URL: https://www.opennet.me/cgi-bin/openforum/vsluhboard.cgi
Форум: vsluhforumID1
Нить номер: 44174
[ Назад ]

Исходное сообщение
"Samba + AC = Failed to verify incoming ticket!"

Отправлено FdF , 19-Май-04 20:13 
Есть сеть с Active Directory под win2000
Есть линюх, который я пытаюсь приткнуть в домен.
В AC машину зарегистрировал, на linux все сетевые шары видны.
А вот пытаюсь зайти из сети на linux - требует логин пароль и не пускает все равно.
в логах пишет
[2004/05/19 19:44:18, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
  Failed to verify incoming ticket!

log/log.winbindd
[2004/05/19 19:41:47, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain ALVENTA ALVENTA.SARATOV S-0-0                            
[2004/05/19 19:41:47, 1] libsmb/clikrb5.c:ads_krb5_mk_req(305)          
  krb5_cc_get_principal failed (No credentials cache found)              
[2004/05/19 19:41:48, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain BUILTIN  S-1-5-32                                        
[2004/05/19 19:41:48, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain SERVER3  S-1-5-21-1224869564-288785947-4227334007        
[2004/05/19 20:02:08, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain ALVENTA ALVENTA.SARATOV S-0-0                            
[2004/05/19 20:02:08, 1] libsmb/clikrb5.c:ads_krb5_mk_req(305)          
  krb5_cc_get_principal failed (No credentials cache found)              
[2004/05/19 20:02:09, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain BUILTIN  S-1-5-32                                        
[2004/05/19 20:02:09, 1] nsswitch/winbindd_util.c:add_trusted_domain(178)
  Added domain SERVER3  S-1-5-21-1224869564-288785947-4227334007        


Привожу конфиги:

[root@ns bin]# ./wbinfo -t                      
checking the trust secret via RPC calls succeeded
[root@ns bin]# ./wbinfo -u
Выдает список пользователей

[root@ns bin]# klist                                                        
Ticket cache: FILE:/tmp/krb5cc_0                                            
Default principal: fedor@ALVENTA.SARATOV                                    
                                                                            
Valid starting     Expires            Service principal                    
05/19/04 18:46:06  05/20/04 04:46:06  krbtgt/ALVENTA.SARATOV@ALVENTA.SARATOV
05/19/04 19:25:00  05/20/04 04:46:06  server1$@ALVENTA.SARATOV              
05/19/04 19:25:07  05/20/04 04:46:06  server2$@ALVENTA.SARATOV              
05/19/04 19:25:08  05/20/04 04:46:06  server3                   $@ALVENTA.SARATOV              
05/19/04 19:41:38  05/19/04 19:43:38  kadmin/changepw@ALVENTA.SARATOV      
                                                                        
Kerberos 4 ticket cache: /tmp/tkt0                                          
klist: You have no tickets cached                                          

SMB.CONF

[global]                  
workgroup = ALVENTA            
netbios name = SERVER3          
realm = ALVENTA.SARATOV            
password server = 10.0.0.10          
winbind uid = 10000-65000          
winbind gid = 10000-65000          
winbind separator = +            
winbind cache time = 5            
acl compatibility = winnt          
idmap uid = 10000-20000            
idmap gid = 10000-20000    
winbind enum users = yes    
winbind enum groups = yes    
winbind use default domain = no
template shell = /bin/bash  
hostname lookups = Yes    
hosts allow = 10.0.0.0/255.255.255.0 127.
security = ADS
encrypt passwords = yes
interfaces = eth1
name resolve order = wins lmhosts bcast
wins server = 10.0.0.10
[tmp]              
  comment = Temporary file space
  path = /tmp          
  read only = no        
  public = yes


[logging]                                
default = FILE:/var/log/krb5libs.log    
kdc = FILE:/var/log/krb5kdc.log        
admin_server = FILE:/var/log/kadmind.log
                                        
[libdefaults]                            
    default_realm = ALVENTA.SARATOV      
    dns_lookup_realm = true              
    dns_lookup_kdc = true                
                                        
[realms]                                
  ALVENTA.SARATOV = {                    
  kdc = 10.0.0.10:88                    
  admin_server = 10.0.0.10:749          
  default_domain = ALVENTA.SARATOV      
}                                      
                                        
[domain_realm]                          
  alventa.saratov = ALVENTA.SARATOV      
  .alventa.saratov = ALVENTA.SARATOV    


