[Samba] Problem: User authentication stopped working

Chris Osicki osk at admin.swisscom-mobile.ch
Thu May 7 18:33:34 GMT 2009


Hi

I have several Samba servers which have been running for almost two
years without any problem.
Recently I rebooted one of those servers and have the following
problem: the join to the domain is OK but all user authentications
fail. I mean nobody can "connect" a share.
The system I rebooted is half of a two node cluster, the other
node with exactly the same configuration, up 230 days, (still?) 
works OK. 
As if something cached would get lost during reboot and couldn't be
reestablished.

These systems are:
Red Hat Enterprise Linux AS release 4 (Nahant Update 4)
samba3-winbind-3.0.24-33
samba3-3.0.24-33

I know, this version is a bit dated but haven't had any reason to
upgrade. 

Below is a part of the logfile. It's far below my know-how to interpret
it correctly.
Something must have changed on the domain controllers (what is very
difficult to find out in this environment), I guess, and Samba cannot 
cope with.

I would be very thankfull for any help.

Thanks for your time.

Regards,
Chris

[2009/05/05 13:37:13, 6] param/loadparm.c:lp_file_list_changed(2998)
  lp_file_list_changed()
  file /etc/samba/smb.conf.nfsv2 -> /etc/samba/smb.conf.nfsv2  last
mod_time: Thu Apr 30 15:11:26 2009

[2009/05/05 13:37:13, 5] auth/auth_util.c:make_user_info_map(161)
  make_user_info_map: Mapping user [CORPROOT]\[tgdosch1] from
workstation [MSILYNFS2]
[2009/05/05 13:37:13, 5] auth/auth_util.c:make_user_info(75)
  attempting to make a user_info for tgdosch1 (tgdosch1)
[2009/05/05 13:37:13, 5] auth/auth_util.c:make_user_info(85)
  making strings for tgdosch1's user_info struct
[2009/05/05 13:37:13, 5] auth/auth_util.c:make_user_info(117)
  making blobs for tgdosch1's user_info struct
[2009/05/05 13:37:13, 10] auth/auth_util.c:make_user_info(135)
  made an encrypted user_info for tgdosch1 (tgdosch1)
[2009/05/05 13:37:13, 3] auth/auth.c:check_ntlm_password(221)
  check_ntlm_password:  Checking password for unmapped user
[CORPROOT]\[tgdosch1]@[MSILYNFS2] with the new password inter
face
[2009/05/05 13:37:13, 3] auth/auth.c:check_ntlm_password(224)
  check_ntlm_password:  mapped user is:
[CORPROOT]\[tgdosch1]@[MSILYNFS2]
[2009/05/05 13:37:13, 10] auth/auth.c:check_ntlm_password(233)
  check_ntlm_password: auth_context challenge created by random
[2009/05/05 13:37:13, 10] auth/auth.c:check_ntlm_password(235)
  challenge is:
[2009/05/05 13:37:13, 5] lib/util.c:dump_data(2222)
  [000] 48 88 C5 FE 02 2D 12 F1                           H.Ã
þ.-.ñ
[2009/05/05 13:37:13, 10] auth/auth.c:check_ntlm_password(261)
  check_ntlm_password: guest had nothing to say
[2009/05/05 13:37:13, 8] lib/util.c:is_myname(2043)
  is_myname("CORPROOT") returns 0
[2009/05/05 13:37:13, 6] auth/auth_sam.c:check_samstrict_security(414)
  check_samstrict_security: CORPROOT is not one of my local names
(ROLE_DOMAIN_MEMBER)
[2009/05/05 13:37:13, 10] auth/auth.c:check_ntlm_password(261)
  check_ntlm_password: sam had nothing to say
[2009/05/05 13:37:13, 3] smbd/sec_ctx.c:push_sec_ctx(208)
  push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2009/05/05 13:37:13, 3] smbd/uid.c:push_conn_ctx(345)
  push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2009/05/05 13:37:13, 3] smbd/sec_ctx.c:set_sec_ctx(241)
  setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2009/05/05 13:37:13, 5] auth/auth_util.c:debug_nt_user_token(448)
  NT user token: (NULL)
[2009/05/05 13:37:13, 5] auth/auth_util.c:debug_unix_user_token(474)
  UNIX token of user 0
  Primary group is 0 and contains 0 supplementary groups
[2009/05/05 13:37:13, 3] smbd/sec_ctx.c:pop_sec_ctx(339)
  pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2009/05/05 13:37:13, 5] auth/auth.c:check_ntlm_password(273)
  check_ntlm_password: winbind authentication for user [tgdosch1] FAILED
with error NT_STATUS_LOGON_FAILURE
[2009/05/05 13:37:13, 2] auth/auth.c:check_ntlm_password(319)
  check_ntlm_password:  Authentication for user [tgdosch1] -> [tgdosch1]
FAILED with error NT_STATUS_LOGON_FAILURE
[2009/05/05 13:37:13, 5] auth/auth_util.c:free_user_info(1867)
  attempting to free (and zero) a user_info structure
[2009/05/05 13:37:13, 10] auth/auth_util.c:free_user_info(1871)
  structure was created for tgdosch1
[2009/05/05 13:37:13, 3] smbd/error.c:error_packet(146)
  error packet at smbd/sesssetup.c(99) cmd=115 (SMBsesssetupX)
NT_STATUS_LOGON_FAILURE
[2009/05/05 13:37:13, 5] lib/util.c:show_msg(485)


-- 

Chris Osicki osk at osk.ch
Dipl. Informatik-Ing. HTL



More information about the samba mailing list