Bug#918432: [Pkg-samba-maint] Bug#918432: samba: net ads join to armel arch Samba DC failed
Le lun. 28 janv. 2019 à 22:16, Tomasz Jeliński a écrit : [...] > > Please keep the bug CC-ed. Yes, please always keep 918...@bugs.debian.org in CC. > I'm tracking Samba bugzilla thread but I can't create account to CC > answer there. I can't register, there is no active option to create > new account. As said at: https://bugzilla.samba.org/createaccount-save.html, you need to send an email to request an account. Please do, I'm adding too much lag... > I'am sending to You in attachments tarball with config > files requested by Louis and additional debugging information. Thanks > Workstation is samba amd64 arch (stable branch). Workstation samba > client (stable branch) connects without problem to samba AD-DC server > amd64 arch (tested on stable and testing branches). The problem only > occurs when I'am trying to join to samba ad-dc server installed on > QNAP TS device (armel arch) from my Workstation. I checked stable and > testing branch samba on QNAP TS device (armel arch) and notice the > same error message when I was trying to connect from samba stable > workstation. > > Today I attempt to connect from samba testing amd64 arch client > (hostname DC2) to AD-DC server. Error is the same but I have got > additional info: > > "Starting GENSEC submechanism gse_krb5 > gse_get_client_auth_token: Server principal not found > gensec_update_done: gse_krb5[0x560c3a869f90]: NT_STATUS_INVALID_PARAMETER > gensec_spnego_create_negTokenInit_step: gse_krb5: creating > NEG_TOKEN_INIT for ldap/dc1.ad.rowerowanorka.pl failed (next[(null)]): > NT_STATUS_INVALID_PARAMETER > gensec_update_done: spnego[0x560c3a864610]: NT_STATUS_INVALID_PARAMETER" > > When I analyzing Wireshark dump I found something strange. Kerberos > "NT Status Error" is a part of string "AD.ROWEROWANORKA.PL" what is > Kerberos REALM name. > > I send to You all gathered samba debuging files in attachment. There > are net ads join logs from stable and testing samba client (amd64), > wireshark dumps and screenshot with this strange packet in Wireshark > dump. This is too low level for me. I hope a samba team member will take a look at it... Regards -- Mathieu Parent
Bug#918432: [Pkg-samba-maint] Bug#918432: samba: net ads join to armel arch Samba DC failed
Hai, Can the TS post the configs of both server also. please show /etc/hosts /etc/resolv.conf /etc/krb5.conf /etc/samba/smb.conf Greetz, Louis
Bug#918432: [Pkg-samba-maint] Bug#918432: samba: net ads join to armel arch Samba DC failed
Control: forwarded -1 https://bugzilla.samba.org/show_bug.cgi?id=13755 Hi Tomasz, Please keep the bug CC-ed. Le mer. 9 janv. 2019 à 21:03, Tomasz Jeliński a écrit : > > > W dniu 09.01.2019 o 04:56, Mathieu Parent pisze: > > Le dim. 6 janv. 2019 à 01:12, Tomasz Jelinski a écrit > > : > >> Package: samba > >> Version: 2:4.5.12+dfsg-2+deb9u4 > >> Severity: normal > >> > >> Dear Maintainer, > > Hi, > Hi, > >> I can't connect workstation to samba DC configured on Orion platform > >> (armel arch) with installed Debian Stretch (packages are fully updated to > >> newest avaliable versions). > > Are you able to reproduce this from Debian testing (4.9.4)? > > > Today I upgraded samba to testing on device which trying to acts as > samba AD DC (QNAP TS-209 armel arch). I cleaned samba databases > (ldb,tdb) and performed DC provision from scratch. I acknowledge that > problem still exists and I can reproduce this on samba packages from > Debian testing repository (attachment - netadsjoin.log) OK. > System Information from QNAP TS-209 samba AD-DC: > > Package: samba > Version: 3:4.9.4+dfsg-1 > > Debian Release: 10.6 > APT prefers testing > APT policy: (561, 'testing'), (550, 'stable'), (510, > 'stable-updates'), (500, 'stable') > Architecture: armel (armv6tel) > > Kernel: Linux 4.9.0-8-marvell > Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8), > LANGUAGE=pl_PL.UTF-8 (charmap=UTF-8) > Shell: /bin/sh linked to /bin/dash > Init: systemd (via /run/systemd/system) > > Versions of packages samba depends on: > ii adduser 3.115 > ii dpkg 1.18.25 > ii libbsd0 0.8.3-1 > ii libc6 2.28-2 > ii libldb1 2:1.5.1+really1.4.3-1 > ii libpam-modules1.1.8-3.6 > ii libpam-runtime1.1.8-3.6 > ii libpopt0 1.16-10+b2 > ii libpython2.7 2.7.13-2+deb9u3 > ii libtalloc22.1.8-1 > ii libtdb1 1.3.16-2+b1 > ii libtevent00.9.37-1 > ii lsb-base 9.20161125 > ii procps2:3.3.12-3+deb9u1 > ii python2.7.13-2 > ii python-dnspython 1.15.0-1 > ii python-samba 2:4.9.4+dfsg-1 > ii python2.7 2.7.13-2+deb9u3 > ii samba-common 2:4.9.4+dfsg-1 > ii samba-common-bin 2:4.9.4+dfsg-1 > ii samba-libs2:4.9.4+dfsg-1 > ii tdb-tools 1.3.11-2 > > Versions of packages samba recommends: > ii attr1:2.4.47-2+b2 > ii logrotate 3.11.0-0.1 > ii samba-dsdb-modules 2:4.9.4+dfsg-1 > ii samba-vfs-modules 2:4.9.4+dfsg-1 > > Versions of packages samba suggests: > pn bind9 > pn bind9utils > pn ctdb > ii ldb-tools 2:1.1.27-1+b1 > ii ntp1:4.2.8p10+dfsg-3+deb9u2 > pn smbldap-tools > ii ufw0.35-4 > ii winbind2:4.9.4+dfsg-1 > > -- no debconf information > > Workstation has a samba stable version - 2:4.5.12+dfsg-2+deb9u4. I > suppose that problem is related to armel architecture because I can > perform 'net ads join' from my workstation to samba DC stable version > 2:4.5.12+dfsg-2+deb9u4 , configured in the same way on amd64 arch > (tested on Debian Stretch VM in Virtualbox) So, you have upgraded the server, but not the workstation. What if you test with a testing/sid armel? Regards -- Mathieu Parent
Bug#918432: [Pkg-samba-maint] Bug#918432: samba: net ads join to armel arch Samba DC failed
Le dim. 6 janv. 2019 à 01:12, Tomasz Jelinski a écrit : > > Package: samba > Version: 2:4.5.12+dfsg-2+deb9u4 > Severity: normal > > Dear Maintainer, Hi, > I can't connect workstation to samba DC configured on Orion platform > (armel arch) with installed Debian Stretch (packages are fully updated to > newest avaliable versions). Are you able to reproduce this from Debian testing (4.9.4)? Regards -- Mathieu Parent