Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi - got a bit of a pickle going on with *sigh* my Samba server.

 

It's very new, as am I to Linux, and currently have winbind and samba set up. Looking to create a share for profiles to be stored on for a 2008r2 domain.

 

Falling at this hurdle I've come to, which is that upon testing winbind with wbinfo -a I can authenticate admin accounts and the administrator accounts fine, but 'normal' users (staff and students) return:

 

challenge/response password authentication failed

error code was NT_STATUS_NO_SUCH_USER (0xc0000064)

error messsage was: No such user

 

...And I've just got no bloody idea why :(

 

wbinfo -u shows users as it should, wbinfo -g shows groups as it should.

 

Not got around to testing out any shares yet, but I don't know I'll be able to set them up right without this wokring.

 

Anyone got any ideas? Anyone else hate Linux too? (joking... :o)

Posted

Hi! Thanks so much for the reply!

 

I got:

 

# kinit username

kinit: Configuration file does not specify default realm when parsing name username

Posted

Hi - have made my krb5.conf look like the one in the example but still no joy. Returns

 

root@:/etc# kinit username

kinit: Cannot resolve network address for KDC in realm ".LOCAL" while getting initial credentials

 

...But I'm about to ask a daft question. Local domain (as in, NOT the one that ends in ...sch.uk) should be set as ".LOCAL" without those ""... IS that right?

 

That's actually something I've never really understood - how DO you know what your local domain name actually is?

 

Cheers for the patient help and for stopping me putting my fist through the krb5.conf screen. :)

Posted
Hi - have made my krb5.conf look like the one in the example but still no joy. Returns

 

root@:/etc# kinit username

kinit: Cannot resolve network address for KDC in realm ".LOCAL" while getting initial credentials

 

 

Is your time in sync with the domain controller?

 ntpdate  

 

...But I'm about to ask a daft question. Local domain (as in, NOT the one that ends in ...sch.uk) should be set as ".LOCAL" without those ""... IS that right?

 

not really sure what your asking. The netbios name is the pre-windows 2000 workgroup style name. Myworkgroup is "CURRIC" (the old netbios name) whereas my realm is COLLEGE.INTERNAL.

 

I'll pm some recent configs.

Posted (edited)

Thanks Cybernerd you're awesome.

 

It's the realm name I don't know, not sure where I find out what it is... :/

 

EDIT - ok so I'm thinking that my domain name being WHATEVER.LA.SCH.UK then my realm name should be WHATEVER.LOCAL

 

Sound like I'm barking up the right tree there?

Edited by Miscbrah
Posted
Thanks Cybernerd you're awesome.

 

It's the realm name I don't know, not sure where I find out what it is... :/

 

EDIT - ok so I'm thinking that my domain name being WHATEVER.LA.SCH.UK then my realm name should be WHATEVER.LOCAL

 

Sound like I'm barking up the right tree there?

 

The realm is the top level of the active directory tree. log into active directory and run dcdiag on the command line - it wlll tell you in there somewhere (probably a better way)

Posted

OH MY GAWD it's doing something positive...

 

At least that kinit part!

 

If it's WORKING the prompt resets after you tyoe the password in right? I'm assuming so, because if I type it in wrong to test it tells me authentication failed...

 

...HOWEVER...

 

wbinfo -a still gives me this old pants:

 

root@james:/etc# wbinfo -a

Enter 's password:

plaintext password authentication failed

Could not authenticate user with plaintext password

Enter 's password:

challenge/response password authentication failed

error code was NT_STATUS_NO_SUCH_USER (0xc0000064)

error messsage was: No such user

Could not authenticate user with challenge/response

root@james:/etc#

 

...Is this giving anyone any obvious hints? :/

 

I'm so lost, cheers for reading whoever's reading. :)

Posted
...Is this giving anyone any obvious hints? :/

 

Windows Server 2008 R2 has, by default, some security setting or other that makes it not authenticate Samba devices. Sorry, I can't recall the exact thing, but a quick Google for "server 2008 samba" or similar should bring it up.

  • Thanks 1
Posted
Windows Server 2008 R2 has, by default, some security setting or other that makes it not authenticate Samba devices. Sorry, I can't recall the exact thing, but a quick Google for "server 2008 samba" or similar should bring it up.

