-
Posts
320 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by netadmin
-
wbinfo -t produces the following result: checking the trust secret via RPC calls succeeded Is this is a good response? In addition, wbinfo -g lists all domain user groups (not sure if that helps any).
-
I have been trying to repackage a few programs to run as an MSI, so I can deploy them with group policy. I am using Wininstall LE to do the repackaging I have tested deployment with three programs so far: Adobe Flash Player (the Adobe MSI file, no changes made) CCleaner (repackaged MSI file) Google Sketchup (repackaged MSI file). All three install fine, but CCleaner and Google Sketchup (the repackaged ones) both generate the following error in the server application log: ERROR (Software installation): Software installation was unable to read the MSI file {File location}. The following error was encountered: SQL query syntax invalid or unsupported. I have tried it several times and keep getting the error. Is it not possible to deploy these repackaged apps without this error?
-
I checked the Samba and Winbind logs and found a few interesting events that might be related to the NTLM problem. Screenshots are attached. These events occur after every system restart. Any thoughts on whether these are a likely cause, and tips on how to correct these? Thanks.
-
I now fixed the broken ACL. However, it is still not accepting the username/password. I did notice something odd: the first few login prompts just say then the last few login prompts say The username is only recorded in the log for the second style of login prompt. Does this mean something is still not configured correctly, and could cause it to not accept any username/password? Thanks.
-
^It turns out I had accidentally copied the Squid 2.6 init script. A quick squid reinstall fixed that problem and I now get the authentication dialog. However, I am still getting 6+ dialogs and it is not accepting the username and password. I have updated the config file to be very similar to yours. I do not know if I missed something in the config file, or what. Do you have any more ideas? (I can get any file that might be helpful). Thanks again. squid_-_notepad.pdf
-
Thank you, Geoff. That's very helpful. I am now trying to install Squid version 2.5, like on your system, so the configuration file will be more similar, and hopefully, easier for me to find the problem. One odd problem occurred after I reinstalled it and editted the config file. The attached error message appears anytime squid starts/stops. This appeared a few minutes after Squid "terminated abnormally" and said warning: Squid killed! Have you seen this message before?
-
Thank you, Geoff, I'd appreciate that if you would post your settings. I did notice one more thing, not sure if it's related- check the attachment to see the warning I get anytime squid starts or stops.
-
Hmm... they look correct to me, but that does not mean much, plus it still does not work. Do I have to define another ACL variable somewhere? squid.pdf
-
OK, I discovered that the reason winbind kept crashing was that the server needed a restart after I reinstalled Samba. The permissions have been corrected. However, when I try to access websites, I still get about 10-12 login prompts and it still does not accept the username/password. The log file shows that it is recording the username, which is was not before, so this appears to be a good sign. Do you think that http access is disabled for NTLM user ACL, or is it still a winbind problem?
-
OK, it looks like I had a corrupt file somewhere. I reinstalled Samba and got it configured like before. I can now manually start winbind. However, when I try to change the permission settings (changing group to Squid) for the winbindd_privileged folder, winbind then stops and refuses to start itself, or be manually started. Please see my attached image. This is my current permission settings for the folder. Please let me know if you have any advice.
-
OK--Here's the latest update on my system. Earlier, I tried to reset the permissions to grant squid access to winbind. However, in the process, something went very wrong and I now get the following error when I try to start winbind. [2007/06/17 21:39:47, 0] lib/util_sock.c:create_pipe_sock(1285) invalid permissions on socket directory /var/lib/samba/winbindd_privileged open_winbind_socket: Resource temporarily unavailable Any tips on how to properly fix this? I have tried resetting the permissions to what the other folders are set to originally, and it still has the same error. I am really hoping I will not have to format the hard drive and start the Suse install from the beginning. Luckily, my VNC connection continues to work, so this is making my troubleshooting much easier.
-
@Geoff I'm not sure exactly what happened. I restarted the server, after I had been looking at the log files. I have changed all settings back that I had been tweaking. Something seems to be wrong now, though. -The Suse login screen no longer has the option to logon to the windows domain (not that I need that, I'm just afraid it might mean a larger Suse issue) -wbinfo -u now says error looking up domain users. -winbind now refuses to start. When I manually start it, it says WARNING: /var/run/samba/winbindd.pid FAILED. Do you have any ideas on where to start checking settings? It appears like the config files still reference the domain connection, like before. I really appreciate all the help you have given so far, and am hoping you might have an idea on this latest issue.
-
First of all, I am very sorry that I had double posted the last message. I got that cleaned up now. (I had clicked quote rather than edit, like I had wanted to do and did not notice until just now.) I looked at the log files and think I might have found the problem on why it is not accepting the username and password for the domain, but have no clue how to fix it. Below is an excerpt from the Squid log. Login for user [DOMAIN]\[administrator]@[DOMAIN] failed due to [winbind client not authorized to use winbindd_pam_auth_crap. Ensure permissions on /var/lib/samba/winbindd_privileged are set correctly.] 2007/06/17 10:29:21| authenticateNTLMHandleReply: Error validating user via NTLM. Error returned 'BH NT_STATUS_ACCESS_DENIED' Anyone have any ideas?