Содержание

Сообщения в этом обсуждении
"Samba + AC = Failed to verify incoming ticket!"
Отправлено FdF , 20-Май-04 18:29 
Продолжение...
Мне удалось все же зайти на linux станию из сети, но.
1. Я смог зайти под учетной записью которая есть не в домене а в системе (Linux) после того как я добавил ее через smbpasswd в самбу
2. я забил ту же пароль что и в домене при добавлении пользователя, в самба все равно попросила ввести пароль при обращении к ней - таким образом получается, что самба не принела учетную запись домена.
3. Самба наотрез не добавляет пользователей из AD себе в smbpasswd

Как сделать так чтобы пользователи все же брались из домена

Кратко привожу изменения в конфигах...
smb.conf

[global]                                        
   workgroup = ALVENTA                          
   netbios name = SERVER3                      
   realm = ALVENTA.SARATOV                      
   bind interfaces only = Yes                  
   password server = 10.0.0.10                  
   log level = 0                                
   preferred master = No                        
   local master = No                            
   domain master = No                          
   dns proxy = No                              
   ads server = 10.0.0.10                      
                                                
    winbind uid = 10000-65000                  
    winbind gid = 10000-65000                  
    winbind use default domain = yes            
    ;winbind separator = +                      
    winbind cache time = 5                      
    acl compatibility = winnt                  
    ;obey pam restrictions = yes                
    ;host msdfs = Yes                          
    hosts allow = 10.0.0.0/255.255.255.0 127. 0.
   ;printcap name = /etc/printcap              
    log file = /usr/local/samba/var/log/log.%m
    max log size = 50                        
    security = ADS                            
    encrypt passwords = yes                  
    update encrypted = Yes                    
    interfaces = eth1                        
   wins server = 10.0.0.10                    

krb5.conf

[logging]                                      
default = FILE:/var/log/krb5libs.log          
kdc = FILE:/var/log/krb5kdc.log                
admin_server = FILE:/var/log/kadmind.log      
                                                
[libdefaults]                                  
    default_realm = ALVENTA.SARATOV            
    default_etypes_des = des-cbc-crc des-cbc-md5
    dns_lookup_realm = true                    
    dns_lookup_kdc = true                      
                                                
[realms]                                        
  ALVENTA.SARATOV = {                          
  kdc = 10.0.0.10:88                            
  admin_server = 10.0.0.10:749                  
  default_domain = ALVENTA.SARATOV              
}                                              
                                                
[domain_realm]                                  
  alventa.saratov = ALVENTA.SARATOV            
  .alventa.saratov = ALVENTA.SARATOV            

nsswitch.conf

passwd:     files winbind
shadow:     files        
group:      files winbind

(nss не запущен)


"Samba + AC = Failed to verify incoming ticket!"
Отправлено juDge , 21-Май-04 13:21 
выставь

obly pam restriction = Yes

по поводу правильности написания параметра не уверен =)


"Samba + AC = Failed to verify incoming ticket!"
Отправлено juDge , 21-Май-04 13:24 
или вот так
obey pam restrictions = yes

"Samba + AC = Failed to verify incoming ticket!"
Отправлено Nikolai , 21-Май-04 13:51 
>или вот так
>obey pam restrictions = yes
И фиг чем помогает, кто бы подсказал ещё passdb backend?


"Samba + AC = Failed to verify incoming ticket!"
Отправлено Nikolai , 21-Май-04 16:51 
>>или вот так
>>obey pam restrictions = yes
>И фиг чем помогает, кто бы подсказал ещё passdb backend?
Может кто нибудь из гуру может осветить этот вопрос? Действительно непонятно по идее  ведь samba должна проверять юзера на контроллере домена. А она за каким то фигом к нему вообще не обращается. Т.е. я так понимаю что он даже в smbpasswd не должны пароли доменных юзеров прописываться, раз есть база на контроллере домена, значит оттуда и пароли брать должна.



"Samba + AC = Failed to verify incoming ticket!"
Отправлено FdF , 23-Май-04 19:32 
>>>obey pam restrictions = yes
Не помагает точно! :(

Что делать - ума не приложу.
Может как-то еще можно это дело отладить?
Вообще у кого нибудь через kerberos работает или может есть другие предложения?
типа поставить ldap и синхронизировать как-то базы в win...


"Samba + AC = Failed to verify incoming ticket!"
Отправлено Nikolai , 24-Май-04 18:53 
>>>>obey pam restrictions = yes
>Не помагает точно! :(
>
>Что делать - ума не приложу.
>Может как-то еще можно это дело отладить?
>Вообще у кого нибудь через kerberos работает или может есть другие предложения?
>
>типа поставить ldap и синхронизировать как-то базы в win...
Да не должен он их синхронизировать, он просто в в индовую базу должен запрос делать, и оттуда получать пароль.



