Displaying 18 results from an estimated 18 matches for "werr_no_logon_serv".
2019 Feb 27
4
status on samba trusts
...ted encryption types on local TDO.
>> Validating outgoing trust...
>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
>> Validating incoming trust...
>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
>
>> root at testad2dc:/var/log/samba# samba-tool domain trust validate testad1
>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
>> SID[S-1-5-21-1012147493-3366197983-1829854343]
>> LocalTDO Netbios...
2014 Oct 09
3
Samba4 as BDC on a Win2003 AD_PDC
...request"
This is the output on log.samba when I try to create or modify an user by RSAT connected on Samba 4
[2014/10/09 09:36:29.901189, 0] ../source4/dsdb/repl/drepl_ridalloc.c:43(drepl_new_rid_pool_callback)
../source4/dsdb/repl/drepl_ridalloc.c:43: RID Manager failed RID allocation - WERR_NO_LOGON_SERVERS - extended_ret[0x0]
And, this message is output on log.samba all the time:
[2014/10/09 09:37:00.527471, 0] ../source4/librpc/rpc/dcerpc_util.c:681(dcerpc_pipe_auth_recv)
Failed to bind to uuid e3514235-4b06-11d1-ab04-00c04fc2dcd2 for e3514235-4b06-11d1-ab04-00c04fc2dcd2 at ncacn_ip_tcp:e50...
2019 Feb 21
2
status on samba trusts
Hi,
Having read the release notes on the status of trusts within samba, we
see for 4.9
> "improved support for trusted domains"
but we also always see these messages:
> "Both sides of the trust need to fully trust each other!"
and
> "DCs of domain A can grant domain admin rights in domain B"
What we would like to achieve is a one-way incoming trust
2019 Jul 19
0
replication stuck?
...t of each type):
==== INBOUND NEIGHBORS ====
DC=DomainDnsZones,DC=samba,DC=lindenberg,DC=one
Default-First-Site-Name\BOA via RPC
DSA object GUID: a0c6a86f-61da-4b05-8510-5d7af2cc34b7
Last attempt @ Fri Jul 19 16:46:13 2019 CEST failed, result 1311 (WERR_NO_LOGON_SERVERS)
709 consecutive failure(s).
Last success @ NTTIME(0)
?
==== OUTBOUND NEIGHBORS ====
DC=DomainDnsZones,DC=samba,DC=lindenberg,DC=one
Default-First-Site-Name\BOA via RPC
DSA object GUID: a0c6a86f-61da-4b05-8510-5d7af2cc34b7...
2024 Jan 06
0
Problem create trust between Samba AD and MS Windows AD.
...=both --create-location=both -U truster at ADWIN.LOC
Trust is built, but a validation error occurs.
Validating outgoing trust...
OK: LocalValidation: DC[\\dc01.adwin.loc] CONNECTION[WERR_OK]
TRUST[WERR_OK] VERIFY_STATUS_RETURNED
Validating incoming trust...
ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
As a result, on PC entered into the SMBUB.TEST, you can login with an
account from the ADWIN.LOC, but on PC entered into the ADWIN.LO it's
impossible to login with a user from the SMBUB.TEST domain.
I'm installed updates in the ADWIN...
2024 Jan 19
0
Problem create trust between Samba AD and MS Windows AD.
...=both --create-location=both -U truster at ADWIN.LOC
Trust is built, but a validation error occurs.
Validating outgoing trust...
OK: LocalValidation: DC[\\dc01.adwin.loc] CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED Validating incoming trust...
ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS] TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
As a result, on PC entered into the SMBUB.TEST, you can login with an account from the ADWIN.LOC, but on PC entered into the ADWIN.LO it's impossible to login with a user from the SMBUB.TEST domain.
I'm installed updates in the ADWIN...
2019 Jul 20
2
replication stuck?
...t of each type):
==== INBOUND NEIGHBORS ====
DC=DomainDnsZones,DC=samba,DC=lindenberg,DC=one
Default-First-Site-Name\BOA via RPC
DSA object GUID: a0c6a86f-61da-4b05-8510-5d7af2cc34b7
Last attempt @ Fri Jul 19 16:46:13 2019 CEST failed, result 1311 (WERR_NO_LOGON_SERVERS)
709 consecutive failure(s).
Last success @ NTTIME(0)
?
==== OUTBOUND NEIGHBORS ====
DC=DomainDnsZones,DC=samba,DC=lindenberg,DC=one
Default-First-Site-Name\BOA via RPC
DSA object GUID: a0c6a86f-61da-4b05-8510-5d7af2cc34b7...
2019 Feb 26
0
status on samba trusts
...eated
> Setting supported encryption types on local TDO.
> Validating outgoing trust...
> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com] CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
> Validating incoming trust...
> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS] TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
> root at testad2dc:/var/log/samba# samba-tool domain trust validate testad1
> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com] SID[S-1-5-21-1012147493-3366197983-1829854343]
> LocalTDO Netbios[TESTAD1] DNS[testad1.company.com]...
2019 Feb 28
2
status on samba trusts
...dating outgoing trust...
>>>>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
>>>>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
>>>>> Validating incoming trust...
