Event log 4768 audit failure
vigneshdhanraj.g at gmail.com
Tue Jun 14 09:00:54 UTC 2016
Is there any patch for it?
On Fri, Jun 10, 2016 at 12:36 AM, VigneshDhanraj G <
vigneshdhanraj.g at gmail.com> wrote:
> Thanks uri, make that happen.
> On Wed, Jun 8, 2016 at 11:58 PM, Uri Simchoni <uri at samba.org> wrote:
>> On 06/08/2016 06:38 PM, VigneshDhanraj G wrote:
>> > Hi all,
>> > Hi all,
>> > I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing
>> > amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
>> > A Kerberos authentication ticket (TGT) was requested.
>> > Account Information:
>> > Account Name: root
>> > Supplied Realm Name: TEST.LOCAL
>> > User ID: NULL SID
>> > Service Information:
>> > Service Name: krbtgt/TEST.LOCAL
>> > Service ID: NULL SID
>> > There is no user as root in my DC and there is no functionality
>> breakup. It
>> > is getting correct user name .But, by default first kerberos ticket
>> > requested by root. whenever samba is restarted or communicating with my
>> > system. Audit failure logs are dumped.
>> > I think it might be a regression issue from samba while fixing badlock.
>> > could anyone help regarding this issue?
>> Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled
>> Heimdal), but have zero time to work on it at the moment. If none gets
>> there first I'll fix it in a couple of weeks (or at least look into it).
>> Haven't seen any functional impact until you mentioned that audit log.
More information about the samba-technical