[Samba] wbinfo -t error when samba server is restarted and windows 2000 domain server keeps running

Urik urik9 at siol.net
Wed Sep 13 14:52:03 GMT 2006


I allways use 'net rpc join' - allways with 'rpc' option. I did not run 
'net join' when machine is working normally.
By mistake I included content of smb.conf that was made for testing. 
"Production" smb.conf has workgroup = METAL, other setting are same.

Felipe Augusto van de Wiel pravi:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 09/11/2006 11:50 AM, Urik escreveu:
>   
>> Hello,
>> that is my first posting and I hope I provided enough details.
>>     
>
> 	I thought that was your second post. :-)
>
>
>   
>> 1) system: (SLES 9) Linux mp1 2.6.5-7.193-s390x #1 SMP Wed Jul 20
>> 14:39:18 UTC 2005 s390x s390x s390x GNU/Linux
>>
>> 2) samba version:
>>
>> samba-doc-3.0.20b-3.4
>> samba-client-3.0.20b-3.4
>> samba-winbind-3.0.20b-3.4
>> samba-3.0.20b-3.4
>>
>> 3) smb.conf:
>>
>> # Samba config file created using SWAT
>> # from 172.16.8.1 (172.16.8.1)
>> # Date: 2006/08/27 11:38:37
>>
>> [global]
>>        workgroup = WGRP
>>        security = DOMAIN
>>        map to guest = Bad User
>>        username map = /etc/samba/smbusers
>>        socket options = SO_KEEPALIVE IPTOS_LOWDELAY TCP_NODELAY
>> SO_SNDBUF=14596 SO_RCVBUF=14596
>>        logon path = \\%L\profiles\.msprofile
>>        logon drive = P:
>>        logon home = \\%L\%U\.9xprofile
>>        domain master = No
>>        wins server = 172.16.2.100
>>        ldap idmap suffix = ou=Idmap
>>        ldap machine suffix = ou=Computers
>>        ldap suffix = dc=example,dc=com
>>        ldap ssl = no
>>        idmap uid = 10000-20000
>>        idmap gid = 10000-20000
>>        winbind use default domain = Yes
>>        printer admin = @ntadmin, root, administrator
>>        cups options = raw
>>     
> [...]
>
> 	Did you join the machine to the domain?
>
> 	I saw that you always do a 'net rpc join' when you have problems,
> but did you actually just run a 'net join' before, when the machine is
> working under normal circunstances?
>
>
>   
>> 4) log.wb-WGRP from last power failure and increased debug level
>>
>> [2006/08/26 16:42:31, 3] lib/util.c:fcntl_lock(1826)
>>  fcntl_lock: fcntl lock gave errno 11 (Resource temporarily unavailable)
>> [2006/08/26 16:42:31, 3] lib/util.c:fcntl_lock(1845)
>>  fcntl_lock: lock failed at offset 0 count 1 op 6 type 0 (Resource
>> temporarily unavailable)
>> [2006/08/26 16:42:31, 3] nsswitch/winbindd_cm.c:cm_get_ipc_userpass(105)
>>  cm_get_ipc_userpass: No auth-user defined
>> [2006/08/26 16:42:31, 3] rpc_parse/parse_lsa.c:lsa_io_sec_qos(181)
>>  lsa_io_sec_qos: length c does not match size 8
>> [2006/08/26 16:42:31, 3]
>> nsswitch/winbindd_misc.c:winbindd_dual_list_trusted_domains(124)
>>  [ 1889]: list trusted domains
>> [2006/08/26 16:42:31, 3] nsswitch/winbindd_rpc.c:trusted_domains(837)
>>  rpc: trusted_domains
>> [2006/08/26 16:42:31, 3] rpc_parse/parse_lsa.c:lsa_io_sec_qos(181)
>>  lsa_io_sec_qos: length c does not match size 8
>> [2006/08/26 16:43:51, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(607)
>>  [ 1889]: pam auth crap domain: METAL user: user1
>>     
>
> 	That's strange. You smb.conf says 'workgroup = WGRP' but
> your logs says 'domain: METAL'. Are you sure on that one?
>
>
>   
>> [2006/08/26 16:43:51, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(667)
>>  could not open handle to NETLOGON pipe (error: NT_STATUS_ACCESS_DENIED)
>> [2006/08/26 16:43:51, 2]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(801)
>>  NTLM CRAP authentication for user [METAL]\[user1] returned
>> NT_STATUS_ACCESS_DENIED (PAM: 4)
>> [2006/08/26 16:43:57, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(607)
>>  [ 1889]: pam auth crap domain: METAL user: user1
>> [2006/08/26 16:43:57, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(667)
>>  could not open handle to NETLOGON pipe (error: NT_STATUS_ACCESS_DENIED)
>> [2006/08/26 16:43:57, 2]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(801)
>>  NTLM CRAP authentication for user [METAL]\[user1] returned
>> NT_STATUS_ACCESS_DENIED (PAM: 4)
>> [2006/08/26 16:43:57, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(607)
>>  [ 1889]: pam auth crap domain: METAL user: user1
>> [2006/08/26 16:43:57, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(667)
>>  could not open handle to NETLOGON pipe (error: NT_STATUS_ACCESS_DENIED)
>> [2006/08/26 16:43:57, 2]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(801)
>>  NTLM CRAP authentication for user [METAL]\[user1] returned
>> NT_STATUS_ACCESS_DENIED (PAM: 4)
>> [2006/08/26 16:43:58, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(607)
>>  [ 1889]: pam auth crap domain: METAL user: user1
>> [2006/08/26 16:43:58, 3]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(667)
>>  could not open handle to NETLOGON pipe (error: NT_STATUS_ACCESS_DENIED)
>> [2006/08/26 16:43:58, 2]
>> nsswitch/winbindd_pam.c:winbindd_dual_pam_auth_crap(801)
>>  NTLM CRAP authentication for user [METAL]\[user1] returned
>> NT_STATUS_ACCESS_DENIED (PAM: 4)
>> .....
>>
>> Last four lines are repeated several 100 times for different users
>> trying to access samba share.
>>
>> Thank you all for your help.
>>
>> Urik
>>     
>
> 	I hope this helps.
>
> 	Kind regards,
>
> - --
> Felipe Augusto van de Wiel <felipe at paranacidade.org.br>
> Coordenadoria de Tecnologia da Informação (CTI) - SEDU/PARANACIDADE
> http://www.paranacidade.org.br/           Phone: (+55 41 3350 3300)
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
> Comment: Using GnuPG with Debian - http://enigmail.mozdev.org
>
> iD8DBQFFCAcdCj65ZxU4gPQRAsoOAJ4/B528xAcOH5dbEyjTKEbYsvmiUwCgkGiZ
> vfpO9KRstDySe6btBF0mbhY=
> =9IXw
> -----END PGP SIGNATURE-----
>   



More information about the samba mailing list