RE: User Authentication Fails on Server 2003 SP1



Oops!!!!! You need to enable this policy. You want to be able to send
unencrypted passwords 3rd party SMB servers.
You will then need to change the .conf file to to require encrypted
passwords I think. Try it both ways!

"Jeff Bradish" wrote:

Checked with Domain Admins and they replied:
"It is disabled and it is a group policy that applies to all Domain
controllers"
So it does not seem to be the issue.

As an FYI I am including my smb.conf settings from Samba 2.2.8 if it might
help:
[global]
workgroup = AMER
netbios name = USAHSSMC001
netbios aliases = USAHSSMC001
server string = EDS GSCO
security = DOMAIN
encrypt passwords = Yes
password server =
usahd100,uspld100,usahd101,usahd102,usahd103,usahd104
username map = /etc/sfw/username.map
log level = 2
preferred master = No
local master = No
domain master = No
dns proxy = No
create mask = 0664
I am also using the same smb.conf settings for Samba 3.0.21c.
--
Jeff Bradish


"Irv" wrote:

I think W2003 SP1 required the Domain Controllers to default to having all
communication encrypted which may be giving Samba SMB issues. You could try
modifying your domain controller policy to disable the need to send encrypted
passwords to 3rd party SMB

Computer Config\Windows Settings\Security Settings\Local Policies\Security
Options

Microsoft Network Client: Send unencrypted password to 3rd party SMB servers
Disabled

Not sure if you need to change anything on the Samba end

HTH

Irv


"Jeff Bradish" wrote:

I have tried upgrading Samba to 3.0.21c and still seeing problems with
authentication. In fact, I cannot get Samba 3.0.21c to successfully join the
domain.

I have 2 domain controllers in the domain that have not been upgraded to
2003 SP1. When I point the Samba password server to one of these systems,
authentication works fine, but not when pointed to a domain controller
sitting at 2003 SP1.
--
Jeff Bradish


"Irv" wrote:

I think you need to upgrade Sanmba to version 3.0.14a.

Irv

"Jeff Bradish" wrote:

I have been using Samba 2.2.8 on a Solaris 9 system to share out a Unix file
system to Windows XP users for the past year. Samba was configured to
authenticate users to a Server 2003 domain. Recently the domain controllers
were upgraded to Windows Server 2003 SP1 and authentication to the domain
started to fail and I cannot get the authentication process to function.
Samba logs are showing:
[2006/03/06 10:17:25, 3] smbd/reply.c:(880) Domain=[AMER] NativeOS=[Windows
2002 Service Pack 1 2600] NativeLanMan=[Windows 2002 5.1]
[2006/03/06 10:17:26, 0] rpc_client/cli_pipe.c:(1202)
cli_nt_session_open: cli_nt_create failed on pipe \NETLOGON to machine
USAHD100. Error was NT_STATUS_ACCESS_DENIED
[2006/03/06 10:17:26, 0] smbd/password.c:(1358)
connect_to_domain_password_server: unable to open the domain client session
to machine USAHD100. Error was : NT_STATUS_ACCESS_DENIED

I have been struggling to correct this issue for the past 2 weeks with no
success.

If anyone has any ideas on how to correct this situation, I would really
appreciate the help. Thanks.
--
Jeff Bradish
.



Relevant Pages

  • Re: Samba
    ... I have a RH7.3 server set up and Samba works great. ... Encrypt passwords yes with no guest account. ... On the windows machine in my network places I can see Samba Server ... try it is selinux, ...
    (Fedora)
  • Re: Does samba 3.0.14Aa on OS 5.0.6 work with ldapsam backend on another LDAP server?
    ... used 3.0.9 on SCO 5.0.6 for quite some time after suffering problems I ... a RedHat4 box running samba 3.0.10 and OpenLDAP 2.2.13. ... and no LDAP server (although there were the ... share on the SCO server without any smbpasswd on that server! ...
    (comp.unix.sco.misc)
  • RE: VmWare and Pen-test Learning
    ... Setup a tftp server on your client machine. ... Use John the Ripper to crack the passwords. ... (dictionary attacks, brute force, single mode). ... Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • [HPADM] RE: Mapping Samba Share to XP
    ... "The mapped network drive could not be created because the following error occurred: The remote computer is not available." ... Is there anything I need to change in the configuration on the CIFS server? ... I am unable to map to the Windows XP clients on the 158 subnet still, but this is due to the firewall, so if someone knows how I can make that happen, please let me know? ... Mapping Samba Share to XP ...
    (HP-UX-Admin)
  • samba 3.0 does not list servers when "map to guest = bad user" ?
    ... I've been trying to configure a samba 3.0 server to play nicely both ... with smbclient and with MS windows. ... At present, if I try to view the list of shares from within windows, I ...
    (Debian-User)