Displaying 20 results from an estimated 1000 matches similar to: "-failed to verify ticket-, smb-3.0.7, mit krb5 1.3.1"
2004 Oct 26
0
xpsp2 clients authenticate, W2ksp4 clients must use IP or FQDN
Hi,
I have an interesting issue. I?m running a redhat 9 box with samba 3.0.7,
and Kerberos 1.3.1. I?ve joined the machine to the AD2k3 domain, and all
the informational commands respond as expected, getent's, wbinfo ?g ?t,
and net ads*** and also 'smbclient -k //otherdomainserver/share' works as
it should from the server's terminal.
when connecting to the server with a windows
2004 Oct 14
0
Getting errors while running Samba 3.0.7 with ADS security mode under MIT Kerberos
Hi,
I compiled Samba 3.0.7, MIT Kerberos 1.3.5 and OpenLDAP 2.2.17. I did not
notice any errors during compilation. I searched and found the #define
HAVE_LDAP 1 and #define HAVE_KRB5 1 statements in the config.h file of Samba
3.0.7's include dir. So, ADS should be supported in the compiled Samba 3.0.7
version.
Here is what I did up to now. As described in the How-To Samba doc, I
created
2004 Dec 06
0
Advanced server config question
Greetings,
I have an advanced config question that I'm hoping the Samba Gods can
help me with in regards to feasibility and execution. I'll give the
concept of what I want to do, followed by the details of my present
config.
I have a functioning samba 3.0.8pre2 server that is multihomed. The
100Mb line is attached to our main network. the 1Gb line is attached to
a private 1Gb lan
2004 Mar 30
0
samba 3.0.2a domain member in Windows 2003 domain and MIT 1.3.2
We recently switched our win2k domain to a native mode. We upgraded our
Solaris 9 samba server from 2.2.8 to version 3.0.2a and configured MIT
Kerberos version 1.3.2
I was able to join to machine as a domain member without any problems:
./net ads join -U moshe
moshe password:
[2004/03/30 13:26:46, 0] libads/ldap.c:ads_add_machine_acct(1006)
Host account for shark already exists - modifying old
2005 Oct 31
1
Samba 3.0.20b in ADS mode with MIT realm trust problems
Hi all,
We're having some issues getting Samba to work in the way we'd like it
to in our domain infrastructure.
We have a real Windows domain WIN (WIN.DOC.IC.AC.UK) which is run on
Windows 2003 domain controllers. We also have an MIT Kerberos realm
DOC.IC.AC.UK. A realm trust exists such that WIN.DOC.IC.AC.UK trusts
DOC.IC.AC.UK for authentication, and users have appropriate Kerberos
2005 Nov 23
1
ADS mode / MIT realm trust problem (3.0.20b)
Hi,
A final repost of the below issue -- we still are not making any
progress. It is unclear whether we need to be using winbind -- I don't
believe so, and the Terpstra Samba 3 book doesn't suggest that this is
necessary in this configuration; but please correct me if my
preconception is flawed.
If this is the 'wrong place' to ask -- any suggestions about where I
should be
2013 Aug 19
0
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE
Hi.
I we are migrating form domain ad.adc.com to ad.xyz.com , there is a trust
between the two domains.
Before the move the file server was work perfectly, post migration I get
the following in the samba logs
[2013/08/19 08:07:15.961679, 1] smbd/sesssetup.c:342(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2013/08/19 08:07:25.983662, 1]
2004 Aug 25
2
Upgrade from samba 3.0.4 to 3.0.6 broke file sharing
system is redhat 9 on a dell power edge 2450 running latest krb5 and
openldap rpm
It worked perfectly on 3.0.4 but arcserve wouldn't back up so I upgraded
to 306 and everything installed correctly but now when you try and
connect to the server it pops the user login box up. I can run net ads
user -U Administrator and log in with my admin password and it lists all
my user accounts. I can add
2005 Aug 31
0
Authenticating against AD not working
Hi,
We have a Windows 2000 domain controller using active directory. I would like to authenticate users against it, but it's not working. I've been trying for 2 weeks without much luck. Any (and I do mean ANY) help would be greatly appreciated.
My linux box: Linux cptapp01 2.6.10-5-386 #1 Tue Apr 5 12:12:40 UTC 2005 i686 GNU/Linux (Ubuntu)
My samba: Version 3.0.20
My smb.conf:
[global]
2005 May 25
0
Trouble with access permissions from W2K client to Samba 3.0.2 server
Greetings,
I'm using Samba (3.0.2) on debian sarge as a file server for W2K
clients. I'm having problems with one user in particular. The user can
connect to a share, but has no write access. On the Unix side of the
world, he has full write access.
