search for: user_ok_token

Displaying 20 results from an estimated 41 matches for "user_ok_token".

2007 Apr 04
1
DFS not working from XP
...id=24840] smbd/reply.c:reply_tcon_and_X(668) Client requested device type [IPC] for share [IPC$] [2007/03/31 14:42:11.723922, 5, pid=24840] smbd/service.c:make_connection(1125) making a connection to 'normal' service ipc$ [2007/03/31 14:42:11.724292, 10, pid=24840] smbd/share_access.c:user_ok_token(229) user_ok_token: share IPC$ is ok for unix user tstewart <SNIP> [2007/03/31 14:42:12.369439, 5, pid=24846] smbd/uid.c:change_to_user(260) change_to_user uid=(0,1544) gid=(0,100) [2007/03/31 14:42:12.369711, 4, pid=24846] smbd/vfs.c:vfs_ChDir(741) vfs_ChDir to /tmp [2007/03/31 14:42:1...
2009 Apr 20
2
Getting mad with group permissions
...ec_ctx_stack_ndx = 0 [2009/04/20 11:06:59, 10] passdb/lookup_sid.c:lookup_name(69) lookup_name: Unix Group\staffmovi => Unix Group (domain), staffmovi (name) [2009/04/20 11:06:59, 10] passdb/lookup_sid.c:lookup_name(70) lookup_name: flags = 0x077 [2009/04/20 11:06:59, 10] smbd/share_access.c:user_ok_token(212) User giorgio not in 'valid users' [2009/04/20 11:06:59, 2] smbd/service.c:create_connection_server_info(659) user 'giorgio' (from session setup) not permitted to access this share (documenti_movi) [2009/04/20 11:13:15, 3] smbd/process.c:switch_message(1378) switch me...
2014 Apr 15
0
"Could not convert SID" error - different results for the same AD query
...20432, 10] auth/token_util.c:527(debug_unix_user_token) UNIX token of user 645 Primary group is 602 and contains 4 supplementary groups Group[ 0]: 605 Group[ 1]: 606 Group[ 2]: 608 Group[ 3]: 1222 Much further down the line we see: success: [2014/03/21 15:40:40.283134, 10] smbd/share_access.c:241(user_ok_token) user_ok_token: share cadshare is ok for unix user EXAMPLEAD\nagios failure: [2014/03/21 15:38:46.972158, 10] smbd/share_access.c:219(user_ok_token) User EXAMPLEAD\nagios not in 'valid users' SID S-1-5-21-3579304287-3829738268-3886208222-513 is GID 602, the 'domain users' group....
2016 Aug 31
0
Certain systems can no longer access samba post upgrade to 4.3.9
...8/31 08:00:40.641074, 10, pid=6463, effective(0, 0), real(0, 0)] ../source3/smbd/smb2_server.c:2018(smbd_smb2_request_dispatch) smbd_smb2_request_dispatch: opcode[SMB2_OP_CREATE] mid = 66899 [2016/08/31 08:00:40.641105, 10, pid=6463, effective(0, 0), real(0, 0)] ../source3/smbd/share_access.c:237(user_ok_token) user_ok_token: share (null) is ok for unix user DOMAIN\ish-prd-svc [2016/08/31 08:00:40.641123, 10, pid=6463, effective(0, 0), real(0, 0)] ../source3/smbd/share_access.c:284(is_share_read_only_for_token) is_share_read_only_for_user: share (null) is read-write for unix user DOMAIN\ish-prd-svc [...
2010 Apr 01
4
Printer Admin Difficulties
...st: list has non-ip address (127.) [2010/03/31 13:43:35, 3] lib/access.c:396(check_access) check_access: hostnames in host allow/deny list. [2010/03/31 13:43:35, 2] lib/access.c:406(check_access) Allowed connection from 127.0.0.1 (127.0.0.1) [2010/03/31 13:43:35, 10] smbd/share_access.c:234(user_ok_token) user_ok_token: share ZZZ is ok for unix user adminuser [2010/03/31 13:43:35, 4] rpc_server/srv_spoolss_nt.c:1726(_spoolss_OpenPrinterEx) Setting printer access = PRINTER_ACCESS_ADMINISTER [2010/03/31 13:43:35, 1] ../librpc/ndr/ndr.c:251(ndr_print_function_debug) spoolss_OpenPrinte...
2007 Dec 12
2
Vista SP1-rc1 appears to break against Samba-3.0.27a
...00:25:16, 5] smbd/password.c:user_in_netgroup(466) looking for user ad\myaccount of domain (ANY) in netgroup ad\some group [2007/12/12 00:25:16, 10] passdb/lookup_sid.c:lookup_name(64) lookup_name: ad\some group => ad (domain), some group (name) [2007/12/12 00:25:16, 10] smbd/share_access.c:user_ok_token(232) user_ok_token: share test is ok for unix user AD\myaccount ..whereas Vista-SP1rc1 shows [2007/12/12 00:20:42, 10] libsmb/clikrb5.c:get_krb5_smb_session_key(735) Got KRB5 session key of length 16 [2007/12/12 00:20:42, 10] libsmb/clikrb5.c:unwrap_pac(292) authorization data is not...
