[Freeipa-users] Re: Samba update can't read NT Hash

2017-08-22 Thread Alexander Bokovoy via FreeIPA-users

On to, 17 elo 2017, Alexander Bokovoy via FreeIPA-users wrote:



- Original Message -



Yesterday we updated our fileserver to bring it up to the newest kernel. At
the same time it update the ipa-client and samba. After the update was
finished our ability to access the shared resources on the fileserver
disappeared. After some very careful troubleshooting we have been able to
narrow it down to a problem with Samba, but we have been unable to find
where in the configuration the problem is. I am including several logs,
config files, etc with this, we need this restored ASAP, but can't seem to
isolate the issue.


Please show rpm versions for freeipa, samba, and krb5 packages.

Please also set log level 10 in smb.conf and provide logs off the list.

It is late in my timezone so I'll be able to look at them tomorrow.

To close the loop, it is a change in internal behavior in Samba 4.6.x
that made SSSD-provided libwbclient to return wrong (for newer Samba)
value.

The fix is tracked with https://github.com/SSSD/sssd/pull/353

--
/ Alexander Bokovoy
___
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org


[Freeipa-users] Re: Samba update can't read NT Hash

2017-08-17 Thread Alexander Bokovoy via FreeIPA-users


- Original Message -
> 
> 
> Yesterday we updated our fileserver to bring it up to the newest kernel. At
> the same time it update the ipa-client and samba. After the update was
> finished our ability to access the shared resources on the fileserver
> disappeared. After some very careful troubleshooting we have been able to
> narrow it down to a problem with Samba, but we have been unable to find
> where in the configuration the problem is. I am including several logs,
> config files, etc with this, we need this restored ASAP, but can't seem to
> isolate the issue.

Please show rpm versions for freeipa, samba, and krb5 packages.

Please also set log level 10 in smb.conf and provide logs off the list.

It is late in my timezone so I'll be able to look at them tomorrow.

> 
> logs:
> 
> 
> 
> 
> 
> Log.192.168.105.237
> 
> [2017/08/17 07:59:38.684827, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[homes]"
> 
> [2017/08/17 07:59:38.684939, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[stockroom]"
> 
> [2017/08/17 07:59:38.685049, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[inorgstk]"
> 
> [2017/08/17 07:59:38.685144, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[netlogon]"
> 
> [2017/08/17 07:59:38.685211, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[deptchair]"
> 
> [2017/08/17 07:59:38.685333, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[deptfinance]"
> 
> [2017/08/17 07:59:38.685448, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[facultysearch]"
> 
> [2017/08/17 07:59:38.685523, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[research]"
> 
> [2017/08/17 07:59:38.685610, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[working]"
> 
> [2017/08/17 07:59:38.685713, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[csradmin]"
> 
> [2017/08/17 07:59:38.685802, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[install]"
> 
> [2017/08/17 07:59:38.685933, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[coffice]"
> 
> [2017/08/17 07:59:38.686097, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[grants]"
> 
> [2017/08/17 07:59:38.686202, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[deptoffice]"
> 
> [2017/08/17 07:59:38.686330, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[gradadmissions]"
> 
> [2017/08/17 07:59:38.686411, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[mainoffice]"
> 
> [2017/08/17 07:59:38.686525, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[busoffice]"
> 
> [2017/08/17 07:59:38.686607, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[entropy]"
> 
> [2017/08/17 07:59:38.686718, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[ltarch]"
> 
> [2017/08/17 07:59:38.686807, 2]
> ../source3/param/loadparm.c:2769(lp_do_section)
> 
> Processing section "[netlogon-n175]"
> 
> [2017/08/17 07:59:38.686963, 3] ../source3/param/loadparm.c:1592(lp_add_ipc)
> 
> adding IPC service
> 
> [2017/08/17 07:59:38.687257, 2] ../source3/lib/interface.c:345(add_interface)
> 
> added interface eth0 ip=192.168.105.99 bcast=192.168.105.99
> netmask=255.255.255.255
> 
> [2017/08/17 07:59:38.687362, 3] ../source3/smbd/oplock.c:1322(init_oplocks)
> 
> init_oplocks: initializing messages.
> 
> [2017/08/17 07:59:38.687511, 3] ../source3/smbd/process.c:1957(process_smb)
> 
> Transaction 0 of length 159 (0 toread)
> 
> [2017/08/17 07:59:38.687557, 3]
> ../source3/smbd/process.c:1538(switch_message)
> 
> switch message SMBnegprot (pid 22349) conn 0x0
> 
> [2017/08/17 07:59:38.688383, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [PC NETWORK PROGRAM 1.0]
> 
> [2017/08/17 07:59:38.688408, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [LANMAN1.0]
> 
> [2017/08/17 07:59:38.688418, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [Windows for Workgroups 3.1a]
> 
> [2017/08/17 07:59:38.688423, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [LM1.2X002]
> 
> [2017/08/17 07:59:38.688429, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [LANMAN2.1]
> 
> [2017/08/17 07:59:38.688434, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [NT LM 0.12]
> 
> [2017/08/17 07:59:38.688439, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [SMB 2.002]
> 
> [2017/08/17 07:59:38.688444, 3] ../source3/smbd/negprot.c:603(reply_negprot)
> 
> Requested protocol [SMB 2.???]
> 
> [2017/08/17 07:59:3