Displaying 20 results from an estimated 800 matches similar to: "User's DPAPI/backupkey protected data lost when changing domain password"
2013 Aug 07
2
Samba 4 empty password
Hello,
We are trying to setup a SAMBA-Server with users that have empty passwords.
We are using:
Samba 4.0.8
Kernel 3.10.5
Slackware 14.0 x64
When we set a password the login successes!
That's what we get when trying to login:
[2013/08/07 13:31:46, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: AS-REQ media1 at BC from ipv4:10.0.99.100:62078 for
2012 Dec 06
1
Problem samba3 to samba4
Hello
I've migrated a samba 3 server to a samba 4 (.all the tests mentioned in
this howto are succesfull) .But i can't open a session with a
workstation on samba4 domain : approbation problem. The workstation name
which can't connect is "admin-pc"
Any idea ?
*Here are the logs of log.samba
*
Kerberos: Looking for ENC-TS pa-data -- *admin-pc$@SC*
[2012/12/06 12:50:59,
2018 Feb 12
0
Windows user domain accounts getting locked out regularly
Hi All,
We have a mixed environment running with Windows and Linux with samba as
the domain controller. Smart card login is configured and working
properly with pkinit and certs, etc
(https://wiki.samba.org/index.php/Samba_AD_Smart_Card_Login) though I
don't think this is related.
A handful of Windows clients are regularly getting their accounts locked
during what seems to be a
2016 Jun 24
0
Login not possible / machine account issues
Hi,
Did you find any solution?
I am facing exactly the same scenario.
-CentOS 6.7
-Samba Version 4.4.3
-BIND_DLZ 9.9.8
Some workstations suddenly are unable to login, unless I reboot or rejoin
the domain. The only odd event I see in the client is the one already said:
Log Name: System
Source: Microsoft-Windows-Security-Kerberos
Event ID: 4
Task Category:
2015 Jul 01
3
strange: 20 characters max in samAccountName
Hi all,
Sernet Samba 4.2.2 as Active Directory on Debian 7.8. No other DC.
I can't log in with on Windows systems (Windows 7) when samAccountName are
longer than 20 characters. This seems to be a LAN MAN or NT4 limitation
which should not happen on AD domain.
Any idea what could leads my to that limitation?
I can log in using administrator account or any other having a short
(enough)
2018 Apr 03
0
Renaming a joined windows workstation
Hi all.
I'm experiencing a little problem when I rename an already joined windows
machine. The rename operation is done in the traditional way "Computer
properties> advanced settings> Computer name> change" in a windows 7
Machine. The rename itself finishes successful, but when I check the
computer name in the ADUC, the old name is still displayed. Checking the
object
2013 Aug 28
1
Problem with nslcd and samba
Hi,
I try to use nslcd with samba 4 for get suers and group for AD.
if I do a ldapsearch, I have a message :
Server not in kerberos database
if I do a getent passwd, nslcd display same error message.
log of samba4:
[2013/08/28 10:15:47, 3]
../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: TGS-REQ Administrator at CORMANDOM.INT-CORMAN.BE from
2012 Oct 03
1
Samba4 KDC Windows 7 clients may fail to get a ticket
Hello.
Samba 4.1.0pre1-GIT-aad669b, joined as a DC to an existing domain. Windows 7 machines may fail to get a ticket:
[2012/10/03 09:31:54, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: AS-REQ con-11$@KLIN.KIFATO-MK.COM from ipv4:192.168.1.138:49682 for krbtgt/KLIN.KIFATO-MK.COM at KLIN.KIFATO-MK.COM
[2012/10/03 09:31:54, 3]
2016 Jul 05
0
Login not possible / machine account issues
>>This can occur when the target server principal name (SPN) is registered >>on an account other than the account the target service is using.
Hmm, multiple computers with the same serial cause these things.
So first make sure this computers serial isnt used before.
Or 2 computers with the same name in the netwerk, happens with not syspreped computers.
Keep an eye on your samba
2017 Nov 17
2
error compiling samba in debian wheezy
i get this error when compiling samba 4
[3712/3935] Linking default/source4/rpc_server/libdcerpc-server.so
default/source4/rpc_server/backupkey/dcesrv_backupkey_21.o: In function
`get_pk_from_raw_keypair_params':
dcesrv_backupkey.c:(.text+0xb5e): undefined reference to
`gnutls_x509_privkey_import_rsa_raw2'
default/source4/rpc_server/backupkey/dcesrv_backupkey_21.o: In function
2015 May 28
2
[AD/PDC] Logins with Spaces do not work
Hi,
I've migrated a Windows Server 2003 Active Directory to Samba and am
running both servers in parallel. Samba is run under Debian Linux, Version
is 4.1.17-Debian.
