[Samba] Samba Member NT_STATUS_NETWORK_SESSION_EXPIRED

Oliver Werner oliver.werner at kontrast.de
Wed Sep 28 13:54:18 UTC 2016


Any Ideas what i can test for fix the problem with kerberos…?




> Am 27.09.2016 um 09:05 schrieb Oliver Werner via samba <samba at lists.samba.org>:
> 
> Hi Rowland,
> 
> i have tested unjion and join again the member. But that looks not better :/. Any ideas?
> 
> Best wishes
> OLIVER WERNER
> Systemadministrator
> 
> 
> 
>> Am 23.09.2016 um 14:38 schrieb Oliver Werner via samba <samba at lists.samba.org <mailto:samba at lists.samba.org>>:
>> 
>> Yes the file /etc/krb5.keytab is exists.
>> 
>> You mean this lines?
>> 
>>      dedicated keytab file = /etc/krb5.keytab
>>      kerberos method = secrets and keytab
>>      winbind refresh tickets = yes
>> 
>> there was edits when i join the system.
>> OLIVER WERNER
>> Systemadministrator
>> 
>> 
>> 
>> 
>>> Am 23.09.2016 um 08:55 schrieb Rowland Penny via samba <samba at lists.samba.org <mailto:samba at lists.samba.org> <mailto:samba at lists.samba.org <mailto:samba at lists.samba.org>>>:
>>> 
>>> On Fri, 23 Sep 2016 07:25:40 +0200
>>> Oliver Werner <oliver.werner at kontrast.de <mailto:oliver.werner at kontrast.de> <mailto:oliver.werner at kontrast.de <mailto:oliver.werner at kontrast.de>> <mailto:oliver.werner at kontrast.de <mailto:oliver.werner at kontrast.de> <mailto:oliver.werner at kontrast.de <mailto:oliver.werner at kontrast.de>>>> wrote:
>>> 
>>>> hi,
>>>> 
>>>> now after 10 hours my samba has the next crash and need to restart
>>>> winbind.
>>>> 
>>>> Here are the list/kinit:
>>>> 
>>>> # before kinit
>>>> pl0024:~# klist
>>>> klist: Credentials cache file '/tmp/krb5cc_0' not found
>>>> pl0024:~# kinit Administrator
>>>> Password for Administrator at HQ.KONTRAST:
>>>> pl0024:~# klist
>>>> Ticket cache: FILE:/tmp/krb5cc_0
>>>> Default principal: Administrator at HQ.KONTRAST
>>>> 
>>>> Valid starting       Expires              Service principal
>>>> 23.09.2016 07:21:04  23.09.2016 17:21:04
>>>> krbtgt/HQ.KONTRAST at HQ.KONTRAST renew until 24.09.2016 07:20:56
>>>> 
>>>> thats the only one kerberos cache file in /tmp right now.
>>>> 
>>>> looks like kerberos does not renew the ticket :(?
>>>> OLIVER WERNER
>>>> Systemadministrator
>>>> 
>>> 
>>> failing after 10hrs is very probably kerberos related, you should have
>>> a kerberos cache in /tmp for the machine. Does /etc/krb5.keytab exist ?
>>> Did you have the kereberos lines in smb.conf when you joined the
>>> machine ?
>>> 
>>> Rowland
>>> 
>>> -- 
>>> To unsubscribe from this list go to the following URL and read the
>>> instructions:  https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba> <https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba>> <https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba><https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba>>>
>> -- 
>> To unsubscribe from this list go to the following URL and read the
>> instructions:  https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba> <https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba>>
> -- 
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba <https://lists.samba.org/mailman/options/samba>


More information about the samba mailing list