[Samba] first share access fails

Michael Ströder michael at stroeder.com
Tue Dec 18 17:28:18 UTC 2018


I'm trying to solve a problem with Samba shares failing during first
access, but subsequent second share access always succeeds immediately
with SMB3 being reported by smbstatus.

I'm aware of this MS KB article:


But the failure above has also been reported by Win7 users.

It's a domain member server joined with an AD domain (W2K12R2).
I did not setup the machine. So I don't even know how the join was
exactly done. I was told it was a domain member in an old domain before.

The Samba server runs on CentOS 6.10, but with separate Samba packages
samba4-4.2.10-15.el6.x86_64 etc.

NSS lookups are done via sssd-1.13, POSIX attributes are read from AD
entries, no ID mapping. This simply works also for shell login. winbindd
is also running and seems to be used by smbd, but not for NSS lookups.

During the first fail there seems to be an error with the PAC group info
(see log excerpts appended below). When the second try succeeds I can
see the group SIDs retrieved in the Samba logs.

What really strikes me is this message (obfuscated user's SID):

SID S-1-5-21-123456789-1234567890-3679153413-2567406 ->
getpwuid(4294967295) failed

I don't know why the user's SID is to be mapped to the POSIX-UID of
nobody (4294967295). As said all getent passwd/group etc. stuff just works.

Any hint is highly appreciated.

Ciao, Michael.

--------------------------------- snip ---------------------------------
[2018/12/18 13:37:51.447591,  5]
  Finding user AD42\user1
[2018/12/18 13:37:51.447615,  5]
  Trying _Get_Pwnam(), username as lowercase is ad42\user1
[2018/12/18 13:37:51.448348,  5]
  Trying _Get_Pwnam(), username as given is AD42\user1
[2018/12/18 13:37:51.449017,  5]
  Trying _Get_Pwnam(), username as uppercase is AD42\user1
[2018/12/18 13:37:51.450059,  5]
  Checking combinations of 0 uppercase letters in ad42\user1
[2018/12/18 13:37:51.450101,  5]
  Get_Pwnam_internals didn't find user [AD42\user1]!
[2018/12/18 13:37:51.450125,  5]
  Finding user user1
[2018/12/18 13:37:51.450169,  5]
  Trying _Get_Pwnam(), username as lowercase is user1
[2018/12/18 13:37:51.450212,  5]
  Get_Pwnam_internals did find user [user1]!
[2018/12/18 13:37:51.455755,  1]
  SID S-1-5-21-123456789-1234567890-3679153413-2567406 ->
getpwuid(4294967295) failed
[2018/12/18 13:37:51.455825,  3]
  Failed to finalize nt token
[2018/12/18 13:37:51.455865,  1]
  Failed to map kerberos pac to server info (NT_STATUS_UNSUCCESSFUL)

More information about the samba mailing list