Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
+++ This bug was initially created as a clone of Bug #893121 +++
Description of problem:
Trying to get ipa with smb support running. Finished running ipa-adtrust-install with smb bailing so tried ipactrl restart.
Version-Release number of selected component:
samba-winbind-4.0.0-174.fc18
Additional info:
backtrace_rating: 4
cmdline: /usr/sbin/winbindd
crash_function: dump_core
executable: /usr/sbin/winbindd
kernel: 3.7.1-2.fc18.x86_64
remote_result: NOTFOUND
uid: 0
Truncated backtrace:
Thread no. 1 (10 frames)
#2 dump_core at ../source3/lib/dumpcore.c:336
#3 smb_panic_s3 at ../source3/lib/util.c:833
#4 smb_panic at ../lib/util/fault.c:159
#5 pdb_get_methods at ../source3/passdb/pdb_interface.c:225
#7 pdb_capabilities at ../source3/passdb/pdb_interface.c:1225
#8 _lsa_EnumTrustedDomainsEx at ../source3/rpc_server/lsa/srv_lsa_nt.c:3912
#9 api_lsa_EnumTrustedDomainsEx at default/librpc/gen_ndr/srv_lsa.c:3912
#10 rpcint_dispatch at ../source3/rpc_server/rpc_ncacn_np.c:133
#11 rpcint_bh_raw_call_send at ../source3/rpc_server/rpc_ncacn_np.c:220
#12 dcerpc_binding_handle_raw_call_send at ../librpc/rpc/binding_handle.c:133
--- Additional comment from macleajb.ca on 20130108T16:10:07 ---
Created attachment 674922[details]
File: backtrace
--- Additional comment from macleajb.ca on 20130108T16:10:09 ---
Created attachment 674923[details]
File: cgroup
--- Additional comment from macleajb.ca on 20130108T16:10:11 ---
Created attachment 674924[details]
File: core_backtrace
--- Additional comment from macleajb.ca on 20130108T16:10:14 ---
Created attachment 674925[details]
File: dso_list
--- Additional comment from macleajb.ca on 20130108T16:10:15 ---
Created attachment 674926[details]
File: environ
--- Additional comment from macleajb.ca on 20130108T16:10:17 ---
Created attachment 674927[details]
File: limits
--- Additional comment from macleajb.ca on 20130108T16:10:19 ---
Created attachment 674928[details]
File: maps
--- Additional comment from macleajb.ca on 20130108T16:10:21 ---
Created attachment 674929[details]
File: open_fds
--- Additional comment from macleajb.ca on 20130108T16:10:22 ---
Created attachment 674930[details]
File: proc_pid_status
--- Additional comment from macleajb.ca on 20130108T16:10:24 ---
Created attachment 674931[details]
File: var_log_messages
--- Additional comment from abokovoy on 20130108T16:25:04 ---
Please show your /var/log/ipaserver-install.log. The requirement to start smb.service in this setup is to have ipa-adtrust-install run successfully.
--- Additional comment from macleajb.ca on 20130108T17:16:12 ---
Created attachment 674972[details]
ipa trustad install log
Requested file.
--- Additional comment from abokovoy on 20130108T17:37:57 ---
In the log there is indicated success of ipa-adtrust-install run. Not sure what your original description of 'smb bailing' means then.
In /var/log/messages I can see that winbindd was not able to authenticate to LDAP server using kerberos keytab and therefore everything failed. We can start from here.
1. Please show 'klist -k /etc/smb/samba.keytab'
2. Please show 'klist -c /run/samba/krb5cc_samba'
3. Try to authenticate using the samba.keytab and connect to the LDAP server manually as root (and show output here, replace dc=example,dc=com by correct DN):
OLDKRB5CCNAME=$KRB5CCNAME
export KRB5CCNAME=/run/samba/krb5cc_samba
klist
ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
export KRB5CCNAME=/tmp/test.ccache
kinit -kt /etc/smb/samba.keytab
klist
ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
kdestroy
export KRB5CCNAME=$OLDKRB5CCNAME
One possible issue is that /run/samba/krb5cc_samba is from some old run and has a ticket obtained before re-install of FreeIPA (if any) so it is invalid and not accepted by the KDC.