"Samba + AC = Failed to verify incoming ticket!"
Отправлено Pater , 27-Май-04 10:50 
>>>>obey pam restrictions = yes
>Не помагает точно! :(
>
>Что делать - ума не приложу.
>Может как-то еще можно это дело отладить?
>Вообще у кого нибудь через kerberos работает или может есть другие предложения?
>
>типа поставить ldap и синхронизировать как-то базы в win...


Дурацкий вопрос - ты винбинд запускаешь?
Керберос в самбе работает криво, но даже без него (в режиме domain) должно все завестись.


"Samba + AC = Failed to verify incoming ticket!"
Отправлено juDge , 27-Май-04 16:10 
вот что работает у меня:

RedHat Enterprise ES v3
samba 3.0.2-6.3E


--------- krb5.conf ----------
[logging]
    default = FILE:/var/log/krb5libs.log
    kdc = FILE:/var/log/krb5kdc.log
    admin_server = FILE:/var/log/kadmind.log

[libdefaults]
    default_realm = DOMAIN.LAN
    dns_lookup_realm = true
    dns_lookup_kdc = true
    ticket_lifetime = 24000

[realms]
    DOMAIN.LAN = {
    kdc = srv-pdc.domain.lan:88
    admin_server = srv-pdc.domain.lan:749
    default_domain = domain.lan
    }

[domain_realm]
    .domain.lan = DOMAIN.LAN
    domain.lan = DOMAIN.LAN

------------------------------

----------- smb.conf ---------
# Samba config file created using SWAT
# from 192.168.110.31 (192.168.110.31)
# Date: 2004/05/26 19:36:34

# Global parameters
[global]
    dos charset = CP866
    workgroup = DOMAIN
    realm = DOMAIN.LAN
    server string = File Server
    interfaces = 192.168.110.0/24
    bind interfaces only = Yes
    security = ADS
    allow trusted domains = No
    obey pam restrictions = Yes
    max log size = 1000
    socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
    os level = 0
    preferred master = No
    local master = No
    domain master = No
    dns proxy = No
    wins server = 192.168.110.1
    ldap ssl = no
    idmap uid = 10000-65000
    idmap gid = 10000-65000
    hosts allow = 192.168.110., 127.
    strict locking = No

[tmp]
    path = /tmp
    valid users = '@DOMAIN\Domain Admins'
    read only = No
------------------------------

и все работает как часы


"Samba + AC = Failed to verify incoming ticket!"
Отправлено Pater , 28-Май-04 08:37 
>вот что работает у меня:
>
>RedHat Enterprise ES v3
>samba 3.0.2-6.3E
>
>
>и все работает как часы

Скажи версию и производителя твоей реализации керберос.
у меня heimdal-0.6, несмотря на заверение самба-тим и сборщиков моего дистра (SuSE 9.0, самба сборки SerNet и SuSE версии 3.0.4, сборка от СуСЕ работает отлично некоторое время, потом винбинд начинает тормозить и падать, в логах куча ругани на керберос, в сборках сернет весь софт, пользующий керберос (винбинд, смбклиент) вообще неработоспособен), в режиме security = domain с теми же настройками все работает быстро и безглючно. народ говорит это кривой хеймдал, мол с MIT-kerberos все работает пучком, но у самба-тим (или у сусе-сернет) нелюбовь к мит-керберос.


"Samba + AC = Failed to verify incoming ticket!"
Отправлено mxm , 30-Май-04 15:18 
>>вот что работает у меня:
>>
>>RedHat Enterprise ES v3
>>samba 3.0.2-6.3E
>>
>>
>>и все работает как часы
>
>Скажи версию и производителя твоей реализации керберос.
>у меня heimdal-0.6, несмотря на заверение самба-тим и сборщиков моего
>дистра (SuSE
>

It`s work for me and my PDC(win2003) and others:


usrv# uname -mrs          
FreeBSD 5.2.1-RELEASE i386

usrv# /usr/local/samba/sbin/smbd -V
Version 3.0.4            

usrv# cat /usr/ports/security/heimdal/distinfo              
MD5 (heimdal-0.6.1.tar.gz) = 20ef3dade89afc45eac9d8935a1a9cc0
SIZE (heimdal-0.6.1.tar.gz) = 3312603

