[Samba] Classicupgrade FL 2012_R2 NTLM/Kerberos logon

Andrew Bartlett abartlet at samba.org
Wed Jun 5 20:36:44 UTC 2024


On Wed, 2024-06-05 at 12:27 +0200, Havany wrote:
> Hello,
> Given what Rowland told me, I checked our DNS configuration and to
> avoid side effects, I disabled IPv6.
> We want to migrate on July, and we don't work with a Samba commercial
> provider ;).

I think you need that, particularly given your timeframes.  
Also use Samba 4.20, just in case we fixed this. 
Windows often still creates accounts with just RC4 (the admin account
at upgrade time), and these are expected to keep working, so it should
be possible to make the client still attempt such a logon.
But from what you have shown so far, the client is the one backing off,
and not trying a second time with the password, even at the weaker
enctype.  This is either due to local policy or our reply, and only a
deeper dive will show that.
Andrew Bartlett

-- 
Andrew Bartlett (he/him)       https://samba.org/~abartlet/Samba Team Member (since 2001) https://samba.orgSamba Team Lead                https://catalyst.net.nz/services/sambaCatalyst.Net Ltd
Proudly developing Samba for Catalyst.Net Ltd - a Catalyst IT group
company
Samba Development and Support: https://catalyst.net.nz/services/samba
Catalyst IT - Expert Open Source Solutions


More information about the samba mailing list