My Problem is, that Client Computers cannot log in when their Logins
contain Spaces. We were able to reproduce this by adding/removing spaces
from a username and making login fail/work with this. Umlauts are not a
problem.
2018 Mar 04
1
Samba AD + Kerbero + NFS "Client no longer in database"
I am soo lost trying to get Samba AD 4.7.5 as a Kerberos source for
NFSv4. The NFS server is the Samba AD server running Ubuntu Server
16.0.4.3 and the client is Linux Mint 18.3
This export WORKS and mounts on client
########## /etc/exports ##########
/mnt/fileshare *(rw,no_subtree_check,async)
############################
This export DOES NOT
########## /etc/exports ##########
2017 Nov 17
1
Error compiling samba in debian wheezy
I get this error when compiling samba in debian wheezy
[3706/3935] Linking default/source3/lib/netapi/examples/group/group_getusers
[3707/3935] Linking default/source3/lib/netapi/examples/join/getjoinableous
[3708/3935] Linking default/source3/lib/netapi/examples/group/group_setinfo
[3709/3935] Linking default/source3/lib/netapi/examples/file/file_enum
[3710/3935] Linking
2016 Aug 22
1
Upgrade 4.2.14 --> 4.3.11
Hi,
I had Samba 4.2.14 working as AD DC with shares. After upgrade to version 4.3.11 AD DC authentication, ADUC, etc, stopped working. Shares still work fine.
OS. Oracle Linux 6.x with UEK, uptodate. Samba compiled from source.
Upgrade procedure (nothing special):
./configure --enable-selftest
make
make install
Testparm output:
# Global parameters
[global]
workgroup = EXAMPLE
realm =
2017 Apr 21
0
Fwd: Unable to change passwords from Win XP Pro clients
Sorry, I missed some relevant part of the logs after the suggested changes:
Kerberos: AS-REQ user2 at MYDOMAIN from ipv4:192.168.44.56:2080 for
krbtgt/MYDOMAIN at MYDOMAIN
[2017/04/21 12:47:37.526742, 3]
../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Client sent patypes: encrypted-timestamp, 128
[2017/04/21 12:47:37.526772, 3]
2017 Mar 18
0
kerberos issue (SPN not found) with windows Hyper-V ( samba 4.5.3 AD)
After reviewing logs I found that my previous assumption was wrong.
Situation: - i'm trying to start live migration from hyper-v host A
(BMSRV4-HYPERV) to hyper-v host B (BM-SRV-5) from host B (logged in as
user from DOMAIN ADMINS group).
Kerberos constrained delegation is set in accordnance to microsoft
instructions with proper SPN's set (well, proper as in with the
workaround I
2017 Jun 13
2
Joining a Windows Server 2008 / 2008 R2 DC to a Samba AD - ISSUE - The RPC server is unavailable
Hi ,
We have configured and run SAMBA-4.5 AD DC on Itanium HP UX 11iv3.
We have tried to join the windows server 2008 DC to samba AD with the steps
mentioned in the below link
https://wiki.samba.org/index.php/Joining_a_Windows_Server_
2008_/_2008_R2_DC_to_a_Samba_AD
While i am trying to execute the steps mentioned in section "Joining the
Windows Server to the Domain"
1.
2016 Jul 17
1
Winbindd segfaults with bind9-dlz trying to login via libwinbind-pam
Hello,
I just found and odd behaviour here on my test environment (debian
jessie with samba 4.4.5 backported from sid).
I create and ad-dc as usual, adjust nsswitch.conf and enable
pam-auth-winbind (ruuning pam-auth-update). I also define /bin/bash as
template shell.
Now after i create an samba-user and the users home directory
(/home/DOMAIN/achim).
I can login with that account on the
2013 Nov 04
1
Running SQL Server xp_logininfo with Samba PDC
We have setup Samba 4.1 as a PDC. We have successfully connected several
Windows 2008 Servers to the domain and created various users/groups.
During an application installation on the Windows server, it runs the
command in SQL server:
master..xp_logininfo 'MYDOMAIN\useraccount'
SQLserver is running as a service user created on the domain (here called
MYDOMAIN)
This returns:
Msg
2016 Jul 05
1
Login not possible / machine account issues
Well, in my option, you the have found your problem.
https://technet.microsoft.com/en-us/library/cc721940(v=ws.10).aspx
3) ..... After the unique system information is removed, ....
And
https://blogs.msdn.microsoft.com/aaron_margosis/2009/11/05/machine-sids-and-domain-sids/
Says:
Mark?s point is that SIDs must be unique within the authority in which they are used. So while DEMOSYSTEM