[Samba] Problem after update version 4.15.0

Łukasz Michalski lm at zork.pl
Wed Oct 20 07:12:20 UTC 2021


On 10/5/21 19:47, Ingo Asche via samba wrote:
> Hi All,
>
> I can second the problem. After Updating to 4.15 I also can't login to 
> my AD. After reverting to 4.17.7 all works again without any problems.
>
In my case I was not able to login from win2008 server r2 and from 
windows7 after update from 4.12 to 4.15

Linux clients and win10 clients did not have any problems.

I reverted back to 4.12 (whole virtual machine). I use ArchLinux with 
samba packages from repository.

In win2008srv event log I found Kerberos-security, event 4:

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server 
db$. The target name used was DB$. This indicates that the target server 
failed to decrypt the ticket provided by the client. This can occur when 
the target server principal name (SPN) is registered on an account other 
than the account the target service is using. Please ensure that the 
target SPN is registered on, and only registered on, the account used by 
the server. This error can also happen when the target service is using 
a different password for the target service account than what the 
Kerberos Key Distribution Center (KDC) has for the target service 
account. Please ensure that the service on the server and the KDC are 
both updated to use the current password. If the server name is not 
fully qualified, and the target domain (SAMDOM) is different from the 
client domain (SAMDOM), check if there are identically named server 
accounts in these two domains, or use the fully-qualified name to 
identify the server.

And NETLOGON service error, event 5719:
This computer was not able to set up a secure session with a domain 
controller in domain SAMDOM due to the following:
There are currently no logon servers available to service the logon 
request.

Regards,
Łukasz




More information about the samba mailing list