[Samba] Domain member server: user access

L.P.H. van Belle belle at bazuin.nl
Tue Sep 26 14:19:03 UTC 2017


Well, what i can say is.

The Resolving inconsistant on DC with AD backend. GID 100 and 10000 is only on the DC's. 
My member servers are all checked now, ( 4.5.8 4.5.14 4.6.5 4.6.7 4.6.8 ) these are consistant. 

The sort solution is, run on the DC: 
net cache flush

And check again for example with getent passwd username or id username 
And dont touch the DC, after an upgrade, again run : net cache flush

And besides that, keep an eye on the list. 
The members are safe, ive checked 4.5.8 4.5.12 4.5.14 4.6.5 4.6.7 4.6.8 
( original debian and my packages ) 

So back to your problem, user access. 

Are you still getting/seeing these :  
  Failed to map kerberos pac to server info (NT_STATUS_UNSUCCESSFUL) 
Or   Failed to generate session_info (user and group token) for session
setup: NT_STATUS_ACCESS_DENIED 



Greetz, 

Louis





> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens 
> Stefan G. Weichinger via samba
> Verzonden: dinsdag 26 september 2017 16:00
> Aan: samba at lists.samba.org
> Onderwerp: Re: [Samba] Domain member server: user access
> 
> Am 2017-09-26 um 15:32 schrieb L.P.H. van Belle via samba:
> 
> > So IMHO, very inconistant results. 
> > 
> > So any more thoughts about this? 
> 
> I can't follow that anymore and don't know if and what to 
> fix/change/set ...
> 
> No complaining, just no idea.
> 
> 
> 
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
> 




More information about the samba mailing list