usrv# cat /usr/local/samba/lib/smb.conf          
# Global parameters                    
[global]                              
        acl compatibility = win2k      
        algorithmic rid base = 1000    
        allow trusted domains = Yes    
        announce as = NT              
        announce version = 4.9        
        available = Yes                
        bind interfaces only = No      
        block size = 1024              
        blocking locks = Yes          
        browse list = Yes              
        browseable = Yes              
        case sensitive = No            
        change notify timeout = 60    
        client lanman auth = Yes      
        client NTLMv2 auth = No        
        client plaintext auth = Yes    
        client schannel = Auto        
        client signing = auto          
        client use spnego = No        
        comment = SMB server          
        create mask = 0744            
        csc policy = manual            
        deadtime = 0                  
        debug hires timestamp = No    
        debug pid = No                
        debug uid = No                
        default case = lower          
        default devmode = No          
        delete readonly = Yes          
        delete veto files = No        
        directory mask = 0755          
        directory security mask = 0777
        disable netbios = No          
        disable spoolss = No          
        display charset = KOI8-R                                
        dns proxy = Yes                                          
        domain logons = No                                      
        domain master = No                                      
        dont descend = /proc,/dev                                
        dos charset = CP866                                      
        dos filemode = No                                        
        dos filetime resolution = No                            
        dos filetimes = No                                      
        ea support = No                                          
        encrypt passwords = Yes                                  
        enhanced browsing = Yes                                  
        enumports command = No                                  
        fake directory create times = No                        
        fake oplocks = No                                        
        follow symlinks = Yes                                    
        force create mode = 00                                  
        force directory mode = 00                                
        force directory security mode = 00                      
        force security mode = 00                                
        fstype = NTFS                                            
        getwd cache = Yes                                        
        guest account = nobody                                  
        guest ok = No                                            
        guest only = No                                          
        hide dot files = No                                      
        hide special files = No                                  
        hide unreadable = No                                    
        hide unwriteable files = No                              
        host msdfs = No                                          
        hostname lookups = No                                    
        hosts allow = 127.0.0.0/255.0.0.0 192.168.0.0/255.255.0.0
        idmap gid = 10000-20000                                  
        idmap uid = 10000-20000                                  
        inherit acls = Yes                                      
        inherit permissions = Yes                                
        keepalive = 300                                          
        kernel change notify = Yes                              
        kernel oplocks = Yes                                    
        lanman auth = Yes                                        
        large readwrite = Yes                                    
        ldap delete dn = No                                      
        ldap filter = (uid=%u)                                  
        ldap passwd sync = no                      
        ldap port = 636                            
        ldap replication sleep = 1000              
        ldap ssl = Yes                              
        level2 oplocks = Yes                        
        lm announce = Auto                          
        lm interval = 60                            
        load printers = Yes                        
        local master = No                          
        lock directory = /usr/local/samba/var/locks
        lock spin count = 10                        
        lock spin time = 40                        
        locking = Yes                              
        log file = /usr/local/samba/var/sambazzz.log
        log level = 2                              
        logon home = \\%N\%U                        
        logon path = \\%N\%U\profile                
        lpq cache time = 10                        
        machine password timeout = 604800          
        mangle case = No                            
        mangle prefix = 1                          
        mangled names = Yes                        
        mangling char = ~                          
        mangling method = hash2                    
        map acl inherit = No                        
        map archive = Yes                          
        map hidden = No                            
        map system = No                            
        map to guest = Never                        
        max connections = 0                        
        max disk size = 0                          
        max log size = 5000                        
        max mux = 50                                
        max open files = 20000                      
        max print jobs = 1000                      
        max protocol = NT1                          
        max reported print jobs = 0                
        max smbd processes = 0                      
        max ttl = 259200                            
        max wins ttl = 518400                      
        max xmit = 16644                            
        min passwd length = 5                      
        min print space = 0                        
        min protocol = CORE                        
        min wins ttl = 21600                        
        msdfs root = No                                                
        name cache timeout = 660                                      
        name resolve order = lmhosts wins host bcast                  
        netbios name = USRV                                            
        netbios scope = MH                                            
        NIS homedir = No                                              
        nt acl support = Yes                                          
        nt pipe support = Yes                                          
        nt status support = Yes                                        
        ntlm auth = Yes                                                
        null passwords = Yes                                          
        obey pam restrictions = No                                    
        oplock break wait time = 0                                    
        oplock contention limit = 2                                    
        oplocks = Yes                                                  
        os level = 20                                                  
        pam password change = No                                      
        paranoid server security = No                                  
        passdb backend = tdbsam                                        
        passwd chat = *new*password* %n\n *new*password* %n\n *changed*
        passwd chat debug = No                                        
        passwd chat timeout = 2                                        
        password level = 0                                            
        password server = PDC-NETBIOSNAME
        pid directory = /usr/local/samba/var/locks                    
        posix locking = Yes                                            
        preexec close = No                                            
        preferred master = Auto                                        
        preserve case = Yes                                            
        printable = No                                                
        printcap name = cups                                          
        printing = cups                                                
        private dir = /usr/local/samba/private                        
        profile acls = No                                              
        protocol = NT1                                                
        read bmpx = No                                                
        read only = No                                                
        read raw = Yes                                                
        realm = MYDOMAIN.DOM                                        
        restrict anonymous = 0                                        
        root preexec close = No                            
        security = ADS                                      
        security mask = 0777                                
        server schannel = Auto                              
        server signing = Auto                              
        server string = Samba 3.0.4                        
        set directory = No                                  
        share modes = Yes                                  
        short preserve case = Yes                          
        show add printer wizard = Yes                      
        smb passwd file = /usr/local/samba/private/smbpasswd
        smb ports = 445 139                                
        socket address = 0.0.0.0                            
        socket options = IPTOS_LOWDELAY TCP_NODELAY        
        stat cache = Yes                                    
        store dos attributes = No                          
        strict allocate = No                                
        strict locking = Yes                                
        strict sync = No                                    
        sync always = No                                    
        syslog = 1                                          
        syslog only = No                                    
        template homedir = /home/%D/%U                      
        template primary group = nobody                    
        template shell = /bin/false                        
        time offset = 0                                    
        time server = No                                    
        timestamp logs = Yes                                
        unix charset = KOI8-R                              
        unix extensions = Yes                              
        unix password sync = No                            
        update encrypted = Yes                              
        use client driver = No                              
        use mmap = Yes                                      
        use sendfile = No                                  
        use spnego = Yes                                    
        username level = 0                                  
        utmp = No                                          
        valid users = '@MYDOMAIN\Domain Users'            
        wide links = Yes                                    
        winbind cache time = 300                            
        winbind enable local accounts = Yes                
        winbind enum groups = Yes                          
        winbind enum users = Yes                            
        winbind nested groups = Yes                        
        winbind separator = \                              
        winbind trusted domains only = No                  
        winbind use default domain = Yes                    
        winbind uid = 10000-30000
        winbind gid = 10000-30000
        wins proxy = No          
        wins server = my.pdc.ip.address
        wins support = No        
        workgroup = MYDOMAIN
        write cache size = 0    
        write raw = Yes          
        wtmp directory =        
                                
