[Samba] xfreerdp and SPNEGO failed

L.P.H. van Belle belle at bazuin.nl
Thu Feb 22 15:56:24 UTC 2018


Few questions. 

If kerberos ticket proxy/forward allowed on that machine. 
And what happens if you kinit username at REALM and then use freerdp.

vi ~/.freerdp/known_hosts 
And delete the ip your connecting to. 

And, it might also be a samba bug. 
Try this also : 
ntlm_auth --request-nt-key --domain=NTDOM --username=[user] --password=[pw] 

For the error code: 0xc0000017 
i cant determin exact what that is.
I see samba bugs, with memory references. 
https://bugzilla.samba.org/show_bug.cgi?id=11957 

https://github.com/FreeRDP/FreeRDP/issues?q=is%3Aissue+0xc0000017+is%3Aclosed 
Shows also the error code in 5 closed tickets there.

And remember with windows 10 1709, its more and more hostnames and domainnames. 
Like things as : not working \\ip and  working \\hostname 
Or login as : notworking "username" but working "DOMAIN\username" or username at REALM 


Greetz, 

Louis


> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens 
> lejeczek via samba
> Verzonden: donderdag 22 februari 2018 16:00
> Aan: samba at lists.samba.org
> Onderwerp: [Samba] xfreerdp and SPNEGO failed
> 
> hi everyone
> 
> I realise this not exactly on topic, I'm hoping an expert or 
> two could confirm that following is not caused somehow by samba:
> 
> I try xfreerdp to connect to a Win10 which is a member of 
> NT-style domain and it fails this way:
> 
> [14:55:33:905] [8048:8055] [ERROR][com.freerdp.core.nla] - 
> SPNEGO failed with NTSTATUS: 0xC0000017
> [14:55:33:905] [8048:8055] [ERROR][com.freerdp.core] - 
> freerdp_set_last_error ERRCONNECT_AUTHENTICATION_FAILED 
> [0x00020009]
> [14:55:33:905] [8048:8055] [ERROR][com.freerdp.core.rdp] - 
> rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
> [14:55:33:905] [8048:8055] 
> [ERROR][com.freerdp.core.transport] - transport_check_fds: 
> transport->ReceiveCallback() - -1
> 
> but! if that user is already logged in then xfreerdp will 
> succeed.
> Any thoughts?
> many thanks, L.
> 
> -- 
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
> 
> 




More information about the samba mailing list