>>>>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
>>>>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
>>>>
>>>>> root at testad2dc:/var/log/samba# samba-tool domain trust
>> validate testad1
>>>>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
>>>>> SID[...
2019 Feb 28
0
status on samba trusts
...on local TDO.
>>> Validating outgoing trust...
>>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
>>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
>>> Validating incoming trust...
>>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
>>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
>>
>>> root at testad2dc:/var/log/samba# samba-tool domain trust validate testad1
>>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
>>> SID[S-1-5-21-1012147493-3366197983-1829854343]
>&g...
2023 Jan 08
2
Issues demoting a samba DC.
...ut that one reports successful
replication, while this one (svdcm) shows errors in replication:
==== INBOUND NEIGHBORS ====
DC=tls,DC=msk,DC=ru
Pereslavl-Office\SVDCP via RPC
DSA object GUID: 4b38bf02-0354-44f7-b1b2-4bc8bd73784a
Last attempt @ Sun Jan 8 17:15:55 2023 MSK failed, result 1311 (WERR_NO_LOGON_SERVERS)
12 consecutive failure(s).
Last success @ Sun Jan 8 16:22:13 2023 MSK
I'm not sure this is how things are supposed to be... :)
Thanks!
/mjt
2019 Feb 28
0
status on samba trusts
...gt;> Validating outgoing trust...
> >>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
> >>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
> >>> Validating incoming trust...
> >>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
> >>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
> >>
> >>> root at testad2dc:/var/log/samba# samba-tool domain trust
> validate testad1
> >>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
> >>> SID[S-1-5-21-101214749...
2019 Feb 28
2
status on samba trusts
...gt;>> Validating outgoing trust...
>>>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
>>>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
>>>> Validating incoming trust...
>>>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
>>>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
>>>
>>>> root at testad2dc:/var/log/samba# samba-tool domain trust validate
>>>> testad1
>>>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
>>>> SID[S-1-5-21-1...
2019 Mar 05
0
status on samba trusts
...trust...
>>>>>> OK: LocalValidation: DC[\\WIN-0ENAIPFH11A.testad1.company.com]
>>>>>> CONNECTION[WERR_OK] TRUST[WERR_OK] VERIFY_STATUS_RETURNED
>>>>>> Validating incoming trust...
>>>>>> ERROR: RemoteValidation: DC[] CONNECTION[WERR_NO_LOGON_SERVERS]
>>>>>> TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED
>>>>>
>>>>>> root at testad2dc:/var/log/samba# samba-tool domain trust
>>> validate testad1
>>>>>> LocalDomain Netbios[TESTAD2] DNS[testad2.company.com]
>&...
2019 Oct 15
3
Problem with SPNEGO on full trust 2016 DC <> Samba 4.10.7 AD
...n resolve both DNS domains forwards and backwards and I am able to connect a Windows 10 client to the Samba domain without any issues. The problem occurs when create a full external trust between the two domains. The trust is created successfully with samba-tool however the verify fails with TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED.
The end result is a trust relation that fully works with Kerberos authentication (such as logging in on the trusted domain from a domain connected to the other) but this won't work with NTLM authentication outside of it's realm. I am constantly getting this erro...
2023 Jan 08
1
Issues demoting a samba DC.
On 08/01/2023 11:04, Michael Tokarev via samba wrote:
> Hello!
>
> I'm trying to remove a DC from our samba domain (samba 4.17.4).
> It was the primary controller (with FSMO roles), - I successfully
> transferred the roles to another DC.? Now it's time to demote:
>
> ai# samba-tool domain demote -U mjt-adm
> Using svdcp.tls.msk.ru as partner server for the
2019 Oct 15
0
Problem with SPNEGO on full trust 2016 DC <> Samba 4.10.7 AD
...n resolve both DNS domains forwards and backwards and I am able to connect a Windows 10 client to the Samba domain without any issues. The problem occurs when create a full external trust between the two domains. The trust is created successfully with samba-tool however the verify fails with TRUST[WERR_NO_LOGON_SERVERS] VERIFY_STATUS_RETURNED.
>
> The end result is a trust relation that fully works with Kerberos authentication (such as logging in on the trusted domain from a domain connected to the other) but this won't work with NTLM authentication outside of it's realm. I am constantly getting...
2023 Jan 08
1
Issues demoting a samba DC.
...one (svdcm) shows errors in replication:
>
> ==== INBOUND NEIGHBORS ====
> DC=tls,DC=msk,DC=ru
> ????Pereslavl-Office\SVDCP via RPC
> ??????? DSA object GUID: 4b38bf02-0354-44f7-b1b2-4bc8bd73784a
> ??????? Last attempt @ Sun Jan? 8 17:15:55 2023 MSK failed, result 1311
> (WERR_NO_LOGON_SERVERS)
> ??????? 12 consecutive failure(s).
> ??????? Last success @ Sun Jan? 8 16:22:13 2023 MSK
>
> I'm not sure this is how things are supposed to be... :)
It isn't, but it may work if you can fix the UUID dns record, if not, we
will cross that bridge when we come to it ;-)...