search for: sam_logon

Displaying 11 results from an estimated 11 matches for "sam_logon".

2016 Nov 02
1
winbind trust account password management
I'm running Samba v4.4.4 as a domain member server in security=domain mode. Our 3 domain controllers are Server 2012r2. Every 3-4 days, I see log messages from winbind saying "winbind_samlogon_retry_loop: sam_logon returned ACCESS_DENIED". Sometimes this corresponds to a trust password change, but not always. Today, new connections to Samba were failing with the error "SPNEGO(gse_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_INTERNAL_ERROR" for an hour. I restored service by re-running...
2005 Apr 04
4
NT_STATUS_ACCESS_DENIED with winbindd authentication
Hi, We're running a print server having the following specifications: Samba 3.0.11 Suse 9.1 Kernel 2.6.5-7.108 kernel A few days back none of the users were able to log onto the print server. The debug 10 logs show the following lines: [2005/03/29 11:21:05, 5] auth/auth.c:check_ntlm_password(271) check_ntlm_password: winbind authentication for user [**user-name**] FAILED with error
2005 Mar 03
3
winbindd reporting "killing connections to DOMAIN"
...nbindd_misc.c:winbindd_ping(238) [ 6364]: ping [2005/03/03 14:56:54, 3, pid=3736] nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(465) [ 6364]: pam auth crap domain: MPLC user: finchm [2005/03/03 14:56:54, 3, pid=3736] nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556) winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain MPLC [2005/03/03 14:56:54, 3, pid=3736] nsswitch/winbindd_cm.c:cm_get_ipc_userpass(109) IPC$ connections done anonymously [2005/03/03 14:56:54, 3, pid=3736] nsswitch/win...
2001 Nov 05
0
smbd cpu spin & Failed to marshall NET_R_SAM_LOGON
...es not seemed to have helped. This is a Solaris 2.6 environment. Every time the smbd goes into CPU spin, I notice the following things: a) truss -p on the process report nothing happening ie looks like internal loop not stuck on some system resource). b) there is a report that complains about sam_logon everytime I have checked loke the following (in log.smbd): [2001/11/05 08:36:26, 0, pid=16184, effective(60001, 60001), real(0, 0)] rpc_server/srv_netlog.c:api_net_sam_logon(208) api_net_sam_logon: Failed to marshall NET_R_SAM_LOGON. [2001/11/05 08:36:26, 0, pid=16184, effective(60001, 60001),...
2005 Mar 18
0
(no subject)
...000 milliseconds [2005/03/18 13:52:44, 3] nsswitch/winbindd_cm.c:connection_ok(703) Connection to for domain DOMAIN (pipe \PIPE\NETLOGON) has died or was never started (fd == -1) and [2005/03/17 14:26:26, 3] nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556) winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain DOMAIN Samba-3.0.11 AD Win2003
2006 Apr 26
1
Bad Password
...witch/winbindd_dual.c:child_process_request(359) process_request: request fn PAM_AUTH [2006/04/26 11:09:17, 3] nsswitch/winbindd_pam.c:winbindd_dual_pam_auth(252) [ 8465]: pam auth NA\trimblrd [2006/04/26 11:09:17, 3] nsswitch/winbindd_pam.c:winbindd_dual_pam_auth(400) winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain NA [2006/04/26 11:09:17, 8] nsswitch/winbindd_cm.c:connection_ok(806) Connection to USTR-NADC1 for domain NA has NULL cli! [2006/04/26 11:09:17, 3] nsswitch/winbindd_c...
2008 Jul 30
0
SAMBA + ADS + Kerberos Problem...
...e/parse_prs.c:prs_ntstatus(767) 001c status : NT_STATUS_ACCESS_DENIED [2008/07/30 17:01:32, 10] libsmb/credentials.c:creds_client_check(325) creds_client_check: credentials check OK. [2008/07/30 17:01:32, 3] nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1546) winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain DOMAIN When i do: wbinfo -u: Show the ADS user BUT not show the DOMAIN I mean: Does not show: DOMAIN + ADS_USER only show ADS_USER The same with wbinfo -g Other think,...
2004 Nov 29
0
delay in winbindd user/group lookups with many users/groups in domain
....org/archive/samba-cvs/2004-November/052998.html Would this help me? But then, what about a group cache? Any hints to solve the above problem are _very_ appreciated! Thanks in advance! Regards, Walter PS: No errors in the logfiles but this one in the winbind log: "winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain MY_DOMAIN" Yet, 'wbinfo -t' succeeds. I'm do not know if the error message is related to my problem above and what is causing this (yet).
2005 Mar 03
1
OT: Is "Samba" an acronym?
...: ping > | [2005/03/03 14:56:54, 3, pid=3736] > | nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(465) > | [ 6364]: pam auth crap domain: MPLC user: finchm > | [2005/03/03 14:56:54, 3, pid=3736] > | nsswitch/winbindd_pam.c:winbindd_pam_auth_crap(556) > | winbindd_pam_auth_crap: sam_logon returned ACCESS_DENIED. > | Maybe the trust account password was changed and we > | didn't know it. Killing connections to domain MPLC > | [2005/03/03 14:56:54, 3, pid=3736] > | nsswitch/winbindd_cm.c:cm_get_ipc_userpass(109) > | IPC$ connections done anonymously > | [2...
2013 Apr 05
0
Struggling with Samba + AD member config (winbind auth failing) :(
...request returned ok. [2013/04/06 01:04:00, 3] rpc_client/cli_pipe.c:rpc_pipe_bind(2085) rpc_pipe_bind: Remote machine ULVDC01.Unilinedoo.local pipe \NETLOGON fnum 0x1 bind request returned ok. [2013/04/06 01:04:00, 3] nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1841) * winbindd_pam_auth: sam_logon returned ACCESS_DENIED. Maybe the trust account password was changed and we didn't know it. Killing connections to domain UNILINEDOO* [2013/04/06 01:04:00, 2] nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(1931) * NTLM CRAP authentication for user [UNILINEDOO]\[ul67] returned NT_STATUS_A...
2016 Nov 17
2
Unable to add AD users to local groups
On 11/17/2016 02:42 PM, Rowland Penny via samba wrote: > On Thu, 17 Nov 2016 14:32:16 -0500 > Robert Martel via samba <samba at lists.samba.org> wrote: > >> >> On 11/16/2016 04:34 PM, Rowland Penny via samba wrote: >>> Provided that the group urbanweb exists in /etc/group and your users >>> are shown by getent passwd or id, then you could try the unix