3.2.6 SeMachineAccountPrivilege regression?

William Jojo w.jojo at hvcc.edu
Wed Jan 14 17:42:08 GMT 2009



---- Original message ----
>Date: Tue, 13 Jan 2009 17:48:50 -0800
>From: Jeremy Allison <jra at samba.org>  
>Subject: Re: 3.2.6 SeMachineAccountPrivilege regression?  
>To: William Jojo <w.jojo at hvcc.edu>
>Cc: samba-technical at samba.org
>
>On Tue, Jan 13, 2009 at 08:46:23PM -0500, William Jojo wrote:
>> 
>> When trying to join XP-Sp2 to Samba 3.2.6 on AIX, I get an "access denied" response. The user has SeMachineAccountPrivilege. The root user can always join.
>> 
>> To my knowledge this worked ok in 3.2.4 (haven't tested this item in 3.2.5 yet).
>> 
>> Snip from log:
>> 
>> [2009/01/13 16:01:53,  3] smbd/ipc.c:api_fd_reply(345)
>>   Got API command 0x26 on pipe "samr" (pnum 7189)
>> [2009/01/13 16:01:53,  3] rpc_server/srv_pipe_hnd.c:free_pipe_context(519)
>>   free_pipe_context: destroying talloc pool of size 0
>> [2009/01/13 16:01:53,  3] rpc_server/srv_pipe.c:api_rpcTNP(2304)
>>   api_rpcTNP: rpc command: SAMR_QUERYUSERINFO
>> [2009/01/13 16:01:53,  2] rpc_server/srv_samr_nt.c:access_check_samr_function(246)
>>   _samr_QueryUserInfo: ACCESS DENIED (granted: 00000d04f4;  required: 0000000200)
>> [2009/01/13 16:01:53,  3] rpc_server/srv_pipe_hnd.c:free_pipe_context(519)
>>   free_pipe_context: destroying talloc pool of size 0
>> 
>> 
>> Is this related to the usermgr.exe bug that I saw Jeremy comment on in another thread? Sorry for the late report, I'm a bit behind in my testing. :-)
>
>Yes it is. Can you test the latest 3-2-test git tree and see
>if this is now fixed (it should be).
>

Jeremy,

I pulled the specific patch from git and applied to 3.2.6. Works great! Thanks a bunch!


Cheers,
Bill



>Thanks,
>
>Jeremy.


More information about the samba-technical mailing list