Re: [Samba-it] PDC Ubuntu 9.04 con Samba 3.3.2 non riesco più a connettere alcuni utenti.

robalda robalda at gmail.com
Mon Sep 7 10:08:26 MDT 2009


Il giorno 07 settembre 2009 17.17, Paolo Sala<piviul at riminilug.it> ha scritto:
> robalda scrisse in data 07/09/2009 16:48:
>> Il giorno 07 settembre 2009 16.34, ivan re<re.ivan at gmail.com> ha scritto:
>>
>>> controllando i primi risultati su google sembrerebbe trattarsi di un
>>> problema legato alle porte 139 e 445.
>>>
>>> Una soluzione, che trovi all'indirizzo
>>> http://lists.samba.org/archive/samba/2005-April/104043.html, consiglia di
>>> fare un drop con iptable della porta 445.
>>>
>>> Ivan
>>>
>>
>> Grazie per l'interessamento.
>>
>> Prima di postare ho fatto anche io una ricerca su Google e ho provato
>> senza successo.
>>
>> Il fatto che gli altri computer, per adesso non danno problemi, mi
>> lascia perplesso e gli stessi computer che ora non si connettono ieri
>> funzionavano perfettamente, e sul computer non riesco a loggare nessun
>> utente del dominio.
>>
> Ma sul client il firewall è attivo?
>
> Piviul
> _______________________________________________
> Samba-it mailing list
> Samba-it at xsec.it
> https://lists.xsec.it/mailman/listinfo/samba-it
>

