similar to: Anyone have account lockouts working on a Samba PDC?

Displaying 20 results from an estimated 300 matches similar to: "Anyone have account lockouts working on a Samba PDC?"

2017 Nov 07
1
'doveadm replicator remove' only temporary?
Hi folks, Wondering if this is expected behavior; we'd like to be able to pause replication for a particular account on our 2.2.32 active-active cluster, but delivering a message (LMTP) to the account seems to turn replication back on again: (replication on) server1:~# doveadm replicator status rgiles username priority fast sync full sync success sync
2018 Apr 16
2
How to change Domain password as normal user?
On Mon, 16 Apr 2018 14:12:02 -0400 Mark Foley via samba <samba at lists.samba.org> wrote: > Still having daily problems. Yesterday, again, I reset the user > password from the AD/DC as the domain administrator: samba-tool user > setpassword mark > > Today, I was unable to log in. The only message in the log.samba file > is: > > [2018/04/16 14:02:12.199145, > 2]
2018 Apr 14
2
How to change Domain password as normal user?
Need help on this. My account is locked out. Need way to reset. --Mark -----Original Message----- Date: Fri, 13 Apr 2018 14:49:44 -0400 Organization: Ohio Highway Patrol Retirement System To: samba at lists.samba.org Subject: Re: [Samba] How to change Domain password as normal user? On Thu, 5 Apr 2018 16:59:15 +0100 Rowland Penny <rpenny at samba.org> wrote: > > On Thu, 05 Apr 2018
2018 Mar 23
2
tracking account lockouts
Hi, I'm trying to track random account lockouts on the domain. Is there any recommendations for log level or log handling that let me see what machines/servers are locking the account? I'm using samba 4.5.5. as a DC (3 DCs). My current logging settings are: logging = syslog log level = 1 auth:5 passdb:5 winbind:5 Att, Vinicius
2018 Apr 09
1
Account lockouts caused by SAMBA + WinBind do not report "Caller Computer Name" in security audit
Hello all, We are troubleshooting an issue that when SAMBA is joined to a Windows domain controller as a member server that has password failure lockouts configured, the Windows security auditing does not show the "Caller Computer Name" in the event ID generated (4740). We are using Samba 4.6.2 from CentOS 7. We posted a Bugzilla at Red Hat here:
2019 Jan 18
3
NT_STATUS_ACCOUNT_LOCKED_OUT
I'm having a very annoying problem I can't figure out. I've been running Samba4 as our office AD/DC for several years. This is a recent problem. Whenever I Remote Desktop into a particular Windows workstation (192.168.0.4) I get the following message in /var/log/samba/log.samba: Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)]\[mark at HPRS] at [Thu, 17 Jan 2019
2019 Jan 19
2
NT_STATUS_ACCOUNT_LOCKED_OUT
On Sat, 19 Jan 2019 19:03:58 +0000 Rowland Penny wrote: > > On Sat, 19 Jan 2019 13:37:18 -0500 > Mark Foley via samba <samba at lists.samba.org> wrote: > > > I sure could use some help on this. Perhaps this problem is due to a > > recent Windows update? > > > > I have determined that whenever I log into the Windows 7 host > > DBSERVER from any
2008 Jan 17
2
samba 3.0.24 works - samba 3.0.25 fails
Folks: I've got several systems attached to a 2003 domain where we use kerberos to authenticate. When I upgraded a system to the latest greatest samba things stopped working. Just to find where it happened in the different versions of samba I downloaded, built, & ran 3.0.23d to 3.0.25c using the same smb.conf file. Turns out the 2.0.23d and 3.0.24 works but from 3.0.25 on it fails.
2018 Apr 05
2
How to change Domain password as normal user?
OK, I'm having issues with the problem. To summarize, I'm trying to have a normal user change his password from a domain member. I've tried: passwd, kpasswd and 'samba-tool user password -U $USER --ipaddress=<IPofAD/DC>'. All mechanisms do change the domain password and I can log into Windows and Linux domain members, and website requiring domain authentication.
2004 Jul 13
1
Enabling account lockouts
The release notes indicate support for bad password lockout policy starting with version 3.0.3 but I can't figure out how to enable it. I didn't see anything in the docs about turning it on. I also tried looking through all the options by using swat in advanced mode. How do I enable bad password lockout policy?