Attached are the relevant portions of the log file and my smb.conf file.
Other details:
The domain controller is W2K ADS. I have several
2005 Feb 25
0
Problems using ADS to validate Windows Network users on a Samba3 Member Server
Dear All:
I made a change to my Samba configuration to enable Solaris ACLs in my
Installation of Samba 3.0.11. After then, I lost the ability to permit
domain users to browse the shares.
The server is running Solaris 8 2/04, and Samba is bound against MIT
Kerberos 1.4 and OpenLDAP 2.2.23. It authenticates to two Windows 2000
DCs. I had obtained a Kerberos ticket from the Domain Controllers,
2003 Nov 19
1
Samba 3.0 client connection error
Hi
I successfully joined the AD as member server, smbclient
\\\\hostname\\homes -U username works,
but on a windows 2000 client connecting to the homes share using \\hostname
failes with
[2003/11/13 16:39:46, 1] smbd/sesssetup.c:reply_spnego_kerberos(172)
Failed to verify incoming ticket!
[2003/11/13 16:39:46, 1] smbd/sesssetup.c:reply_spnego_kerberos(172)
Failed to verify incoming ticket!
2004 Dec 14
1
Winbind separator char causing make_server_info_from_pw failed errors
Hi all-
In migrating from 3.0.2 to 3.0.8 on a box that's an ADS domain member, I
had a relic line in smb.conf like this:
winbind separator char = -
With 3.0.2, users connecting wouldn't have a domain and separator char
component, so spnego kerberos replies to the 2003 domain controller
would be fine.
In 3.0.8, users connections would have the domain and separator char
for spnego
2005 Aug 30
0
Help with ADS authentication from Windoze
Here is my situation:
I have an AIX 4.3.3 machine, that I have compiled open-ldap, kerberos5
(1.3..6), and Samba 3.0.20.
Here is my smb.conf file:
[global]
realm = REGION.DOMAIN.COM
security = ADS
password server = randomdc.region.domain.com
workgroup = REGION
client use spnego = yes
;winbind separator = \
[homes]
comment = Home Directories
read only = no
create mode = 0750
2007 Jun 27
1
rfc2307 - 3.0.24
I'm running samba 3.0.24 (the latest package that seems to be available for
Ubuntu 7). I have a Windows 2003 AD with the R2/RFC2307 schema loaded. I
would prefer to use the 3.0.24 package if possible unless there is an ubuntu
package for 3.0.25. Any suggestions would be appreciated.
Wbinfo -u and -g appear to work great. Net ads testjoin comes back
successful.
In log.winbindd-idmap I get
2005 Oct 31
0
Session setup with machine account
Hi,
Our Samba Servers are getting slower and slower. Even opening the
context menu on some files take 5 seconds. My log file is filled up with
messages like:
nsaction 909 of length 1454
[2005/10/31 12:58:04, 3] smbd/process.c:switch_message(886)
switch message SMBsesssetupX (pid 24227) conn 0x0
[2005/10/31 12:58:04, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) -
2006 Feb 14
0
Problem cooperating with Windows and AD
Hi,
I'm having a problem getting my Windows machines to access shares in
Samba. When they browse to the Samba box it sometimes gives them an
error saying that they don't have permission or that the server is
unavailable. However this doesn't always happen and other times it lists
the shares. When I try to access the shares it just prompts for the
username/password over and over.
2010 Dec 20
4
problem connecting DFS-share with winXP - successful with Vista & 7
Hi,
i have problems connecting to DFS-Share from Client WindowsXP. Same
configuration works fine for Windows Vista and 7. On Windows 7 the
LMCompatibility Level is 3.
the striking point I see in logfile is following
2010/12/20 10:30:17, 1] smbd/service.c:make_connection_snum(1119)
10.184.144.171 (10.184.144.171) signed connect to service applbin
initially as user useracc
2004 Oct 08
0
(retry) 3.0.7: 'map to guest' incomplete behavior
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
(my first attempt got mangled because of the attachments, so I'm
reposting)
I have a 3.0.7 server that is part of an active directory domain, and I
have a problem where 'map to guest = Bad User' doesn't do what I expect.
On this system, unix users are a subset of AD users. Those users who
have accounts on both unix and AD can
2004 Oct 08
0
(retry) 3.0.7: username map doesn't work with security=ADS
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
(OK, my first message got mangled because of the attachments, so I'm
reposting)
I've got a samba 3 box that's part of an AD domain. It works correctly
for most users; but there was a problem where certain users couldn't
connect. We'd get a log message that looks like this:
Username SAMPLE.COM\pcuser is invalid on this system