<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Hello,<br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I have upgraded a client and a freeipa server from Fedora 24 to 25 recently.<br></div>And I *cannot* access linux shares located on the F25 freeipa client from a windows desktop.<br>But I can access linux shares located on the F25 freeipa server from that windows desktop.<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">And I can access linux shares located on the F24 freeipa client from that windows desktop.</div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">To be clear, I have:<br><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">  A/ 1 F25 freeipa server<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">  B/ 1 F25 freeipa client<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">  C/ 1 F24 freeipa client<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">  D/ 1 windows desktop<br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I can access linux shares of A from D.<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I can access linux shares of C from D.<br></div>I *cannot* access linux shares of B from D.<br><br><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I get these messages on B in /var/log/samba/log.10.0.21.247 :<br><br><span style="font-family:monospace,monospace">[2016/12/01 11:42:19.218759,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:534(fill_mem_keytab_<wbr>from_dedicated_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:534: smb_krb5_open_keytab failed (Key table name malformed)<br>[2016/12/01 11:42:19.218800,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:627(gse_krb5_get_<wbr>server_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:627: Error! Unable to set mem keytab - -1765328205<br>[2016/12/01 11:42:19.218823,  1] ../auth/gensec/gensec_start.c:<wbr>698(gensec_start_mech)<br>  Failed to start GENSEC server mech gse_krb5: NT_STATUS_INTERNAL_ERROR<br>[2016/12/01 11:42:19.261611,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:534(fill_mem_keytab_<wbr>from_dedicated_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:534: smb_krb5_open_keytab failed (Key table name malformed)<br>[2016/12/01 11:42:19.261638,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:627(gse_krb5_get_<wbr>server_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:627: Error! Unable to set mem keytab - -1765328205<br>[2016/12/01 11:42:19.261653,  1] ../auth/gensec/gensec_start.c:<wbr>698(gensec_start_mech)<br>  Failed to start GENSEC server mech gse_krb5: NT_STATUS_INTERNAL_ERROR<br>[2016/12/01 11:42:19.263330,  2] ../source3/auth/auth.c:315(<wbr>auth_check_ntlm_password)<br>  check_ntlm_password:  Authentication for user [smith] -> [smith] FAILED with error NT_STATUS_NO_SUCH_USER<br>[2016/12/01 11:42:19.263380,  2] ../auth/gensec/spnego.c:720(<wbr>gensec_spnego_server_<wbr>negTokenTarg)<br>  SPNEGO login failed: NT_STATUS_NO_SUCH_USER<br>[2016/12/01 11:42:19.270531,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:534(fill_mem_keytab_<wbr>from_dedicated_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:534: smb_krb5_open_keytab failed (Key table name malformed)<br>[2016/12/01 11:42:19.270562,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:627(gse_krb5_get_<wbr>server_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:627: Error! Unable to set mem keytab - -1765328205<br>[2016/12/01 11:42:19.270586,  1] ../auth/gensec/gensec_start.c:<wbr>698(gensec_start_mech)<br>  Failed to start GENSEC server mech gse_krb5: NT_STATUS_INTERNAL_ERROR<br>[2016/12/01 11:42:19.313479,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:534(fill_mem_keytab_<wbr>from_dedicated_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:534: smb_krb5_open_keytab failed (Key table name malformed)<br>[2016/12/01 11:42:19.313506,  1] ../source3/librpc/crypto/gse_<wbr>krb5.c:627(gse_krb5_get_<wbr>server_keytab)<br>  ../source3/librpc/crypto/gse_<wbr>krb5.c:627: Error! Unable to set mem keytab - -1765328205<br>[2016/12/01 11:42:19.313523,  1] ../auth/gensec/gensec_start.c:<wbr>698(gensec_start_mech)<br>  Failed to start GENSEC server mech gse_krb5: NT_STATUS_INTERNAL_ERROR<br>[2016/12/01 11:42:19.315256,  2] ../source3/auth/auth.c:315(<wbr>auth_check_ntlm_password)<br>  check_ntlm_password:  Authentication for user [smith] -> [smith] FAILED with error NT_STATUS_NO_SUCH_USER<br>[2016/12/01 11:42:19.315291,  2] ../auth/gensec/spnego.c:720(<wbr>gensec_spnego_server_<wbr>negTokenTarg)<br>  SPNEGO login failed: NT_STATUS_NO_SUCH_USER</span><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Also from the F25 server, I have the following when I run smbclient<br><br><span style="font-family:monospace,monospace">f25server # smbclient -k -L f25desktop.mydomain<br>lp_load_ex: changing to config backend