Kerberos dc event logs, by default root requesting krb5 ticket
vigneshdhanraj.g at gmail.com
Tue Jun 7 17:19:48 UTC 2016
I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
A Kerberos authentication ticket (TGT) was requested.
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID
There is no user as root in my DC and there is no functionality breakup. It
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with my
system. Audit failure logs are dumped.
I think it might be a regression issue from samba while fixing badlock.
could anyone help regarding this issue?
More information about the samba-technical