[test]                          
    path = /usr/tmp              
    readonly = false            

usrv# cat /etc/krb5.conf                                    
[libdefaults]                                                
        default_realm = MYDOMAIN.DOM                      
        clockskew = 300                                      
        v4_instance_resolve = false                          
        v4_name_convert = {                                  
                host = {                                    
                        rcmd = host                          
                        ftp = ftp                            
                }                                            
                plain = {                                    
                        something = something-else          
                }                                            
        }                                                    
                                                            
[realms]                                                    
        MYDOMAIN.DOM = {                                  
                kdc = PDC-NETBIOSNAME.MYDOMAIN.DOM                    
                v4_instance_resolve = false                  
        }                                                    
        OTHER.REALM = {                                      
                v4_instance_resolve = false                  
                v4_instance_convert = {                      
                        kerberos = kerberos                  
                        computer = computer.some.other.domain
                }                                            
        }                                                    
[domain_realm]                                              
        .mydomain.dom = MYDOMAIN.DOM                    

usrv# cat /etc/nsswitch.conf | grep winbind
passwd:     files winbind nisplus nis      
group:      files winbind nisplus nis      

usrv# ls /usr/local/lib/*winbind*                                      
/usr/local/lib/lib_nss_winbind.so       /usr/local/lib/nss_winbind.so.1
/usr/local/lib/lib_nss_winbind.so.1     /usr/local/lib/nss_winbind.so.2
/usr/local/lib/lib_nss_winbind.so.2     /usr/local/lib/pam_winbind.so  
/usr/local/lib/nss_winbind.so                                          

usrv# id Guest                                                      
uid=10014(Guest) gid=10006(Domain Guests) groups=10006(Domain Guests)

usrv# id Administrator
uid=10006(Administrator) gid=10005(Domain Users)
groups=10005(Domain Users), 10002(Schema Admins),
10003(Enterprise Admins), 10004(Domain Admins),
10007(Group Policy Creator Owners)

usrv# /samba/bin/smbclient -L \\usrv                      
Password:                                                  
Anonymous login successful                                
Domain=[MYDOMAIN] OS=[Unix] Server=[Samba 3.0.4]        
                                                          
