[Samba] Re: Strange Usermapping problem with 3.0.23b
Matthias Schündehütte
msch at snafu.de
Sat Aug 19 07:33:44 GMT 2006
Hi,
here some further informations:
I compared the logfiles of a working and a non-working session and
found differences immediatly before the usermapping occurs:
in the non-working session:
[2006/08/18 15:12:29, 3]
libads/kerberos_verify.c:ads_secrets_verify_ticket(261)
ads_secrets_verify_ticket: enc type [1] failed to decrypt with error
Message size is incompatible with encryption type
[2006/08/18 15:12:29, 3]
libads/kerberos_verify.c:ads_secrets_verify_ticket(261)
ads_secrets_verify_ticket: enc type [3] failed to decrypt with error
Message size is incompatible with encryption type
[2006/08/18 15:12:29, 3] smbd/sesssetup.c:reply_spnego_kerberos(207)
Ticket name is [SchuendeMa at WW004.SIEMENS.NET]
[2006/08/18 15:12:29, 3] smbd/map_username.c:map_username(155)
Mapped user WW004\SchuendeMa to matthias
[2006/08/18 15:12:29, 3] smbd/map_username.c:map_username(155)
Mapped user WW004\matthias to smb
In the working session, this 'failure to decrypt' does not occur and
the name of my workstaton is correctly detected:
[2006/08/18 15:10:56, 3] libsmb/ntlmssp.c:ntlmssp_server_auth(672)
Got user=[SchuendeMa] domain=[WW004] workstation=[B10R622C] len1=24 len2=24
So why does this decryption work if I use the IP-Address of the server
or a non-AD DNS-name and fail if I use the WINS- or AD-DNS name?
--
Ciao/BSD - Matthias
Matthias Schuendehuette <msch [at] snafu.de>, Berlin (Germany)
PGP-Key at <pgp.mit.edu> and <wwwkeys.de.pgp.net> ID: 0xDDFB0A5F
More information about the samba
mailing list