[Bug 239601] New: Winbind offline login loses credentials while windows user still logged in
https://bugzilla.novell.com/show_bug.cgi?id=239601 Summary: Winbind offline login loses credentials while windows user still logged in Product: openSUSE 10.2 Version: Final Platform: x86 OS/Version: SuSE Other Status: NEW Severity: Major Priority: P5 - None Component: Other AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: slea@taupehat.com QAContact: qa@suse.de Have set up here a laptop with openSUSE 10.2, clean install. Laptop was installed at the location of a Windows 2000 AD domain, and was joined to the domain during the regular installation process which progressed without apparent error. While "on the lot," the laptop works perfectly, with no apparent errors. When off the lot, user authentication for known domain accounts (accounts which have previously logged in to the laptop) works correctly at first, throwing only the "cached credentials" advisory. Within some brief period of time (about 15-30 minutes), desktop applications being acting strangely or not launching - it looks as though IPC isn't working. Launching a terminal from the logged in user results in a fifteen minute wait (+- 10 minutes) and ultimately the shell displays "I have no name!" indicating some sort of pam meltdown maybe? From that point on, domain accounts can no longer log in, and the currently-logged-in domain user cannot save open documents or otherwise maintain any sort of state, as the OS no longer recognizes that user's rights to write (or read) anywhere. The only log hit that's apparent when this happens is as follows: [2007/01/26 21:19:21, 1] nsswitch/winbindd_group.c:winbindd_getgrnam(370) group 0 in domain FOO does not exist Below is the entirety of my smb.conf. The only edit I've made to this paste is to change the domain and realm with FOO and FOO.EXAMPLE respectively: [global] idmap gid = 10000-20000 idmap uid = 10000-20000 realm = FOO.EXAMPLE security = ADS template homedir = /home/%D/%U template shell = /bin/bash usershare allow guests = No winbind offline logon = yes winbind refresh tickets = yes workgroup = FOO winbind use default domain = yes It really looks as if the "magic" that "winbind refresh tickets = yes" is supposed to perform is failing, or perhaps winbind is trying to refresh tickets on an overly-aggressive schedule. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 chrubis@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|bnc-team- |samba-maintainers@SuSE.de |screening@forge.provo.novell| |.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 gd@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |samba-maintainers@SuSE.de AssignedTo|samba-maintainers@SuSE.de |gd@novell.com Status|NEW |ASSIGNED ------- Comment #1 from gd@novell.com 2007-02-07 03:45 MST ------- Can you please check the new rpms from: ftp://ftp.suse.com/pub/projects/samba/3.0/10.2/ ? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 ------- Comment #2 from slea@taupehat.com 2007-02-20 21:49 MST ------- Seems to be working out. From curiosity, what was the changed component? Feel free to marked RESOLVED. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 gd@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |RESOLVED Resolution| |DUPLICATE ------- Comment #3 from gd@novell.com 2007-02-21 03:25 MST ------- IIRC it was this fix: http://websvn.samba.org/cgi-bin/viewcvs.cgi?rev=20171&view=rev Thanks for the report, closing. *** This bug has been marked as a duplicate of bug 227782 *** -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 slea@taupehat.com changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |slea@taupehat.com ------- Comment #4 from slea@taupehat.com 2007-02-22 23:19 MST ------- Uhh, Guenther, I'm getting the following: " You are not authorized to access bug #227782. " I'd love to get a better sense of what broke here (thanks for the CVS link, by the way) and the discussion of the original bug would be illuminative. Any chance of opening this up? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=239601 ------- Comment #5 from slea@taupehat.com 2007-03-08 16:12 MST ------- Seriously now. Bug #227782 is closed, but the patch has been out for weeks now. Can we please unlock this bug? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com