Discussion:
[Samba] Event log 4768 audit failure
VigneshDhanraj G
2016-06-08 15:38:30 UTC
Permalink
Hi all,

Hi all,

I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)

A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Information:
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID

There is no user as root in my DC and there is no functionality breakup. It
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with my
system. Audit failure logs are dumped.

I think it might be a regression issue from samba while fixing badlock.

could anyone help regarding this issue?
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
VigneshDhanraj G
2016-06-09 19:06:01 UTC
Permalink
Thanks uri, make that happen.
Post by VigneshDhanraj G
Hi all,
Hi all,
I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing numerous
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
A Kerberos authentication ticket (TGT) was requested.
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID
There is no user as root in my DC and there is no functionality breakup.
It
Post by VigneshDhanraj G
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with my
system. Audit failure logs are dumped.
I think it might be a regression issue from samba while fixing badlock.
could anyone help regarding this issue?
Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled
Heimdal), but have zero time to work on it at the moment. If none gets
there first I'll fix it in a couple of weeks (or at least look into it).
Haven't seen any functional impact until you mentioned that audit log.
Thanks,
Uri.
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
VigneshDhanraj G
2016-06-14 09:00:54 UTC
Permalink
Is there any patch for it?

Regards,
Vigneshdhanraj G

On Fri, Jun 10, 2016 at 12:36 AM, VigneshDhanraj G <
Post by VigneshDhanraj G
Thanks uri, make that happen.
Post by VigneshDhanraj G
Post by VigneshDhanraj G
Hi all,
Hi all,
I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing
numerous
Post by VigneshDhanraj G
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
A Kerberos authentication ticket (TGT) was requested.
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID
There is no user as root in my DC and there is no functionality
breakup. It
Post by VigneshDhanraj G
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with my
system. Audit failure logs are dumped.
I think it might be a regression issue from samba while fixing badlock.
could anyone help regarding this issue?
Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled
Heimdal), but have zero time to work on it at the moment. If none gets
there first I'll fix it in a couple of weeks (or at least look into it).
Haven't seen any functional impact until you mentioned that audit log.
Thanks,
Uri.
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
VigneshDhanraj G
2016-06-15 07:19:37 UTC
Permalink
Is this bug is related to the issue i mentioned
https://bugzilla.samba.org/show_bug.cgi?id=11769

Regards,
Vigneshdhanraj G

On Tue, Jun 14, 2016 at 2:30 PM, VigneshDhanraj G <
Post by VigneshDhanraj G
Is there any patch for it?
Regards,
Vigneshdhanraj G
On Fri, Jun 10, 2016 at 12:36 AM, VigneshDhanraj G <
Post by VigneshDhanraj G
Thanks uri, make that happen.
Post by VigneshDhanraj G
Post by VigneshDhanraj G
Hi all,
Hi all,
I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing
numerous
Post by VigneshDhanraj G
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
A Kerberos authentication ticket (TGT) was requested.
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID
There is no user as root in my DC and there is no functionality
breakup. It
Post by VigneshDhanraj G
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with my
system. Audit failure logs are dumped.
I think it might be a regression issue from samba while fixing badlock.
could anyone help regarding this issue?
Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled
Heimdal), but have zero time to work on it at the moment. If none gets
there first I'll fix it in a couple of weeks (or at least look into it).
Haven't seen any functional impact until you mentioned that audit log.
Thanks,
Uri.
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
VigneshDhanraj G
2016-06-28 13:26:42 UTC
Permalink
Is there any update??

On Wed, Jun 15, 2016 at 12:49 PM, VigneshDhanraj G <
Post by VigneshDhanraj G
Is this bug is related to the issue i mentioned
https://bugzilla.samba.org/show_bug.cgi?id=11769
Regards,
Vigneshdhanraj G
On Tue, Jun 14, 2016 at 2:30 PM, VigneshDhanraj G <
Post by VigneshDhanraj G
Is there any patch for it?
Regards,
Vigneshdhanraj G
On Fri, Jun 10, 2016 at 12:36 AM, VigneshDhanraj G <
Post by VigneshDhanraj G
Thanks uri, make that happen.
Post by VigneshDhanraj G
Post by VigneshDhanraj G
Hi all,
Hi all,
I upgraded samba from 4.2.9 to 4.2.12. After upgrade i am seeing
numerous
Post by VigneshDhanraj G
amount of kerberos errors in DC event. Event id- 4768(Audit Failure)
A Kerberos authentication ticket (TGT) was requested.
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID
There is no user as root in my DC and there is no functionality
breakup. It
Post by VigneshDhanraj G
is getting correct user name .But, by default first kerberos ticket
requested by root. whenever samba is restarted or communicating with
my
Post by VigneshDhanraj G
system. Audit failure logs are dumped.
I think it might be a regression issue from samba while fixing
badlock.
Post by VigneshDhanraj G
could anyone help regarding this issue?
Seen it too (in packet traces, 4.3.latest, net ads join -k, bundled
Heimdal), but have zero time to work on it at the moment. If none gets
there first I'll fix it in a couple of weeks (or at least look into it).
Haven't seen any functional impact until you mentioned that audit log.
Thanks,
Uri.
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Loading...