2020 Jun 05
3
It seems to have bug for @group to set in valid or invalid conf
...[2020/06/05 16:40:40.672789, 10, pid=2781, effective(0, 0), real(0, 0)] ../../source3/smbd/service.c:70(set_conn_connectpath) set_conn_connectpath: service IPC$, connectpath = /tmpfs/tmp [2020/06/05 16:40:40.672815, 10, pid=2781, effective(0, 0), real(0, 0)] ../../source3/smbd/share_access.c:220(user_ok_token) user_ok_token: share IPC$ is ok for unix user bbb [2020/06/05 16:40:40.672840, 10, pid=2781, effective(0, 0), real(0, 0)] ../../source3/smbd/share_access.c:271(is_share_read_only is_share_read_only_for_user: share IPC$ is read-only for unix user bbb [2020/06/05 16:40:40.672868, 10, pid=2781, e...
2013 Jan 11
0
werr_access_denied when running setdriver for a printer
...r others, while all the printers have the same settings. Samba 3.5.20 with CUPS 1.5.4. Does this part of log give any clue of why could this happen? function print_access_check() -- where does it take its data to check for printer access? [2013/01/11 15:57:10.794623, 10] smbd/share_access.c:238(user_ok_token) user_ok_token: share myprinter1 is ok for unix user korobkin [2013/01/11 15:57:10.794666, 10] lib/util_seaccess.c:58(se_map_generic) se_map_generic(): mapped mask 0x20020008 to 0x00020008 [2013/01/11 15:57:10.794701, 10] lib/util_seaccess.c:58(se_map_generic) se_map_generic(): mapped mask 0x...
2007 Jan 25
1
domain/unix groups and valid users parameter
Hi, I want to switch from 'security = server' to 'security = ADS'. Kerberos is working and I can login to the server. With Samba 3.0.22 I was able to restrict access to shares with the 'valid users' directive. ve is local unix group. valid users = +ve And force the group ownership with the 'force group' directive. force group = +ve [foo] comment = foo
2007 Feb 04
3
Samba-3.0.23 problem
...L) [2007/02/04 12:43:17, 5] auth/auth_util.c:debug_unix_user_token(474) UNIX token of user 0 Primary group is 0 and contains 0 supplementary groups [2007/02/04 12:43:17, 3] smbd/sec_ctx.c:pop_sec_ctx(339) pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0 [2007/02/04 12:43:17, 10] smbd/share_access.c:user_ok_token(208) User mikes not in 'valid users' [2007/02/04 12:43:17, 2] smbd/service.c:make_connection_snum(580) user 'mikes' (from session setup) not permitted to access this share (exec_share) [2007/02/04 12:43:17, 3] smbd/error.c:error_packet(146) error packet at smbd/reply.c(676) cm...
2007 Dec 12
1
vfs_ChDir fails, even though the share is read-write for that user
...et to: [arrakis] path = "/export/arrakis" comment = "Arraken Test share" writeable = yes valid users = @"UIUC+domain users" vfs objects = zfsacl nfs4: mode = special The logs will spit out: [2007/12/12 10:09:17, 10] smbd/share_access.c:(232) user_ok_token: share arrakis is ok for unix user UIUC+vanhoudn [2007/12/12 10:09:17, 10] smbd/share_access.c:(274) is_share_read_only_for_user: share arrakis is read-write for unix user UIUC+vanhoudn Which is good. And, we can see that samba is correctly finding all of the groups that this user is a member of...
2020 Oct 16
1
azure ad provisioning | password hashes sync
...: NULL > [2020/10/16 13:43:47.320250, 3, pid=25360, effective(0, 0), real(0, 0)] ../../lib/util/access.c:371(allow_access) > Allowed connection from 192.x.y.z (192.x.y.z) > [2020/10/16 13:43:47.320326, 10, pid=25360, effective(0, 0), real(0, 0)] ../../source3/smbd/share_access.c:238(user_ok_token) > user_ok_token: share IPC$ is ok for unix user DOM\azuresyncadm > [2020/10/16 13:43:47.320412, 10, pid=25360, effective(0, 0), real(0, 0)] ../../source3/smbd/service.c:70(set_conn_connectpath) > set_conn_connectpath: service IPC$, connectpath = /tmp > [2020/10/16 13:43:47.320472,...