2005 Jun 27
0
Account lockouts
Using Samba 3.0.14a with multiple domain controllers across WAN links I discovered that account lockout policies are broke. My testing show's that account lockout policies are not stored in LDAP as one would think but in a local TDB file on that particular BDC or PDC. The result is I'm seeing errors in my logs and users are getting locked out. There appears to be no replication setup
2018 Mar 23
0
tracking account lockouts
On 3/23/2018 12:49 PM, Vinicius Bones Silva via samba wrote: > Hi, > > I'm trying to track random account lockouts on the domain. Is there > any recommendations for log level or log handling that let me see what > machines/servers are locking the account? > > I'm using samba 4.5.5. as a DC (3 DCs). > > My current logging settings are: > > logging = syslog
2006 Apr 18
1
How to map locked user Administrator in AD domain to guest ?
Hello I have Samba running as AD member. In addition there is a support of quest user connections to shares, that allow guest connections to shares, where access is restricted on IP addresses base. Problem is, that Administrator is not mapped to guest, because Administrator in AD domain is locked. Samba gets respond NT_STATUS_ACCOUNT_LOCKED_OUT and denies connection. While computers, that are
2018 Apr 13
2
How to change Domain password as normal user?
On Thu, 5 Apr 2018 16:59:15 +0100 Rowland Penny <rpenny at samba.org> wrote: > > On Thu, 05 Apr 2018 11:31:18 -0400 > Mark Foley via samba <samba at lists.samba.org> wrote: > > > OK, I'm having issues with the problem. To summarize, I'm trying to > > have a normal user change his password from a domain member. I've > > tried: passwd, kpasswd
2019 Jan 20
1
NT_STATUS_ACCOUNT_LOCKED_OUT
On Sat, 19 Jan 2019 16:26:21 -0500 Mark Foley via samba <samba at lists.samba.org> wrote: > On Sun, 20 Jan 2019 08:06:26 +1300 Andrew Bartlett wrote: > > > > On Sat, 2019-01-19 at 13:37 -0500, Mark Foley via samba wrote: > > > I sure could use some help on this.  Perhaps this problem is due > > > to a recent Windows update? > > >  > > >
2017 Dec 02
2
logline of account becoming NT_STATUS_ACCOUNT_LOCKED_OUT
Hi, I am trying to capture from the logs the moment that samba locks an account. (because of too many failed logon attempts) This is samba 4.7.2, with: > log level = 1 auth_audit:3 What we see in the logs is like this: > Auth: [LDAP,simple bind/TLS] user [(null)]\[cn=username,cn=users,dc=samba,dc=company,dc=com] at [Sat, 02 Dec 2017 15:13:45.102695 CET] with [Plaintext] status
2019 Aug 08
3
Problems joining Samba 4 in the domain
Hi, I have 2 DC in my network. DC master is a Samba 4 and the secondary is Windows Server 2008. I want to put another Samba 4 as DC to replace Windows Server, however the following errors are emerging: root at samba4-dc2:~# samba-tool domain join empresa.com.br DC -k yes -d 3 lpcfg_load: refreshing parameters from /etc/samba/smb.conf GENSEC backend 'gssapi_spnego' registered GENSEC
2000 Feb 09
0
Lockouts caused by Samba
This problem was somewhat irregular in the past, but is becoming a major nuisance now... On connecting a drive, users (all W95) have their NT domain accounts locked out. In the logs, I see things like: [2000/02/09 07:24:49, 1] smbd/password.c:(1131) password server <PDC> rejected the password [2000/02/09 07:24:49, 0] passdb/smbpass.c:(50) startsmbfilepwent: unable to open file
2008 May 14
1
windbind locks out domain account
Howdy folks, I'm having a weird issue here. I have winbind running on several other servers on our domain, and they are working fine. From what I can tell the configuration is identical, as I custom rolled my own RPM that set's all the config parameters. What's happening is when I try to ssh to this one specific server, it seems looking at the logs it's trying to continuously
2018 Apr 26
4
account locks not working ssh/winbind?
Hai.   Config. Debian Stretch, samba 4.7.7. member server AD backend. Network setup like in the howtos here. : https://github.com/thctlo/samba4/tree/master/howtos      Today i discovered that somehow a disabled user was able to login after a few retries.   I run a SSH/SFTP server for data exchange with the customer of the company here.   The SSH/SFTP server is restricted by groups, this