Displaying 20 results from an estimated 2000 matches similar to: "pam_winbind + password never expires"
2007 Jan 08
0
pam_winbind + password never expires [re-post]
Sorry for the repost, but I've not gotten any response and the problem
persists. Does anyone have any idea how to fix?
===================================
I read a few posts in the archives about this problem and that it was to
be fixed in 3.0.23c. Currently I'm running 3.0.23d-2+b1 on a debian
system and am getting the following:
$ ssh -l testuser fileserver
Password:
Your password
2009 May 01
2
pam_winbind: user needs new password
Hi,
I just upgraded from Mandriva 2009.0 (Samba 3.2.3) to Mandriva 2009.1
(Samba 3.3.2), keeping all the same config files I had before. I use
pam_winbind to authenticate users against MS Active Directory.
Everything was working perfectly prior to the upgrade, and now
everything seems to be fine except for one thing: no user can have
access due to the following errors (taken from auth.log):
May
2006 Aug 15
3
pam_winbind says I need new password
Hello all,
I have a pretty large DC and am using winbind for our linux workstations and
im having a preculiar issue. Not all accounts but some...including mine are
recieving the pam error to change password.
example...
...
WARNING: Your password has expired.
You must change your password now and login again!
Changing password for user msellers.
Changing password for msellers
(current) NT
2006 Aug 01
2
[HELP] Samba 3.0.23a pam_winbind says password expired
hi,
i just do some tests with a fresh compiled samba 3.0.23a.
trying to authenticate against PAM with pam_winbind gives:
Aug 1 09:59:21 humevo36 pam_winbind[27853]: pam_winbind:
pam_sm_authenticate (flags: 0x0000)
Aug 1 09:59:23 humevo36 pam_winbind[27853]: Verify user `gasch'
Aug 1 09:59:23 humevo36 pam_winbind[27853]: enabling cached login flag
Aug 1 09:59:23 humevo36
2006 Feb 01
0
SAMBA 3.0.21b expired password issue for Solaris 9 - perhaps a bug in winbind or /etc/pam.conf misconfigure
All,
The SAMBA version 3.0.21b expired password pam_winbind.so section
perhaps might still have an issue. It seems to just be in some kind of
loop and
never completes the section in pam_winbind.c of pam_sm_chauthtok.
See ssh (Solaris 4.2.p1 ssh) sequence below:
ssh hermione
Password:
Changing password for leeraym
(current) NT password:
Re-enter new Password:
Password:
Password:
2008 Jan 20
1
winbind forced password change requires interactive shell
We've discovered that although Winbind supports password changes when the
account password is expired, this only works with *interactive* shells.
This is a major problem for us. Use case 1: SSH tunnels:
$ ssh user2@localhost -N -L 4711:localhost:22
user2@localhost's password:
<trying to use the tunnel>
channel 2: open failed: administratively prohibited: open failed
As you can
2011 Jul 01
2
Problems with BDC authentication
Today we had a problem with our Win NT4 PDC and discovered numerous
failover issues with our Samba file server.
For starters, this is a Debian Etch machine running Samba-3.0.24-2. At
this point, this is a critical production machine. Upgrading is on our
to-do path, but is not an option for an immediate fix to this problem.
With the exception of this problem, this Samba installation has been
2006 Aug 09
1
pam_winbind fails with "never expires" password
I'm helping a school district set up Samba for staff/student shares. The
PDC/BDCs are running NT4. Samba is v 3.0.23a on Fedora Core 5
boxes. winbind is mapping the users. Access to shares through Windows
clients or smbclient works perfectly.
There is a desire to have some faculty access the server using, e.g., an
ssh client (mostly for remote file access). When I try to log in
2006 Oct 30
0
Followup re: pam_winbind and "never expires" passwords
More info on the problem that users could access shares, but not login,
if their passwords were "expired" by days, but had "password never
expires" flagged.
During further experimentation, I discovered (I'm not a Windows person)
that in addition to flagging a user as "password never expires", there
is an account policy flag specifying the same thing globally.
2009 Jun 24
0
winbind authentication mystery
Greetings,
I'm running Fedora 11 (Samba 3.3.2) and am trying to configure winbind
authentication against a Windows 2003 server.
I've run kinit and net join successfully, and can wbinfo -u, -g, and -t
successfully, as well as getent passwd and getent group successfully. I
can even use passwd to change domain user passwords.
However, when I try to log in via gdm, ssh, or even su, I do not
2009 Dec 31
0
winbind authentication mystery
Hi Chris,
Were you able to solve this.
Regards,
David.
Greetings,
I'm running Fedora 11 (Samba 3.3.2) and am trying to configure winbind
authentication against a Windows 2003 server.
I've run kinit and net join successfully, and can wbinfo -u, -g, and -t
successfully, as well as getent passwd and getent group successfully. I
can even use passwd to change domain user passwords.
However,
2019 May 02
2
Possibly WERR_DS_DRA_ACCESS_DENIED or NT_STATUS_CANT_ACCESS_DOMAIN_INFO
Thank you for the quick response:
root at DC2:~# rm -rf /etc/samba/smb.conf
root at dc2:~# ll /etc/samba/ [The lmhosts file I created trying to
troubleshoot: touch /etc/samba/lmhosts. It hasn't been touched.]
total 52
drwxr-xr-x 4 root root 4096 May 2 12:57 ./
drwxr-xr-x 135 root root 12288 May 2 11:05 ../
drwxr-xr-x 2 root root 4096 May 2 09:56 etc/
-rw-r--r-- 1 root root
2012 Jun 29
2
doveadm purge -A via doveadm-proxy director fails after some users
Hi,
we have configured userdb and passdb in the director and try to
iterate all users and pass the "purge" command via doveadm proxy to
port 19000 on the correct director backend host.
A single purge -u username at example.org via doveadm-proxy works correctly,
but iterating over some users with -A fails.
Note: users/domains have been anonymized in output:
2016 Sep 14
0
Exporting keytab for SPN failure
Am 14.09.2016 um 18:23 schrieb Michael A Weber:
>
>> On Sep 14, 2016, at 10:44 AM, Achim Gottinger via samba
>> <samba at lists.samba.org <mailto:samba at lists.samba.org>> wrote:
>>
>>
>>
>> Am 14.09.2016 um 05:53 schrieb Michael A Weber via samba:
>>> Experts—
>>>
>>> I’m attempting to export a keytab for a created
2019 May 02
2
Possibly WERR_DS_DRA_ACCESS_DENIED or NT_STATUS_CANT_ACCESS_DOMAIN_INFO
So we have two different Samba servers we are trying to connect to what was
originally a Windows 2003 AD and was raised to 2008R2 (both Forest and
Domain).
(We really only need to connect one of them - the one hosting Samba 4.7.6).
Any ideas or suggestions are helpful! We've scoured the lists (Rowland -
you are amazing), but still not found what is wrong (we think it is
probably a config
2016 Sep 14
1
Exporting keytab for SPN failure
> On Sep 14, 2016, at 12:57 PM, Achim Gottinger <achim at ag-web.biz> wrote:
>
>
>
> Am 14.09.2016 um 18:23 schrieb Michael A Weber:
>>
>>> On Sep 14, 2016, at 10:44 AM, Achim Gottinger via samba <samba at lists.samba.org <mailto:samba at lists.samba.org>> wrote:
>>>
>>>
>>>
>>> Am 14.09.2016 um 05:53
2009 Apr 05
2
Prohibit removing INBOX
Hello list,
I'm using dovecot 1.1.11 and I'm going to prohibit users to remove
their INBOX and some other directories in the mailbox root.
I used Access Control Lists (http://wiki.dovecot.org/ACL) to do this:
protocol imap {
mail_plugins = acl
}
plugin {
# With global ACLs in /etc/dovecot/acls/ directory:
acl = vfile:/etc/dovecot/acls
}
/etc/dovecot/acls/.DEFAULT:
owner
2019 May 02
0
Possibly WERR_DS_DRA_ACCESS_DENIED or NT_STATUS_CANT_ACCESS_DOMAIN_INFO
On Thu, 2 May 2019 14:44:18 -0400
James Fowler <fowlerj at adst.org> wrote:
> I have read that so many times. I started out with the simple,
> prompted 'samba-tool domain join' and built up from there.
>
> Version is:
> Samba 4.7.6 from Ubuntu (18.04.2)
>
> Interesting what happens when I take out --site directive (see below).
>
> root at DC2:~#
2018 Dec 12
2
doveadm proxy list repeats header line
Hi all,
just a minor thing: Why does `doveadm proxy list` repeat the header line
after each entry? Too me, that just makes the output harder to read.
So instead of this:
root at mail1 ~ # doveadm proxy list
username proto src ip dest ip port
info at domain1.de imap 80.152.196.98 222.133.127.53 993
username service src-ip dest-ip
2023 Jul 20
1
Samba rejecting authentication from Windows machines
Hi everybody.
First a short overview of our setup:
We have 2 Samba DCs in Domain 1
We use a Windows 10 Pro VM for the RSAT Tools which we access via RDP
We have 1 Windows Server 2012 DC for Domain 2
Between Domain 1 and 2 is a Trust for cross-domain file share access
Since the last reboot of our samba DCs they suddenly started to block login attempts on the RSAT-VM and also the Trust to the