-
No Konsole errors after I typed your revised command I then tried a klist -e and it had the following response, I'm guessing this is good. Ticket cache: FILE:/tmp/krb5cc_0 Default principal: Administrator@DOMAIN Valid starting Expires Service principal 06/16/07 20:42:24 06/17/07 06:42:05 krbtgt/DOMAIN@DOMAIN renew until 06/17/07 20:42:24, Etype (skey, tkt): ArcFour with HMAC/md5, ArcFour with HMAC/md5 Kerberos 4 ticket cache: /tmp/tkt0 klist: You have no tickets cached I now tested the proxy server by changing the browser connection setting on the firewall computer (I know I have to manually enter the username) and it goes into an endless logon loop, continually asking for username/password and never accepting it. :?
-
OK. One less error now When I reset squid with squid -z, I get the following message: 2007/06/16 14:08:00| WARNING: No units on 'authenticate_ttl 180', assuming 180.000000 second 2007/06/16 14:08:00| Creating Swap Directories firewall:~ # /etc/init.d/squid start Starting WWW-proxy squid done Something seems to have a problem right now. When I try to connect to a website on this linux box, but going through the proxy server, it does not accept network usernames and passwords. It just keeps asking for username and password and never accepting it. Also, I found a Kerberos test command (klist -e) and got the following error message: klist: No credentials cache found (ticket cache FILE:/tmp/krb5cc_0) Kerberos 4 ticket cache: /tmp/tkt0 klist: You have no tickets cached Did I miss a step?
-
I install a cheap USB switcher, if the PCs are nearby. Haven't found anything for over the network use on Windows, though.
-
I tried to update the Squid.conf file and got a few errors. I think I'm getting close! Code entered into squid.conf auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp auth_param ntlm children 5 auth_param ntlm max_challenge_reuses 0 auth_param ntlm max_challenge_lifetime 2 minutes auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic auth_param basic children 5 auth_param basic realm Squid proxy-caching web server auth_param basic credentialsttl 5 hours acl NTLMUsers proxy_auth REQUIRED http_access allow all NTLMUsers When I reset and restarted Squid in Konsole, the following error messages appeared. 2007/06/16 12:39:24| unrecognised ntlm auth scheme parameter 'max_challenge_reuses' 2007/06/16 12:39:24| unrecognised ntlm auth scheme parameter 'max_challenge_lifetime' 2007/06/16 12:39:24| ACL name 'all' not defined! FATAL: Bungled squid.conf line 1888: http_access allow all NTLMUsers Squid Cache (Version 2.6.STABLE5): Terminated abnormally. Any ideas?
-
Thanks, Cybernerd. I'll keep that trick in mind.
-
Sorry about that. Trying that revised code worked perfectly. It now says NT_STATUS_OK: Success (0x0) Thanks! I'll try to configure Squid later today.
-
OK. I tried entering the username (the second one on the command) as DOMAIN\administrator (with domain the actual domain name, of course) and got the same error message. Something else interesting, I noticed on the logon screen there is an option to logon to Suse with your Windows domain username/password. I tried this, it started to login, then said could not start kstartupconfig. Check your installation. and then goes back to the login screen. Could this be related?
-
On one of the Squid documentation pages I just found, it recommended testing the NTLM authentication. I tried this and got an error message and was wondering if you have any ideas what might be wrong (if anything). It said to enter /usr/bin/ntlm_auth --username=[username] at the console. I did this, and then it prompts for the password, like the documentation says. However, the documentation says it should then say NT_STATUS_OK, and if not, to recheck your config (nothing more specific, though). It actually says NT_STATUS_NO_SUCH_USER on an account that is part of the domain (the admin account). Thanks for any ideas. I GREATLY appreciate it and am learning a lot about linux.
-
OK. Below is the response after I ran the command. checking the trust secret via RPC calls succeeded
-
I did some clicking around today and it turns out I had forgotten to actually join the domain. smb.conf now lists security = ADS. The linux machine is also now listed in Active Directory. Any tips on next steps, or additional tests I need to run?
-
It does not even list a security line. I'm guessing this means I need to manually configure it?
-
Thank you. I found in Suse 10.2's Yast control panel there is an option for Windows Domain Membership and Samba server. When I clicked on Domain membership, it downloaded files for samba and winbind. (I don't remember about Kerberos, I don't think it downloaded anything). I entered my domain name in Windows Domain Membership. Do I need to do anything else? (Right now, the linux pc is at my house, and not connected to the school network. I will connect it to the network when get everything mostly ready to go, so I hopefully only have small config changes to do). Anyway, is anyone familiar with this step? I'll admit, I am very new to linux, and still have a lot to learn. Thanks!
