Displaying 20 results from an estimated 4000 matches similar to: "Win2k auth on named share fails on mixed Windows network."
2005 Apr 16
1
Problems with ADS membership in win2k domain
I'm having problems with ADS membership for samba. I had a "mostly"
working version with RHES v2.1, krb5 v1.2, samba v3.0.5.
I knew to get to a fully functioning version I would need krb5 v1.3
or later. So finally I had an opertunity to junk RH's crufty krb5
and build from scratch with:
RHES v2.1
MIT krb5 v1.4
samba v3.0.13
This works fine on another server. Now to the
2004 Apr 20
1
RES: Samba 3.0.2a with ADS w2k3 Active Directory, enctype s
Hi Jim,
I did what the doc says but the problem is the same.
Does anybody saw this work ? I mean, is the Samba 3.0.2a+Kerberos MIT 1.3.3
able to be accessed by a WXP, W2K or W2K3 machine, using Kerberos tickets
generated in a Windows 2003 KDC (W2K3 AD) ?
Thanks
-----Mensagem original-----
De: Jim McDonough [mailto:jmcd@us.ibm.com]
Enviada em: segunda-feira, 19 de abril de 2004 17:07
Para:
2004 May 27
3
Any ideas ?
Hints or check lists for that type or error ?
[2004/05/27 14:11:06.627563, 10, pid=23616]
libads/kerberos_verify.c:ads_verify_ticket(185)
ads_verify_ticket: enc type [1] failed to decrypt with error Bad
encryption type
[2004/05/27 14:11:06.627589, 10, pid=23616]
passdb/secrets.c:secrets_named_mutex_release(716)
secrets_named_mutex: released mutex for replay cache mutex
[2004/05/27
2009 May 04
2
bad encryption type in AD domain authentication
Hello,
I'm trying to access a samba share using an ADS user credentials. I always
get an error, and the debug traces (log level = 5) are giving me the output
in the follow.
I have searched the samba ML archives, and I have found the thread
http://lists.samba.org/archive/samba/2004-April/084545.html
but, before asking the system admin to apply the eventual KB fixes, I would
like to know if the
2012 May 04
1
s3 connect to s4 ads woes, need guidance..
I'm beating my head up against the wall here.. Need some extra eyes!!!
Setup -- Samba4 Domain Controller and samba3 print server.. DNS
FlatFile,, All dns works..
Issue, When I browse to the print Server vi \\IP-Address I am able to
connect just fine.. When I browse using \\netbios-name I connect to the
server but it opens up a username/pass dialog box and no name or
passwords will work..
2006 Sep 18
1
username map change = samba failure
Since I haven't gotten any responses from the segfault log I posted
earlier, I will try another approach. Below is what happens when a
client tries to connect. Again, this all started after I changed a
username mapping entry from root = DOMAIN\Administrator to root =
@"DOMAIN\Domain Admins". This is in a security = ADS setup. wbinfo -u
and -g return the correct information.
2005 Apr 16
1
Problems with ADS membership with win2k domain
I'm having problems with ADS membership for samba. I had a "mostly"
working version with RHES v2.1, krb5 v1.2, samba v3.0.5.
I knew to get to a fully functioning version I would need krb5 v1.3
or later. So finally I had an opertunity to junk RH's crufty krb5
and build from scratch with:
RHES v2.1
MIT krb5 v1.4
samba v3.0.13
This works fine on another server. Now to the
2013 Oct 09
1
URGENT - production server stops working (v3.6)
Hello,
i need some help. A samba3 (3.6.9-151.el6_4.1) ADS member (WIN 2008 AD
Master) Server did his work for years. Since hours some Clients can not
connect to the name (\\fileserver)
connecting to \\192... sometimes work.
Log say:
2013/10/09 09:54:27.735101, 3] smbd/sesssetup.c:660(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1638
[2013/10/09 09:54:27.735423, 3]
2017 Nov 09
3
Slow Kerberos Authentication
Hai,
You may need to add the the following in krb5.conf
[libdefaults]
allow_weak_crypto = true
; for Windows 2003
; default_tgs_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; default_tkt_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; permitted_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
; for Windows 2008 with AES
default_tgs_enctypes = aes128-cts-hmac-sha1-96
2016 Apr 20
2
Debian patched 3.6.6 winbindd fails.
Hi there,
I manage a Samba installation which has been operating very well on
Debian Wheezy for a number of years. Up until last week I was running
3.6.25, which (as always until now) I compiled myself. Because of the
large number of changes in the recent security patches, I opted to try
the Debian 'samba' and 'winbind' packages. I was a little horrified
to find that Debian is
2017 Nov 10
2
Slow Kerberos Authentication
No, no idee, but really, upgrade to samba, best option, in my opinion.
