From: Predrag Gavrilovic on

I also have this problem, running samba 3.4.7 from debian backports on
Lenny.
I have applied registry patches as suggested on samba wiki:

HKLM\System\CCS\Services\LanmanWorkstation\Parameters
DWORD DomainCompatibilityMode = 1
DWORD DNSNameResolutionRequired = 0

Windows 7 joins domain but trust relation fails after month or so with
"netlogon_creds_server_check failed" error. Needless to say, XP and
Vista work ok.

Can anyone (please) confirm possibility of windows 7 joining samba
domain and staying joined for more than a month.
If so, what version of samba is working? Is samba 3.5 required, or other
registry patches mentioned (as not needed) in wiki?

Време: 16.12.2009. 06:06, Alex Ferrara пише:
> _netr_ServerAuthenticate3: netlogon_creds_server_check failed. Rejecting auth request from client AC-2150 machine account AC-2150$
>
> I have noticed that the new Windows 7 machines say the password has expired on the same date that is in "sambaPwdLastSet". I added the "X" attribute in sambaAcctFlags in an attempt to stop the accounts from expiring. Below is an ldif of a Windows 7 machine trust account
>
> dn: uid=ac-2150$,ou=computers,dc=domain,dc=local
> objectClass: top
> objectClass: account
> objectClass: posixAccount
> objectClass: sambaSamAccount
> cn: ac-2150$
> uid: ac-2150$
> uidNumber: 1111
> gidNumber: 515
> homeDirectory: /dev/null
> loginShell: /bin/false
> description: Computer
> gecos: Computer
> sambaDomainName: DOMAIN
> sambaPrimaryGroupSID: S-1-5-21-3581057417-3103041693-70022037-515
> sambaSID: S-1-5-21-3581057417-3103041693-70022037-3222
> sambaNTPassword: DABA25E3910551C63347D399520C123D
> sambaAcctFlags: [WX ]
> sambaPwdLastSet: 1260776037
>
> Any help would be appreciated.
>
> aF
> -- To unsubscribe from this list go to the following URL and read the
> instructions: https://lists.samba.org/mailman/options/samba


--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
From: Roel van Meer on
Predrag Gavrilovic writes:

> Windows 7 joins domain but trust relation fails after month or so with
> "netlogon_creds_server_check failed" error. Needless to say, XP and
> Vista work ok.
>
> Can anyone (please) confirm possibility of windows 7 joining samba
> domain and staying joined for more than a month.
> If so, what version of samba is working? Is samba 3.5 required, or other
> registry patches mentioned (as not needed) in wiki?

We have been using samba 3.5.[12] and with those the Windows 7 trust
relation stays intact.

Regards,

roel


--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
From: tms3 on

SNIP
> Windows 7 joins domain but trust relation fails after month or so with
> "netlogon_creds_server_check failed" error. Needless to say, XP and
> Vista work ok.
>
> Can anyone (please) confirm possibility of windows 7 joining samba
> domain and staying joined for more than a month.
> If so, what version of samba is working? Is samba 3.5 required, or
> other
> registry patches mentioned (as not needed) in wiki?

Version samba34-3.4.5_1 on FreeBSD 8.0 and 7.2 with LDAP backend, 14
WAN connected nodes, no account expiration.
>
>
>
> Време: 16.12.2009. 06:06, Alex Ferrara пише:
>>
>> _netr_ServerAuthenticate3: netlogon_creds_server_check failed.
>> Rejecting auth request from client AC-2150 machine account AC-2150$
>>
>> I have noticed that the new Windows 7 machines say the password has
>> expired on the same date that is in "sambaPwdLastSet". I added the
>> "X" attribute in sambaAcctFlags in an attempt to stop the accounts
>> from expiring. Below is an ldif of a Windows 7 machine trust account
>>
>> dn: uid=ac-2150$,ou=computers,dc=domain,dc=local
>> objectClass: top
>> objectClass: account
>> objectClass: posixAccount
>> objectClass: sambaSamAccount
>> cn: ac-2150$
>> uid: ac-2150$
>> uidNumber: 1111
>> gidNumber: 515
>> homeDirectory: /dev/null
>> loginShell: /bin/false
>> description: Computer
>> gecos: Computer
>> sambaDomainName: DOMAIN
>> sambaPrimaryGroupSID: S-1-5-21-3581057417-3103041693-70022037-515
>> sambaSID: S-1-5-21-3581057417-3103041693-70022037-3222
>> sambaNTPassword: DABA25E3910551C63347D399520C123D
>> sambaAcctFlags: [WX ]
>> sambaPwdLastSet: 1260776037
>>
>> Any help would be appreciated.
>>
>> aF
>> -- To unsubscribe from this list go to the following URL and read the
>> instructions: https://lists.samba.org/mailman/options/samba
>
>
> --
> To unsubscribe from this list go to the following URL and read the
> instructions: https://lists.samba.org/mailman/options/samba

--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
From: Predrag Gavrilovic on
Thank you all for prompt responses

Have you applied any other registry patches beside those that I have
applied?

Predrag Gavrilovic

Време: 19.05.2010. 14:57, tms3(a)tms3.com пише:
>
> SNIP
>> Windows 7 joins domain but trust relation fails after month or so with
>> "netlogon_creds_server_check failed" error. Needless to say, XP and
>> Vista work ok.
>>
>> Can anyone (please) confirm possibility of windows 7 joining samba
>> domain and staying joined for more than a month.
>> If so, what version of samba is working? Is samba 3.5 required, or other
>> registry patches mentioned (as not needed) in wiki?
>
> Version samba34-3.4.5_1 on FreeBSD 8.0 and 7.2 with LDAP backend, 14 WAN
> connected nodes, no account expiration.
>>
>>
>>
>> Време: 16.12.2009. 06:06, Alex Ferrara пише:
>>>
>>> _netr_ServerAuthenticate3: netlogon_creds_server_check failed.
>>> Rejecting auth request from client AC-2150 machine account AC-2150$
>>>
>>> I have noticed that the new Windows 7 machines say the password has
>>> expired on the same date that is in "sambaPwdLastSet". I added the
>>> "X" attribute in sambaAcctFlags in an attempt to stop the accounts
>>> from expiring. Below is an ldif of a Windows 7 machine trust account
>>>
>>> dn: uid=ac-2150$,ou=computers,dc=domain,dc=local
>>> objectClass: top
>>> objectClass: account
>>> objectClass: posixAccount
>>> objectClass: sambaSamAccount
>>> cn: ac-2150$
>>> uid: ac-2150$
>>> uidNumber: 1111
>>> gidNumber: 515
>>> homeDirectory: /dev/null
>>> loginShell: /bin/false
>>> description: Computer
>>> gecos: Computer
>>> sambaDomainName: DOMAIN
>>> sambaPrimaryGroupSID: S-1-5-21-3581057417-3103041693-70022037-515
>>> sambaSID: S-1-5-21-3581057417-3103041693-70022037-3222
>>> sambaNTPassword: DABA25E3910551C63347D399520C123D
>>> sambaAcctFlags: [WX ]
>>> sambaPwdLastSet: 1260776037
>>>
>>> Any help would be appreciated.
>>>
>>> aF
>>> -- To unsubscribe from this list go to the following URL and read the
>>> instructions: https://lists.samba.org/mailman/options/samba
>>
>>
>> --
>> To unsubscribe from this list go to the following URL and read the
>> instructions: https://lists.samba.org/mailman/options/samba
>


--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
From: John Drescher on
> Have you applied any other registry patches beside those that I have
> applied?
>
I have not and I do not have any trust problems.

John
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba