[Bug 1760406] [NEW] Samba/Winbind - Windows ActiveDirectory - Event log 4768 audit failure

tom 1760406 at bugs.launchpad.net
Sun Apr 1 10:42:52 UTC 2018


Public bug reported:

Hi all,

I use a Ubuntu 16.04.4 LTS version with samba / winbind packages to get
information of Active Directory (Users, group membership etc). This
information are needed for my squid setup. The information are received
well and the integration into squid.conf works fine. Unfortunately I
have one big problem. I am seeing numerous amount of kerberos errors in
DC event. Event id- 4768(Audit Failure)

A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Information:
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID

There is no user as root in my DC and there is no functionality breakup. It
is getting correct user name. But, by default first kerberos ticket
requested by root. Whenever samba is restarted or communicating with my
system. Audit failure logs are dumped. Over the time (day) there are a lot of such kerberos requests through my DC.

I think it might be a regression issue from samba while fixing badlock.

Could anyone help regarding this issue?

Thanks

** Affects: samba (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: 4768 samba winbind

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to samba in Ubuntu.
https://bugs.launchpad.net/bugs/1760406

Title:
  Samba/Winbind - Windows ActiveDirectory - Event log 4768 audit failure

Status in samba package in Ubuntu:
  New

Bug description:
  Hi all,

  I use a Ubuntu 16.04.4 LTS version with samba / winbind packages to
  get information of Active Directory (Users, group membership etc).
  This information are needed for my squid setup. The information are
  received well and the integration into squid.conf works fine.
  Unfortunately I have one big problem. I am seeing numerous amount of
  kerberos errors in DC event. Event id- 4768(Audit Failure)

  A Kerberos authentication ticket (TGT) was requested.
  Account Information:
  Account Name: root
  Supplied Realm Name: TEST.LOCAL
  User ID: NULL SID
  Service Information:
  Service Name: krbtgt/TEST.LOCAL
  Service ID: NULL SID

  There is no user as root in my DC and there is no functionality breakup. It
  is getting correct user name. But, by default first kerberos ticket
  requested by root. Whenever samba is restarted or communicating with my
  system. Audit failure logs are dumped. Over the time (day) there are a lot of such kerberos requests through my DC.

  I think it might be a regression issue from samba while fixing
  badlock.

  Could anyone help regarding this issue?

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1760406/+subscriptions



More information about the foundations-bugs mailing list