which samba version / patch for Active Directory 2008

Sallee, Stephen (Jake) Jake.Sallee at umhb.edu
Mon Sep 20 18:43:15 CEST 2010


Have you tried disjoining and rejoining  the domain after the upgrade?
It sounds crazy but I have seen similar problems fixed this way.

Jake Sallee
Godfather Of Bandwidth
Network Engineer

Fone: 254-295-4658
Phax: 254-295-4221


-----Original Message-----
From: freeradius-users-bounces+jake.sallee=umhb.edu at lists.freeradius.org
[mailto:freeradius-users-bounces+jake.sallee=umhb.edu at lists.freeradius.o
rg] On Behalf Of Neil Prockter
Sent: Monday, September 20, 2010 11:29 AM
To: freeradius-users at lists.freeradius.org
Subject: Re: which samba version / patch for Active Directory 2008

Hello,

Well things have taken a turn for the worse.  At the weekend we upgraded
the last AD Domain controller to 2008r2 (still in AD2003 mode) and the
radius servers instantly stopped working with "named pipe disconnected"
and now "ntlm --username" and "wbinfo -a" no longer work.

I have a samba 3.4 install which 'works' from the "ntlm --username" and
"wbinfo -a" point of view but which, I strongly suspect, returns
incorrect NT_KEYs. (the reason I suspect this is that the previous
servers always returned the same value and that value matches the output
of the python script attached to
https://bugzilla.samba.org/show_bug.cgi?id=6563)

I've spent the best part of the day bang head on wall so I thought I'd
ask a thing

Would the KEY changing every few minutes be expected? (under
samba3.0/ad2003 it remained the same)  By key I mean the output of
"/usr/local/samba/bin/ntlm_auth --request-nt-key --username=bob
--challenge=deadshortbeef --nt-response=deadlongerbeef"

If no one has seen things like this I'll move over to the samba lists,
getting the feeling this issue belongs there.

Thanks all,

Neil

Please access the attached hyperlink for an important electronic
communications disclaimer:
http://www.lse.ac.uk/collections/planningAndCorporatePolicy/legalandComp
lianceTeam/legal/disclaimer.htm
-
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html




More information about the Freeradius-Users mailing list