[Samba] Re: Strange Usermapping problem with 3.0.23b

Matthias Schündehütte msch at snafu.de
Sat Aug 19 07:33:44 GMT 2006


Hi,

here some further informations:

I compared the logfiles of a working and a non-working session and 
found differences immediatly before the usermapping occurs:

in the non-working session:

[2006/08/18 15:12:29, 3] 
libads/kerberos_verify.c:ads_secrets_verify_ticket(261)
  ads_secrets_verify_ticket: enc type [1] failed to decrypt with error 
Message size is incompatible with encryption type
[2006/08/18 15:12:29, 3] 
libads/kerberos_verify.c:ads_secrets_verify_ticket(261)
  ads_secrets_verify_ticket: enc type [3] failed to decrypt with error 
Message size is incompatible with encryption type
[2006/08/18 15:12:29, 3] smbd/sesssetup.c:reply_spnego_kerberos(207)
  Ticket name is [SchuendeMa at WW004.SIEMENS.NET]
[2006/08/18 15:12:29, 3] smbd/map_username.c:map_username(155)
  Mapped user WW004\SchuendeMa to matthias
[2006/08/18 15:12:29, 3] smbd/map_username.c:map_username(155)
  Mapped user WW004\matthias to smb



In the working session, this 'failure to decrypt' does not occur and 
the name of my workstaton is correctly detected:

[2006/08/18 15:10:56, 3] libsmb/ntlmssp.c:ntlmssp_server_auth(672)
  Got user=[SchuendeMa] domain=[WW004] workstation=[B10R622C] len1=24 len2=24


So why does this decryption work if I use the IP-Address of the server 
or a non-AD DNS-name and fail if I use the WINS- or AD-DNS name?

-- 
Ciao/BSD - Matthias

Matthias Schuendehuette <msch [at] snafu.de>, Berlin (Germany)
PGP-Key at <pgp.mit.edu> and <wwwkeys.de.pgp.net> ID: 0xDDFB0A5F




More information about the samba mailing list