        Sharename       Type      Comment                  
        ---------       ----      -------                  
        test            Disk      SMB server              
        IPC$            IPC       IPC Service (Samba 3.0.4)
        ADMIN$          IPC       IPC Service (Samba 3.0.4)
Anonymous login successful                                
Domain=[MYDOMAIN] OS=[Unix] Server=[Samba 3.0.4]        
                                                          
        Server               Comment                      
        ---------            -------                      
        host01               some host 01
        host02
        PDC-NETBIOSNAME      MYDOMAIN PDC
        USRV                 Samba 3.0.4                  
                                                          
        Workgroup            Master                        
        ---------            -------                      
        MYDOMAIN             PDC-NETBIOSNAME

Maybe, something isn`t correct -- so, I apologized.


"Samba + AC = Failed to verify incoming ticket!"
Отправлено FdF , 31-Май-04 12:27 
Попробывал использовать предложенный конфиг:
вот некоторые строки лога...
Unable to open/create TDB passwd
или
  pdb_getsampwnam: Unable to open TDB passwd (/usr/local/samba/private/passdb.tdb)!
(хотя файл есть и доступен (правда пустой))
при авторизации обычно в логах
user [administrator] -> [administrator] FAILED with error NT_STATUS_NO_SUCH_USER
по других тоже самое

./smbclient -k -L LINUX
session setup failed: NT_STATUS_LOGON_FAILURE

[root@ns bin]# ./smbclient -L LINUX
Password:                                      
Anonymous login successful                    
Domain=[ALVENTA] OS=[ASPLinux 7.3] Server=[Samba 3.0.4]
tree connect failed: NT_STATUS_LOGON_FAILURE  


"Samba + AC = Failed to verify incoming ticket!"
Отправлено mxm , 31-Май-04 14:35 
>Попробывал использовать предложенный конфиг:
>вот некоторые строки лога...
> Unable to open/create TDB passwd
>или
>  pdb_getsampwnam: Unable to open TDB passwd (/usr/local/samba/private/passdb.tdb)!
>(хотя файл есть и доступен (правда пустой))
>при авторизации обычно в логах
>user [administrator] -> [administrator] FAILED with error NT_STATUS_NO_SUCH_USER
>по других тоже самое
>
>./smbclient -k -L LINUX
>session setup failed: NT_STATUS_LOGON_FAILURE
>
>[root@ns bin]# ./smbclient -L LINUX
>Password:
>Anonymous login successful
>Domain=[ALVENTA] OS=[ASPLinux 7.3] Server=[Samba 3.0.4]
>tree connect failed: NT_STATUS_LOGON_FAILURE

Уважаемый, займитесь чтением документации и анализом приведенного
примера. Например, в приведенном конфигурационном файле, опущены
закомментированные строки. Инициализация кербероса тоже желательна.
Вы предлагаете сделать всё за Вас? Пример был "снят" с работающей машины,
если нужны дополнительные листинги -- обращайтесь.


"Samba + AC = Failed to verify incoming ticket!"
Отправлено Pater , 01-Июн-04 08:32 
> Инициализация кербероса тоже желательна.

...Если он будет работать и работать устойчиво...:-(


"Samba + AC = Failed to verify incoming ticket!"
Отправлено nrvalex , 31-Май-04 14:38 
password server = имя  а не ip


"Samba + AC = Failed to verify incoming ticket!"
Отправлено Pater , 01-Июн-04 08:40 
>password server = имя  а не ip

Кстати не важно.
Работает и так и так.
Проверял.
О чем кстати и написано в соотвествующем мане.


"Samba + AC = Failed to verify incoming ticket!"
Отправлено FdF , 04-Июн-04 11:58 
Пока все без успеха...
вот мои данные
плиз....