If thats not possible, it happens..
A timeout option can be set in krb5.conf
for example : kdc_timeout = 5000
You have these for krb5.conf to try out also.
the complete list.
des-hmac-sha1
DES with HMAC/sha1 (weak)
aes256-cts-hmac-sha1-96 aes256-cts AES-256
CTS mode with 96-bit SHA-1 HMAC
2006 Nov 30
1
samba 3.0.23d on ubuntu - ADS member -failed to verify ticket
I have a server with ubuntu 6.06 LTS with samba 3.0.23d (compiled against
heimdal krb5) and heimdal-clients0.7.1-1ubuntu3.
I have configured samba as a ADS domain member.
Problem is that when I want to access a samba share from a windows xp domain
member I am keep asked for user and password and
debug level 3 shows this on log.<workstation_name> :
...
[2006/11/30 12:42:15, 3]
2006 Mar 22
2
Authentication problems with win2k3 domain controller
Hi
I'm having problems with samba-3.0.21b and Windows Server 2003 domain
controllers.
When I try to access the samba server from a client (\\sambasrv) I
only get a login prompt, no username/password combination works.
Accessing the samba server through its IP-number instead of
using the netbios name works.
This together with the log message "Failed to verify incoming ticket!"
2005 Jun 13
4
Kerberos enc type [xx] failed
Hi All,
I am getting Kerberos "enc type" problem that I can't explain:
[2005/06/11 11:41:29, 1, pid=29355]
libads/kerberos_verify.c:ads_keytab_verify_ticket(61)
ads_keytab_verify_ticket: krb5_kt_start_seq_get failed (No such file
or directory)
[2005/06/11 11:41:29, 3, pid=29355]
libads/kerberos_verify.c:ads_secrets_verify_ticket(193)
ads_secrets_verify_ticket: enc type [16]
2009 Jan 29
1
Samba 3.2.7 and XP authentication error
List,
Long and confusing message follows...
I'm facing a frustrating problem. XP clients can use resoures on the
samba server by IP-address, but not by name. So, "net view \\servername"
gives "access denied" but "net view \\ipaddress" gives list of shared
resources.
Samba server (3.2.7 sernet rpm) is a member server in W2003 domain.
I emphasise that with
2004 Apr 19
1
Samba 3.0.2a with ADS w2k3 Active Directory, enctypes
Hi people,
I have a Linux box running Samba 3.0.2a in ADS mode MIT Kerberos 1.3.3. My
W2K e WXP users can't access the linux box by netbios name, the only access
that works is by IP address, I know that's caused because access thought IP
address don't make use of Kerberos. The most strange for me it's that the
same environment works fine with a W2K Active Directory, I read in same
2004 Aug 25
2
Upgrade from samba 3.0.4 to 3.0.6 broke file sharing
system is redhat 9 on a dell power edge 2450 running latest krb5 and
openldap rpm
It worked perfectly on 3.0.4 but arcserve wouldn't back up so I upgraded
to 306 and everything installed correctly but now when you try and
connect to the server it pops the user login box up. I can run net ads
user -U Administrator and log in with my admin password and it lists all
my user accounts. I can add
2005 Nov 03
1
Going insane - ads_secrets_verify_ticket
I have been fighting with this FreeBSD port for two days
off/on
Can anyone please suggest something? Even if it's paid
support to fix this?
Thanks!
Eric
[2005/11/03 17:03:17, 3]
smbd/sesssetup.c:reply_sesssetup_and_X_spnego(619)
NativeOS=[Windows 2002 Service Pack 2 2600]
NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2005/11/03 17:03:17, 3]
2007 Aug 15
1
Performance Problem / failed to verify PAC server signature
Hello,
We are experiencing ADS lower performance on Samba-3.0.22 for HPUX. I
did Google search, and find out one message posted at
http://lists.samba.org/archive/samba/2005-November/114231.html at the
earlier time.
>From my observation, it seems there was a spin on
reply_spnego_negotiate()/ reply_spnego_kerberos() calls that invokes
register_vuid() to register uvid with different vuid# for a
2003 Nov 24
2
v3.0.X kerberos_verify sol8 compile problem
Having a problem getting v3.0.0(or pre3) to compile on a Solaris 8 box,
tried Sun compilers and Solaris compilers.. Recompiled/Re-installed
Kerberos all roads lead to the same error compiling Samba, it gets about 2/3
of the way done and spews...
Compiling libads/kerberos_verify.c
libads/kerberos_verify.c: In function `create_keytab':
libads/kerberos_verify.c:77: structure has no member