No no è attivo, e ho provato a droppare la porta 445

ho aumentato il log a 3 ecco il risultato

[2009/09/07 18:04:42,  3] smbd/process.c:process_smb(1554)
  Transaction 0 of length 137 (0 toread)
[2009/09/07 18:04:42,  3] smbd/process.c:switch_message(1378)
  switch message SMBnegprot (pid 7028) conn 0x0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [PC NETWORK PROGRAM 1.0]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [LANMAN1.0]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [Windows for Workgroups 3.1a]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [LM1.2X002]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [LANMAN2.1]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(569)
  Requested protocol [NT LM 0.12]
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_nt1(392)
  using SPNEGO
[2009/09/07 18:04:42,  3] smbd/negprot.c:reply_negprot(674)
  Selected protocol NT LM 0.12
[2009/09/07 18:04:42,  3] smbd/process.c:process_smb(1554)
  Transaction 1 of length 240 (0 toread)
[2009/09/07 18:04:42,  3] smbd/process.c:switch_message(1378)
  switch message SMBsesssetupX (pid 7028) conn 0x0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X(1412)
  wct=12 flg2=0xc807
[2009/09/07 18:04:42,  2] smbd/sesssetup.c:setup_new_vc_session(1368)
  setup_new_vc_session: New VC == 0, if NT4.x compatible we would
close all old resources.
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(1175)
  Doing spnego session setup
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(1210)
  NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows
2002 5.1] PrimaryDomain=[]
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_spnego_negotiate(802)
  reply_spnego_negotiate: Got secblob of size 40
[2009/09/07 18:04:42,  3] libsmb/ntlmssp.c:debug_ntlmssp_flags(62)
  Got NTLMSSP neg_flags=0xa2088207
[2009/09/07 18:04:42,  3] smbd/process.c:process_smb(1554)
  Transaction 2 of length 270 (0 toread)
[2009/09/07 18:04:42,  3] smbd/process.c:switch_message(1378)
  switch message SMBsesssetupX (pid 7028) conn 0x0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X(1412)
  wct=12 flg2=0xc807
[2009/09/07 18:04:42,  2] smbd/sesssetup.c:setup_new_vc_session(1368)
  setup_new_vc_session: New VC == 0, if NT4.x compatible we would
close all old resources.
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(1175)
  Doing spnego session setup
[2009/09/07 18:04:42,  3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(1210)
  NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows
2002 5.1] PrimaryDomain=[]
[2009/09/07 18:04:42,  3] libsmb/ntlmssp.c:ntlmssp_server_auth(747)
  Got user=[] domain=[] workstation=[DA-TREBITSCH] len1=1 len2=0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] auth/auth.c:check_ntlm_password(220)
  check_ntlm_password:  Checking password for unmapped user
[]\[]@[DA-XXXXXXXX] with the new password interface
[2009/09/07 18:04:42,  3] auth/auth.c:check_ntlm_password(223)
  check_ntlm_password:  mapped user is: [XXXXXXXX]\[]@[DA-XXXXXXXX]
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] auth/auth.c:check_ntlm_password(269)
  check_ntlm_password: guest authentication for user [] succeeded
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] lib/privileges.c:get_privileges(63)
  get_privileges: No privileges assigned to SID
[S-1-5-21-675888318-2279333937-590520917-501]
[2009/09/07 18:04:42,  3] lib/privileges.c:get_privileges(63)
  get_privileges: No privileges assigned to SID [S-1-5-2]
[2009/09/07 18:04:42,  3] lib/privileges.c:get_privileges(63)
  get_privileges: No privileges assigned to SID [S-1-5-32-546]
[2009/09/07 18:04:42,  3] libsmb/ntlmssp_sign.c:ntlmssp_sign_init(337)
  NTLMSSP Sign/Seal - Initialising with flags:
[2009/09/07 18:04:42,  3] libsmb/ntlmssp.c:debug_ntlmssp_flags(62)
  Got NTLMSSP neg_flags=0xa2088205
[2009/09/07 18:04:42,  3] smbd/password.c:register_existing_vuid(289)
  register_existing_vuid: User name: nobody	Real name: nobody
[2009/09/07 18:04:42,  3] smbd/password.c:register_existing_vuid(299)
  register_existing_vuid: UNIX uid 65534 is UNIX user nobody, and will
be vuid 100
[2009/09/07 18:04:42,  3] smbd/process.c:process_smb(1554)
  Transaction 3 of length 86 (0 toread)
[2009/09/07 18:04:42,  3] smbd/process.c:switch_message(1378)
  switch message SMBtconX (pid 7028) conn 0x0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:push_sec_ctx(224)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/uid.c:push_conn_ctx(388)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:pop_sec_ctx(432)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/service.c:find_forced_group(614)
  Forced group users
[2009/09/07 18:04:42,  3] smbd/service.c:make_connection_snum(871)
  Connect path is '/tmp' for service [IPC$]
[2009/09/07 18:04:42,  0] smbd/service.c:make_connection_snum(897)
  make_connection: connection to IPC$ denied due to security descriptor.
[2009/09/07 18:04:42,  3] smbd/error.c:error_packet_set(61)
  error packet at smbd/reply.c(724) cmd=117 (SMBtconX) NT_STATUS_ACCESS_DENIED
[2009/09/07 18:04:42,  3] smbd/process.c:process_smb(1554)
  Transaction 4 of length 43 (0 toread)
[2009/09/07 18:04:42,  3] smbd/process.c:switch_message(1378)
  switch message SMBulogoffX (pid 7028) conn 0x0
[2009/09/07 18:04:42,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:42,  3] smbd/reply.c:reply_ulogoffX(1972)
  ulogoffX vuid=100
[2009/09/07 18:04:53,  3] smbd/process.c:smbd_process(1930)
  receive_message_or_smb failed: NT_STATUS_END_OF_FILE, exiting
[2009/09/07 18:04:53,  3] smbd/sec_ctx.c:set_sec_ctx(324)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/09/07 18:04:53,  3] smbd/connection.c:yield_connection(31)
  Yielding connection to
[2009/09/07 18:04:53,  3] smbd/server.c:exit_server_common(964)
  Server exit (normal exit)



More information about the samba-it mailing list