[global]
acl compatibility = win2k
algorithmic rid base = 1000
allow trusted domains = Yes
announce as = NT
announce version = 4.9
available = Yes
bind interfaces only = No
block size = 1024
blocking locks = Yes
browse list = Yes
browseable = Yes
case sensitive = No
change notify timeout = 60
client lanman auth = Yes
client NTLMv2 auth = No
client plaintext auth = Yes
client schannel = Auto
client signing = auto
client use spnego = No
comment = SMB server
create mask = 0744
csc policy = manual
deadtime = 0
debug hires timestamp = No
debug pid = No
debug uid = No
default case = lower
default devmode = No
delete readonly = Yes
delete veto files = No
directory mask = 0755
directory security mask = 0777
disable netbios = No
disable spoolss = No
display charset = KOI8-R
dns proxy = Yes
domain logons = No
domain master = No
dont descend = /proc,/dev                                
dos charset = CP866                                      
dos filemode = No                                        
dos filetime resolution = No                            
dos filetimes = No                                      
ea support = No                                          
encrypt passwords = Yes                                  
enhanced browsing = Yes                                  
enumports command = No                                  
fake directory create times = No                        
fake oplocks = No                                        
follow symlinks = Yes                                    
force create mode = 00                                  
force directory mode = 00                                
force directory security mode = 00                      
force security mode = 00                                
fstype = NTFS                                            
getwd cache = Yes                                        
guest account = nobody                                  
guest ok = No                                            
guest only = No                                          
hide dot files = No                                      
hide special files = No                                  
hide unreadable = No                                    
hide unwriteable files = No                              
host msdfs = No                                          
hostname lookups = No                                    
hosts allow = 127.0.0.0/255.0.0.0 10.0.0.0/255.255.255.0
idmap gid = 10000-20000                                  
idmap uid = 10000-20000                                  
inherit acls = Yes                                      
inherit permissions = Yes                                
keepalive = 300                                          
kernel change notify = Yes                              
kernel oplocks = Yes
lanman auth = Yes
large readwrite = Yes
#ldap delete dn = No
#ldap filter = (uid=%u)
#ldap passwd sync = no
#ldap port = 636
#ldap replication sleep = 1000
#ldap ssl = Yes
level2 oplocks = Yes
lm announce = Auto
lm interval = 60
#load printers = Yes
local master = No
lock directory = /usr/local/samba/var/locks
lock spin count = 10
lock spin time = 40
locking = Yes
log file = /usr/local/samba/var/sambazzz.log
log level = 2
logon home = \\%N\%U
logon path = \\%N\%U\profile
lpq cache time = 10
machine password timeout = 604800
mangle case = No
mangle prefix = 1
mangled names = Yes
mangling char = ~
mangling method = hash2
map acl inherit = No
map archive = Yes
map hidden = No
map system = No
map to guest = Never
max connections = 0
max disk size = 0
max log size = 5000
max mux = 50
max open files = 20000
#max print jobs = 1000
max protocol = NT1
#max reported print jobs = 0
max smbd processes = 0
max ttl = 259200
max wins ttl = 518400
max xmit = 16644
min passwd length = 5
#min print space = 0
min protocol = CORE
min wins ttl = 21600
msdfs root = No
name cache timeout = 660
name resolve order = lmhosts wins host bcast
netbios name = SERVER3
netbios scope =
NIS homedir = No
nt acl support = Yes
nt pipe support = Yes
nt status support = Yes
ntlm auth = Yes
null passwords = Yes
obey pam restrictions = No
oplock break wait time = 0
oplock contention limit = 2
oplocks = Yes
os level = 20
pam password change = No
paranoid server security = No
passdb backend = tdbsam
passwd chat = *new*password* %n\n *new*password* %n\n *changed*
passwd chat debug = No
passwd chat timeout = 2
password level = 0
password server = server1.alventa.saratov
pid directory = /usr/local/samba/var/locks
posix locking = Yes
preexec close = No
preferred master = Auto
preserve case = Yes
#printable = No
#printcap name = cups
#printing = cups
private dir = /usr/local/samba/private
profile acls = No
protocol = NT1
read bmpx = No
read only = No
read raw = Yes
realm = ALVENTA.SARATOV
restrict anonymous = 0
root preexec close = No
security = ADS
security mask = 0777
server schannel = Auto
server signing = Auto
server string = Samba 3.0.4
set directory = No
share modes = Yes
short preserve case = Yes
#show add printer wizard = Yes
smb passwd file = /usr/local/samba/private/smbpasswd
smb ports = 445 139
#socket address = 0.0.0.0
socket options = IPTOS_LOWDELAY TCP_NODELAY
stat cache = Yes
store dos attributes = No
strict allocate = No
strict locking = Yes
strict sync = No
sync always = No
syslog = 1
syslog only = No
template homedir = /home/%D/%U
template primary group = nobody
template shell = /bin/false
time offset = 0
time server = No
timestamp logs = Yes
unix charset = KOI8-R
unix extensions = Yes
unix password sync = No
update encrypted = Yes
use client driver = No
use mmap = Yes
use sendfile = No
use spnego = Yes
username level = 0
username map = /usr/local/samba/lib/smbusers
utmp = No
#valid users = 'ALVENTA@\Domain Users'
wide links = Yes
winbind cache time = 300
winbind enable local accounts = Yes
winbind enum groups = Yes
winbind enum users = Yes
winbind nested groups = Yes
winbind separator = \
winbind trusted domains only = No
winbind use default domain = Yes
winbind uid = 10000-30000
winbind gid = 10000-30000
wins proxy = No
wins server = 10.0.0.10
wins support = No
workgroup = ALVENTA
write cache size = 0
write raw = Yes
wtmp directory =

smbusers
# Unix_name = SMB_name1 SMB_name2 ...
root = administrator admin worn
nobody = guest pcguest smbguest

