[Samba] Samba AD DC on a trust relationship with IdM - kpasswd not working porperly

Rowland Penny rpenny at samba.org
Thu Apr 7 15:54:27 UTC 2022


On Thu, 2022-04-07 at 12:39 -0300, Mateo Duffour via samba wrote:
> Hi, 
> 
> We've updated our Samba server version to 4.16.0 and we're getting
> this error now (when trying to login with any user): 
> 
> Apr 07 11:50:46 idmsrvpru.idmpru.xxx.xxx.xx krb5_child[4846]: Error
> constructing AP-REQ armor: Server 
> krbtgt/ADTEST.xxx.xxx.xx at IDMPRU.xxx.xxx.xx not found in Kerberos
> database 
> Apr 07 11:50:46 idmsrvpru.idmpru.xxx.xxx.xx krb5_child[4846]: Error
> constructing AP-REQ armor: Server 
> krbtgt/ADTEST.xxx.xxx.xx at IDMPRU.xxx.xxx.xx not found in Kerberos
> database 
> Apr 07 11:50:46 idmsrvpru.idmpru.xxx.xxx.xx sshd[4842]:
> pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0
> tty=ssh ruser= rhost=10.9.9.4 user=usu7 at adtest.xxx.xxx.xx 
> Apr 07 11:50:46 idmsrvpru.idmpru.xxx.xxx.xx sshd[4842]:
> pam_sss(sshd:auth): received for user usu7 at adtest.xxx.xxx.xx: 4
> (System error) 
> Apr 07 11:50:48 idmsrvpru.idmpru.xxx.xxx.xx sshd[4840]: error: PAM:
> Authentication failure for usu7 at adtest.xxx.xxx.xx from 10.9.9.4 
> 
> Any help is appreciated, regards. 

None of that appears to be coming from Samba, could it be coming from
sssd ? If so, I suggest you ask on the sssd-users mailing list.

Rowland





More information about the samba mailing list