Bug 449000
| Summary: | Samba server can't authenticate to NT domain after 2008-05-28 update | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | Nathaniel Taylor <rhbn> | ||||||||
| Component: | samba | Assignee: | Guenther Deschner <gdeschner> | ||||||||
| Status: | CLOSED ERRATA | QA Contact: | |||||||||
| Severity: | urgent | Docs Contact: | |||||||||
| Priority: | urgent | ||||||||||
| Version: | 5.2 | CC: | azelinka, blomqvist.janne, devin.bougie, jplans, mwalls, rgarth, s.hage, ssorce | ||||||||
| Target Milestone: | rc | Keywords: | ZStream | ||||||||
| Target Release: | --- | ||||||||||
| Hardware: | x86_64 | ||||||||||
| OS: | Linux | ||||||||||
| Whiteboard: | |||||||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||||||
| Doc Text: | Story Points: | --- | |||||||||
| Clone Of: | Environment: | ||||||||||
| Last Closed: | 2009-01-20 21:47:12 UTC | Type: | --- | ||||||||
| Regression: | --- | Mount Type: | --- | ||||||||
| Documentation: | --- | CRM: | |||||||||
| Verified Versions: | Category: | --- | |||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||
| Embargoed: | |||||||||||
| Bug Depends On: | |||||||||||
| Bug Blocks: | 450653, 455418 | ||||||||||
| Attachments: |
|
||||||||||
|
Description
Nathaniel Taylor
2008-05-29 20:25:32 UTC
can you attach your smb.conf file so that I can try to reproduce here? also logs would be nice Created attachment 307175 [details]
samba config file
Created attachment 307176 [details]
samba log of client session
Certainly: here's more detail. smb.conf is the config. gnu.log is a log of an attempted access to samba shares. The [ns]mb.log don't contain any details of the problem; they just have startup times. When I tried to (re)join the domain, in case somehow the 'trust' had been overwritten in the update, the following message was shown on the command line but nothing in the logs: # net rpc join member -U nt.adm Password: [2008/05/30 10:56:14, 0] utils/net_rpc_join.c:net_rpc_join_newstyle(371) Error in domain join verification (credential setup failed): NT_STATUS_ACCESS_DENIED Unable to join domain EKC.KTH.SE. According to the admin for the windows network, nothing has changed there in recent days. Furthermore, everything worked with the original version from the CDs 1 year ago, then worked with all the updates up to then, then failed on this last update, then worked with regression to the old version from the CD, then failed with update to the new, then worked with the old again... So, is your domain controlled by NT4 domain controllers or Windows 2000 domain controllers ? It's a single NT4 domain controller, running Windows NT 4 with current updates, serving a domain of Win2000 and WinXP clients. Sorry for the confusion. I only knew the "NT domain" bit, and had to contact the windows admin to find out the full details. Created attachment 307202 [details]
always return netlogon negotiate flags
This patch fixes it for me.
Thanks for the patch. I'm very happy to leave the testing to RedHat, particularly if a working update to samba will come soon. If it's of help that I test the patch on our network too, please would you (Simo) send me an rpm or details of how to get the srpm; it's 'non-obvious' to me from the rhn website, and it's years since I played with rpms. For what it's worth, the patch in Comment #7 fixes this issue for us, also. Same problem, except I had working domain members of an NT domain stop working until I fell back my samba version. Current domain is pdc + 2 bdc (NT). We will provide an offical update soon, in the meantime, you can find test rpms at: http://people.redhat.com/gdeschne/bugs/449000/ Please let us know if it fixes this issue. Yes, thanks. These rpms 3.0.28-1.el5_2.2 don't have the authentication problem of 3.0.28-1.el5_2.1. As an extra data point, the patch in comment #7 fixed the problem (joining an NT 4.0 domain) for me under Fedora 8 when applied to samba-3.0.30-0.fc8 Fixes it for me. The RPMs posted in Comment #11 work for us, also. *** Bug 450509 has been marked as a duplicate of this bug. *** What's going on with this bug? The working patch came out about a month ago, but there isn't yet a mention of an official update. Until there is, I can't afford to use updates. There must be many more users than have shown up on this list, who can't use their samba. To reiterate, what's going on? It's now 3 and a half months since the one-line patch that fixes the problem came out, and yet no official update. Janne, if you are in urgent need of a patched binary I suggest you contact support and escalate the issue to get an hotfix. The fix is scheduled to be released with the 5.3 update for now. Thankyou for the RPMs, they have worked for us. Is there an ETA for the rpms to be released officially? An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2009-0180.html |