--- Additional comment from macleajb.ca on 20130108T18:57:05 ---
Hi Alexander,
I had been installing/uninstalling ipa and the adtrust parts since this was reported but was unable to get the winbind/smb piece to start.
Then, as you suggested I removed the /run/samba/krb5cc_samba file and was able to carry on from "ipa-adtrust-install".
Samba appears to be up and the testing shows it is ok. Sorry I have do not have it in a bad state to try the above. I will report back if it happens again.
JES
--- Additional comment from abokovoy on 20130108T19:04:54 ---
Thanks. I tried to guard against these invalid tickets in the latest releases but sometimes the code is not robust enough. The case of multiple re-installs is rather edge case for testing/development purposes though.
Feel free to close the bug.
--- Additional comment from macleajb.ca on 20130108T19:07:31 ---
May I ask if you can confirm that currently you can not have an IPA-to-IPA 2 way trust and that you can only have a IPA-to-AD trust? I have been trying that without success and did not want to keep trying if it is a known limitation.
Thanks again,
JES
--- Additional comment from abokovoy on 20130108T20:11:06 ---
IPA-to-AD is two-way trust. IPA-to-IPA trusts are not implemented yet. Feel free to file an RFE ticket in FreeIPA's Trac instance at https://fedorahosted.org/freeipa/.
--- Additional comment from abokovoy on 20130110T14:10:52 ---
Closing.
--- Additional comment from gergely on 20130213T09:34:34 ---
I have a Fedora 18 install on my company machine, set up to login using the Active Directory services. I got this same problem today, and I have nothing to do with IPA. However, abrt couldn't report the problem because it's the "duplicate" of this one...
--- Additional comment from marmarek.pl on 20130422T22:15:29 ---
Same here.
Looking at backtrace it have something to do with printing. From logs:
"PANIC: assert failed at ../source3/printing/printing.c(481): pjob->jobid == jobid"
--- Additional comment from asn on 20130423T09:37:34 ---
Sorry, but there is no printing support in winbind at all.
The same problem has been detected in Red Hat Enterprise Linux 7. The following packages are affected:
samba-winbind-4.1.1-10.el7.x86_64
samba-winbind-4.1.1-9.el7.x86_64
Comment 3Andreas Schneider
2014-01-14 16:12:38 UTC
Michal: The original bug is a SELinux issue. If you see a issue here we need a backtrace and log file of Samba.
Else I would like to close it.
Comment 4Alexander Bokovoy
2014-01-14 16:15:24 UTC
Michal, are you reinstalling IPA with trusts on the same machine?
If so, can you try instructions I provided in the original bug and also provide us with logs.
------------------------------------------------
In the log there is indicated success of ipa-adtrust-install run. Not sure what your original description of 'smb bailing' means then.
In /var/log/messages I can see that winbindd was not able to authenticate to LDAP server using kerberos keytab and therefore everything failed. We can start from here.
1. Please show 'klist -k /etc/smb/samba.keytab'
2. Please show 'klist -c /run/samba/krb5cc_samba'
3. Try to authenticate using the samba.keytab and connect to the LDAP server manually as root (and show output here, replace dc=example,dc=com by correct DN):
OLDKRB5CCNAME=$KRB5CCNAME
export KRB5CCNAME=/run/samba/krb5cc_samba
klist
ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
export KRB5CCNAME=/tmp/test.ccache
kinit -kt /etc/smb/samba.keytab
klist
ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
kdestroy
export KRB5CCNAME=$OLDKRB5CCNAME
One possible issue is that /run/samba/krb5cc_samba is from some old run and has a ticket obtained before re-install of FreeIPA (if any) so it is invalid and not accepted by the KDC.
------------------------------------------------
Sorry I can't really provide much information.
This is a semi-automatic report based on ABRT anonymous auto-reporting. It indicates that a bug formerly encountered on Fedora has recently been hit on RHEL7 Beta. It is just a reminder to backport the Fedora fix into RHEL7. Feel free to close the bug is this has already been done.