1 bind request returned ok.
[2013/04/06 01:04:00, 3]
nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1841)
* winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust
account password was changed and we didn't know it. Killing connections to
domain UNILINEDOO*
[2013/04/06 01:04:00, 2]
nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1931)
* NTLM CRAP authentication for user [UNILINEDOO]\[ul67] returned
NT_STATUS_A...
2016 Nov 17
2
Unable to add AD users to local groups
On 11/17/2016 02:42 PM, Rowland Penny via samba wrote:
> On Thu, 17 Nov 2016 14:32:16 -0500
> Robert Martel via samba <samba at lists.samba.org> wrote:
>
>>
>> On 11/16/2016 04:34 PM, Rowland Penny via samba wrote:
>>> Provided that the group urbanweb exists in /etc/group and your users
>>> are shown by getent passwd or id, then you could try the unix