[PATCH] Test the netlogon challenge cache better and add helpful logs

Andrew Bartlett abartlet at samba.org
Mon Jun 26 09:20:53 UTC 2017


On Mon, 2017-06-26 at 10:50 +0200, Stefan Metzmacher wrote:
> Hi Andrew,
> 
> > Debugging incorrect machine accounts on netlogon is really painful, as
> > there are essentially no useful logs on the AD DC for wrong machine
> > account passwords.  
> > 
> > This fixes it.  In the long run a proper hook into the audit logs are
> > due, but this is a good start. 
> 
> Can you please add a bug for the proper solution, I think it's needed
> before 4.7.0 final.

I've filed the bug.  https://bugzilla.samba.org/show_bug.cgi?id=12865

> > I started this due to a suggestion that our challenge cache wasn't
> > right and so I added tests to demonstrate better the capabilities and
> > limitations. 
> > 
> > Please review and push,
> 
> Reviewed by me.

Thanks!

Andrew Bartlett

-- 
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba




More information about the samba-technical mailing list