registry<br>session setup failed: NT_STATUS_LOGON_FAILURE<br></span><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">But if i run it with a F24 desktop, it works:<br><br><span style="font-family:monospace,monospace">f25server # smbclient -k -L f24desktop.mydomain<br>lp_load_ex: changing to config backend registry<br>Domain=[MYDOMAIN] OS=[Windows 6.1] Server=[Samba 4.4.7]<br><br>    Sharename       Type      Comment<br>    ---------       ----      -------<br>    IPC$            IPC       IPC Service (Samba Server Version 4.4.7)<br>    data            Disk      /data on f24desktop<br>    data2           Disk      /data2 on f24desktop<br>    data3           Disk      /data3 on f24desktop<br>    backup          Disk      /backup on f24desktop<br>[...]<br></span><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">net conf list on the f25desktop gives:<br><br><span style="font-family:monospace,monospace">f25desktop # net conf list<br>[global]<br>    workgroup = MYDOMAIN<br>    realm = MYDOMAIN<br>    netbios name = F25SERVER<br>    server string = Samba Server Version %v<br>    kerberos method = dedicated keytab<br>    dedicated keytab file = FILE:/etc/samba/samba.keytab<br>    log file = /var/log/samba/log.%m<br>    rpc_server:epmapper = external<br>    rpc_server:lsarpc = external<br>    rpc_server:lsass = external<br>    rpc_server:lsasd = external<br>    rpc_server:samr = external<br>    rpc_server:netlogon = external<br>    rpc_server:tcpip = yes<br>    rpc_daemon:epmd = fork<br>    rpc_daemon:lsasd = fork<br>    security = user<br>    map untrusted to domain = Yes<br>    smb ports = 139 445<br>    log level = 2<br><br>[data]<br>    comment = /data on f25desktop<br>    path = /data<br>    create mask = 0644<br>    read only = no<br><br>[data2]<br>    comment = /data2</span><span style="font-family:monospace,monospace"><span style="font-family:monospace,monospace"></span> on f25desktop<br>    path = /data2<br>    create mask = 0644<br>    read only = no<br><br>[data3]<br>    comment = /data3 on f25desktop<br>    path = /data3<br>    create mask = 0644<br>    read only = no<br><br>[backup]<br>    comment = /backup on f25desktop<br>    path = /backup<br>    read only = no</span><br><br>net conf list on the f25server gives:<br><span style="font-family:monospace,monospace"><br>f25server # net conf list</span><br><span style="font-family:monospace,monospace">[global]<br>    workgroup = MYDOMAIN<br>    netbios name = F25SERVER<br>    realm = MYDOMAIN<span class="gmail-im"><br>    kerberos method = dedicated keytab<br>    dedicated keytab file = FILE:/etc/samba/samba.keytab<br></span>    create krb5 conf = no<br>    domain master = yes<br>    domain logons = yes<br>    max log size = 10000<br>    log file = /var/log/samba/log.%m<br>    passdb backend = ipasam:ldapi://%2fvar%2frun%</span><wbr><span style="font-family:monospace,monospace">2fslapd-MYDOMAIN.socket<br>    disable spoolss = yes<br>    ldapsam:trusted = yes<br>    ldap ssl = off<br>    ldap suffix = dc=mydomain<br>    ldap user suffix = cn=users,cn=accounts<br>    ldap group suffix = cn=groups,cn=accounts<br>    ldap machine suffix = cn=computers,cn=accounts<span class="gmail-im"><br>    rpc_server:epmapper = external<br>    rpc_server:lsarpc = external<br>    rpc_server:lsass = external<br>    rpc_server:lsasd = external<br>    rpc_server:samr = external<br>    rpc_server:netlogon = external<br>    rpc_server:tcpip = yes<br>    rpc_daemon:epmd = fork<br>    rpc_daemon:lsasd = fork<br>    security = user<br></span>    enable core files = no<br>    log level = 2<br><br>[homes]<br>    comment = Home Directories<br>    read only = no<br>    browseable = yes<br>    create mask = 0664<br>    directory mask = 0775<br></span><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">on the F25 server and desktop, i have the following packages installed:<br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><span style="font-family:monospace,monospace">samba-4.5.1-1.fc25.x86_64<br>samba-client-4.5.1-1.fc25.x86_<wbr>64<br>samba-client-libs-4.5.1-1.<wbr>fc25.x86_64<br>samba-common-4.5.1-1.fc25.<wbr>noarch<br>samba-common-libs-4.5.1-1.<wbr>fc25.x86_64<br>samba-common-tools-4.5.1-1.<wbr>fc25.x86_64<br>samba-libs-4.5.1-1.fc25.x86_64<br>samba-python-4.5.1-1.fc25.x86_<wbr>64<br>samba-test-4.5.1-1.fc25.x86_64<br>samba-test-libs-4.5.1-1.fc25.<wbr>x86_64<br>samba-winbind-4.5.1-1.fc25.<wbr>x86_64<br>samba-winbind-clients-4.5.1-1.<wbr>fc25.x86_64<br>samba-winbind-krb5-locator-4.<wbr>5.1-1.fc25.x86_64<br>samba-winbind-modules-4.5.1-1.<wbr>fc25.x86_64<br>system-config-samba-1.2.100-5.<wbr>fc24.noarch<br>system-config-samba-docs-1.0.<wbr>9-9.fc24.noarch</span><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Any idea what is wrong?<br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Regards, <br></div>Fuji<br></div></div>