[2004/06/02 13:12:57, 2] lib/access.c:check_access(322)
  Allowed connection from  (10.0.0.101)
[2004/06/02 13:12:57, 2] smbd/sesssetup.c:setup_new_vc_session(602)
  setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2004/06/02 13:12:57, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
  Failed to verify incoming ticket!
[2004/06/02 13:12:57, 2] smbd/sesssetup.c:setup_new_vc_session(602)
  setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2004/06/02 13:12:57, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
  Failed to verify incoming ticket!
[2004/06/02 13:12:57, 2] smbd/server.c:exit_server(568)
  Closing connections
[2004/06/02 13:13:03, 2] lib/access.c:check_access(322)
  Allowed connection from  (10.0.0.101)
[2004/06/02 13:13:03, 2] lib/access.c:check_access(322)
  Allowed connection from  (10.0.0.101)
[2004/06/02 13:13:03, 2] smbd/reply.c:reply_special(207)
  netbios connect: name1=SERVER3         name2=COMPUTER01    
[2004/06/02 13:13:03, 2] smbd/reply.c:reply_special(213)
  netbios connect: local=server3 remote=computer01, name type = 0
[2004/06/02 13:13:03, 2] smbd/server.c:exit_server(568)
  Closing connections
[2004/06/02 13:13:04, 2] smbd/sesssetup.c:setup_new_vc_session(602)
  setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2004/06/02 13:13:04, 1] smbd/sesssetup.c:reply_spnego_kerberos(174)
  Failed to verify incoming ticket!
[2004/06/02 13:13:04, 2] smbd/server.c:exit_server(568)
  Closing connections

klist - все нормально.
пользователей wbinfo -i выдает.

[root@ns root]# id Guest                                            
uid=10014(Guest) gid=10006(Domain Guests) úαπ»»δ=10006(Domain Guests)

[root@ns root]# id Administrator                                                
uid=10006(Administrator) gid=10005(Domain Users) groups=10005(Domain Users),1000
2(Schema Admins),10003(Enterprise Admins),10004(Domain Admins),10007(Group Policy Creator Owners)                                                              

HELP!


"Samba + AC = Failed to verify incoming ticket!"
Отправлено funkblaster , 28-Июн-04 16:11 
Пример от juDge точно рабочий. По крайней мере у меня он заработал, а до этого была такая же ошибка как у автора топика. Странно...всё делал по доке с samba.org. Буду разбираться в чём было дело.

"Samba + AC = Failed to verify incoming ticket!"
Отправлено Vasya , 21-Июл-04 15:04 
>Пример от juDge точно рабочий. По крайней мере у меня он заработал,
>а до этого была такая же ошибка как у автора топика.
>Странно...всё делал по доке с samba.org. Буду разбираться в чём было
>дело.


Люди, немного о другом, но рядом лежащем:

КТО В КУРСЕ, помогите пожалуйста понять такую вещь:
ситуация довольно стандартная - нужно авторизовывать доменных (ADS) юзерей на сквиде
при добавлении самбы в ADS я делаю kinit USER@REALM, и получаю tgt, который действителен определенное время (скажем 10 часов)
после этого я добавляю самбу в домен (все пучком, заметьте, доменные юзери видны и вообще все прекрасно жужжит, не кашляет)
сквид тоже жужжит замечательно, пыхтит, авторизует - песня

НО! по прошествии 10 часов билетик (tgt) честно экспайрится и дальше начинается что? - непонятки
(в т.ч. и описанная в топике проблема при попытках коннекта к этой самбе других тачек, а также честный рассказ самбы в логах что де билетик то просроченный, айяйяй)
делаю руками kinit USER@REALM - получаем свеженький билетик и жужжим дальше ~10 часов без вопросов

может я где-то проскочил этот момент в манах, доках, хелпах и пр., так что ВНИМАНИЕ ВОПРОС:

кто или что должно заставить самбу (или кого?) получить новый, валидный tgt автоматом?

ибо не верится мне что каждые 10 часов к серверу должен подбегать человечек и вколачивать kinit USER@REALM, как то это, мягко говоря, недешево, ненадежно и непрактично...