[Samba] winbindd authentication fails with NT_STATUS_RPC_SEC_PKG_ERROR intermittently

Rowland Penny rpenny at samba.org
Fri Jun 16 09:20:46 UTC 2023



On 16/06/2023 08:56, Bharath Bheemarasetti via samba wrote:
> I made this change and it makes some difference but doesn't fix the
> issue entirely. Earlier the auth calls used to fail in around a day
> which has increased to 2 days now after which the auth calls fail with
> NT_STATUS_RPC_SEC_PKG_ERROR and winbind needs to be restarted for it
> to work. We use NTLMv2 for authentication and using the ntlm_auth tool
> (https://www.samba.org/samba/docs/current/man-html/ntlm_auth.1.html)
> returns the same NT_STATUS_RPC_SEC_PKG_ERROR error as well while
> wbinfo -i returns the correct user info.
> 
> Is there anything else that can be done to fix this permanently?

I do not use use ntlm_auth, but doesn't it require:

ntlm auth = mschapv2-and-ntlmv2-only

Or

ntlm auth = yes

in smb.conf ?

I suggest you read the 'ntlm auth' parameter in 'man smb.conf'

Rowland



More information about the samba mailing list