Hello

I've migrated a samba 3 server to a samba 4 (.all the tests mentioned in this howto are succesfull) .But i can't open a session with a workstation on samba4 domain : approbation problem. The workstation name which can't connect is "admin-pc"
Any idea ?

*Here are the logs of log.samba
*
 Kerberos: Looking for ENC-TS pa-data -- *admin-pc$@SC*
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper) Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC (enctype arcfour-hmac-md5) error Decrypt integrity check failed [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/smbd/service_stream.c:63(stream_terminate_connection) Terminating connection - 'kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED' [2012/12/06 12:50:59, 3] ../source4/smbd/process_single.c:104(single_terminate) single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED] [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper) Kerberos: AS-REQ admin-pc$@SC from ipv4:192.168.77.33:49599 for krbtgt/SC@SC [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Client sent patypes: encrypted-timestamp, 128
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for PKINIT pa-data -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for ENC-TS pa-data -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper) Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC (enctype arcfour-hmac-md5) error Decrypt integrity check failed [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/smbd/service_stream.c:63(stream_terminate_connection) Terminating connection - 'kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED' [2012/12/06 12:50:59, 3] ../source4/smbd/process_single.c:104(single_terminate) single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED] [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper) Kerberos: AS-REQ admin-pc$@SC from ipv4:192.168.77.33:49600 for krbtgt/SC@SC [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Client sent patypes: encrypted-timestamp, 128
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for PKINIT pa-data -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for ENC-TS pa-data -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper) Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC (enctype arcfour-hmac-md5) error Decrypt integrity check failed [2012/12/06 12:50:59, 3] ../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Failed to decrypt PA-DATA -- admin-pc$@SC
[2012/12/06 12:50:59, 3] ../source4/smbd/service_stream.c:63(stream_terminate_connection) Terminating connection - 'kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED' [2012/12/06 12:50:59, 3] ../source4/smbd/process_single.c:104(single_terminate) single_terminate: reason[kdc_tcp_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED]


*Here are the logs of log.smbd*

,  3] ../source4/auth/ntlm/auth.c:270(auth_check_password_send)
auth_check_password_send: Checking password for unmapped user [SC]\[ADMIN-PC$]@[ADMIN-PC]
  auth_check_password_send: mapped user is: [SC]\[ADMIN-PC$]@[ADMIN-PC]
[2012/12/06 12:50:59.430091, 3] ../libcli/auth/ntlm_check.c:398(ntlm_password_check)
  ntlm_password_check: NTLMv2 password check failed
[2012/12/06 12:50:59.430217, 3] ../libcli/auth/ntlm_check.c:443(ntlm_password_check)
  ntlm_password_check: Lanman passwords NOT PERMITTED for user *ADMIN-PC$*
[2012/12/06 12:50:59.430564, 3] ../libcli/auth/ntlm_check.c:587(ntlm_password_check) ntlm_password_check: LM password, NT MD4 password in LM field and LMv2 failed for user ADMIN-PC$ [2012/12/06 12:50:59.430664, 2] ../source4/auth/ntlm/auth.c:420(auth_check_password_recv) auth_check_password_recv: sam_ignoredomain authentication for user [SC\ADMIN-PC$] FAILED with error NT_STATUS_WRONG_PASSWORD [2012/12/06 12:50:59.430783, 2] ../auth/gensec/spnego.c:743(gensec_spnego_server_negTokenTarg)
  SPNEGO login failed: NT_STATUS_WRONG_PASSWORD
[2012/12/06 12:50:59.432486, 2] ../source3/smbd/smb2_server.c:3123(smbd_smb2_request_incoming) smbd_smb2_request_incoming: client read error NT_STATUS_CONNECTION_DISCONNECTED [2012/12/06 12:50:59.432958, 3] ../source3/smbd/server_exit.c:218(exit_server_common)
  Server exit (NT_STATUS_CONNECTION_DISCONNECTED)
[2012/12/06 12:51:12.272511,  3] ../source3/smbd/service.c:1165(close_cnum)
  admin-pc (ipv4:192.168.77.33:49579) closed connection to service IPC$
[2012/12/06 12:51:12.275025,  3] ../source3/smbd/process.c:1789(process_smb)
[2012/12/06 12:51:12.275135, 2] ../source3/smbd/smb2_server.c:3123(smbd_smb2_request_incoming)
  Transaction 6 of length 39 (0 toread)
smbd_smb2_request_incoming: client read error NT_STATUS_CONNECTION_DISCONNECTED [2012/12/06 12:51:12.275305, 3] ../source3/smbd/process.c:1392(switch_message)
  switch message SMBtdis (pid 5467) conn 0xa4272e0
[2012/12/06 12:51:12.275633,  3] ../source3/smbd/service.c:1165(close_cnum)
[2012/12/06 12:51:12.275756, 3] ../source3/smbd/server_exit.c:218(exit_server_common)
  admin-pc (ipv4:192.168.77.33:49580) closed connection to service IPC$
  Server exit (NT_STATUS_CONNECTION_DISCONNECTED)
[2012/12/06 12:51:12.277284,  3] ../source3/smbd/process.c:1789(process_smb)
  Transaction 7 of length 43 (0 toread)
[2012/12/06 12:51:12.277480, 3] ../source3/smbd/process.c:1392(switch_message)
  switch message SMBulogoffX (pid 5467) conn 0x0
[2012/12/06 12:51:12.279057, 3] ../source3/smbd/reply.c:2255(reply_ulogoffX)
  ulogoffX vuid=12316
[2012/12/06 12:51:12.281262, 3] ../source3/smbd/server_exit.c:218(exit_server_common)
  Server exit (failed to receive smb request)
[2012/12/06 12:51:28.588578, 2] ../source3/smbd/server.c:436(remove_child_pid)
  Could not find child 5472 -- ignoring
[2012/12/06 12:52:28.653722, 2] ../source3/smbd/server.c:436(remove_child_pid)
  Could not find child 5474 -- ignoring
[2012/12/06 12:53:28.718864, 2] ../source3/smbd/server.c:436(remove_child_pid)





--

Hervé Hénoch
Responsable informatique
Institut Sainte Catherine
250 chemin de Baigne-Pieds
CS 80005 --- 84918 AVIGNON cedex 9
Téléphone : 04.90.27.57.44
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

Reply via email to