2020 Mar 08
2
Trouble resolving some group membership after upgrade from 4.8 to 4.10
...try found for group: 10002 [2020/03/09 10:30:41.753202, 4, pid=2475, effective(0, 0), real(0, 0)] ../../source3/smbd/sec_ctx.c:438(pop_sec_ctx) pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0 [2020/03/09 10:30:41.753262, 10, pid=2475, effective(0, 0), real(0, 0)] ../../source3/smbd/share_access.c:213(user_ok_token) User sambamatt not in 'valid users' If I show the group membership in other ways it appears like sambamatt is a member: $ getent passwd sambamatt sambamatt:*:10103:513:System User:/home/sambamatt:/bin/sh $ getent group Home Home:*:10002:sambamatt $ id sambamatt uid=10...
2008 Apr 16
1
valid users = +group doesn't work
...L) [2008/04/16 15:09:07, 5] auth/auth_util.c:debug_unix_user_token(474) UNIX token of user 0 Primary group is 0 and contains 0 supplementary groups [2008/04/16 15:09:07, 3] smbd/sec_ctx.c:pop_sec_ctx(356) pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0 [2008/04/16 15:09:07, 10] smbd/share_access.c:user_ok_token(211) User lz not in 'valid users' [2008/04/16 15:09:07, 2] smbd/service.c:make_connection_snum(616) user 'lz' (from session setup) not permitted to access this share (www) Interestingly, if I specify valid users = +DOMAIN\windows_group, it works. Maybe I need to configure some...
2012 Jan 04
1
Samba 3.4 authentication suddenly very slow.
After a scheduled power outage, with all hosts cleanly shut down, I'm having a bad performance issue on my samba server. This configuration has worked well for over a year, but after the power outage, attempting to access any share takes over a minute. net ads testjoin is fine, wbinfo -u and wbinfo -g returns the correct information. The shares CAN be accessed, once accessed, read and write
2020 Oct 15
2
azure ad provisioning | password hashes sync
Hi, Reading the microsoft troubleshooting guide, it seems that password hash sync issues can be caused by: > The Active Directory account used by Azure AD Connect to communicate > with on-premises Active Directory is not granted Replicate Directory > Changes and Replicate Directory Changes All permissions, which are > required for password synchronization. How to verify existance or
2015 Jul 31
1
samba-4.1.19: resolving local unix group failes when there exists a local unix user with same name
...2-SUSE-oS13.2-x86_64] tree connect failed: NT_STATUS_NO_SUCH_GROUP Running smbd interactive with maximum debug level shows the following lines: looking for user fee\reinhard.ni of domain (ANY) in netgroup fee\g_tb3 lookup_name: fee\g_tb3 => domain=[fee], name=[g_tb3] lookup_name: flags = 0x077 user_ok_token: share FactWork is ok for unix user FEE\reinhard.ni lookup_name: FEE\webadmin => domain=[FEE], name=[webadmin] lookup_name: flags = 0x077 map_name_to_wellknown_sid: looking up webadmin push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1 push_conn_ctx(0) : conn_ctx_stack_ndx = 0 setting sec ctx (0, 0) - s...
2020 Jun 13
0
It seems to have bug for @group to set in valid or invalid conf
...0.672789, 10, pid=2781, effective(0, 0), real(0, 0)] > ../../source3/smbd/service.c:70(set_conn_connectpath) > set_conn_connectpath: service IPC$, connectpath = /tmpfs/tmp > [2020/06/05 16:40:40.672815, 10, pid=2781, effective(0, 0), real(0, 0)] > ../../source3/smbd/share_access.c:220(user_ok_token) > user_ok_token: share IPC$ is ok for unix user bbb > [2020/06/05 16:40:40.672840, 10, pid=2781, effective(0, 0), real(0, 0)] > ../../source3/smbd/share_access.c:271(is_share_read_only > is_share_read_only_for_user: share IPC$ is read-only for unix user bbb > [2020/06/05 16:40:4...
2016 Aug 30
2
Certain systems can no longer access samba post upgrade to 4.3.9
On Mon, Aug 29, 2016 at 6:13 PM, Jeremy Allison <jra at samba.org> wrote: > On Mon, Aug 29, 2016 at 11:41:53AM -0400, Jeff Hodge via samba wrote: > > During an ubuntu 14.04 update samba was updated from 4.1.6 to 4.3.9. We > > had no problems with any windows system accessing the server prior to the > > upgrade to 4.3.9. It seems to affect access to the entire samba
2007 Jan 10
1
ADS groups and 'valid users'
...ng [2007/01/10 14:52:43, 3] lib/util_sid.c:string_to_sid(223) string_to_sid: Sid +FOO+finance does not start with 'S-'. [2007/01/10 14:52:43, 10] passdb/lookup_sid.c:lookup_name(64) lookup_name: FOO\finance => FOO (domain), finance (name) [2007/01/10 14:52:43, 10] smbd/share_access.c:user_ok_token(208) User MAGAZINES+cwatson not in 'valid users' [2007/01/10 14:52:43, 2] smbd/service.c:make_connection_snum(580) user 'MAGAZINES+cwatson' (from session setup) not permitted to access this share (accounting) It doesn't seem to be checking if MAGAZINES\cwatson is even in a...