 

Thanks David! I'm not getting anything useful from Google though. :/

 

Any other ideas from anywhere? Can't think how anyone would get using this it's horrible!

Posted

Ok, might be getting nearer might not.

 

Up-to-date symptoms are:

 

- getent passwd and getent groups doesn't return anything related to the domain.

 

- kinit DOES somehow seem to work, as in when the password's typed in it doesn't say anything and just move to a new command prompt, where deliberately typing the WRONG password tells me it's not working.

 

- have a folder created and listed in smb.conf but not made much progress adding groups and usernames as I've both no idea how, and no idea if they're even working anyqay.

 

Can anyone PLEASE help me? I'm really really lost and this is driving me up the wall... :(

Posted

Hey Geoff, thanks for reading all that. nsswitch.conf looks like:

 

# Example configuration of GNU Name Service Switch functionality.

# If you have the `glibc-doc-reference' and `info' packages installed, try:

# `info libc "Name Service Switch"' for information about this file.

 

passwd: compat winbind

group: compat winbind

shadow: compat

 

#hosts: files dns

#networks: files

 

#protocols: db files

#services: db files

#ethers: db files

#rpc: db files

 

#netgroup: nis

 

Is that as it should be?

Posted

yes, that looks right. Although I don't think those other lines should be commented out, they aren't related to the issue at hand.

 

After you do a kinit, do a klist and post the result.

  • Thanks 1
Posted

Thanks for helping Geoff!

 

Ok, klist gives me this:

 

root@james:/etc# klist

Ticket cache: FILE:/tmp/krb5cc_0

Default principal: @.SCH.UK

 

Valid starting Expires Service principal

05/02/12 13:29:21 05/02/12 23:29:22 krbtgt/.SCH.UK@.SCH.UK

renew until 05/03/12 13:29:21

root@james:/etc#

 

The server's called "james" as you might guess and 'username I'm testing' and 'long domain name' are substituted.

 

Is that what you'd think I should be seeing?

Posted
Windows Server 2008 R2 has, by default, some security setting or other that makes it not authenticate Samba devices. Sorry, I can't recall the exact thing, but a quick Google for "server 2008 samba" or similar should bring it up.

 

I think its related to older versions of samba. Samba >= 3.6 is ok.

just had a look on a ubuntu workstation (my server is RedHat though)

 

do

 dpkg -l samba 

to check

 

just noticed that samba4 is included in 12.04

Posted
Yes that means that at least the kerberos is working ok. Try doing a 'wbinfo -a --verbose'

 

Ahh, ok then judging by this it's not working after all:

 

 

root@james:/etc#

wbinfo -a jlamb --verbose

Enter jlamb's password:

plaintext password authentication failed

Could not authenticate user jlamb with plaintext password

Enter jlamb's password:

challenge/response password authentication failed

error code was NT_STATUS_NO_SUCH_USER (0xc0000064)

error messsage was: No such user

Could not authenticate user jlamb with challenge/response

root@james:/etc#

Posted
Ahh, ok then judging by this it's not working after all:

 

 

root@james:/etc#

wbinfo -a jlamb --verbose

Enter jlamb's password:

plaintext password authentication failed

Could not authenticate user jlamb with plaintext password

Enter jlamb's password:

challenge/response password authentication failed

error code was NT_STATUS_NO_SUCH_USER (0xc0000064)

error messsage was: No such user

Could not authenticate user jlamb with challenge/response

root@james:/etc#

 

does:

 

wbinfo -a [email protected] --verbose

 

work? replace DNS.DOMAIN.NAME with your actual dns domain ofc.

Posted

Cheers again again - no that doesn't work, gives me:

 

root@james:/home/eng# wbinfo -a jlamb@.SCH.UK --verbose

Enter jlamb@.SCH.UK's password:

plaintext password authentication failed

Could not authenticate user jlamb@.SCH.UK with plaintext password

Enter jlamb@.SCH.UK's password:

challenge/response password authentication failed

error code was NT_STATUS_NO_SUCH_USER (0xc0000064)

error messsage was: No such user

Could not authenticate user jlamb@.SCH.UK with challenge/response

 

It seems like you have a game plan though, which encourages me! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...