Networking Forums

Networking Forums > Computer Networking > Windows Networking > Cannot mount network share

Reply
Thread Tools Display Modes

Cannot mount network share

 
 
Steven
Guest
Posts: n/a

 
      05-23-2006, 08:04 PM
I am running a Linux box with mounts to a windows fileserver. This fileserver
was just a domain member, I recently restructured things and the fileserver
is now a domain controller. Since I upgraded smbclient can no longer
authenticate correctly to the server. I have found the reason in KB article
870987.
http://support.microsoft.com/kb/870987

My question is, is there any work-around?

At this stage I am looking to demote the server to a member server again.
 
Reply With Quote
 
 
 
 
Scott Lowe
Guest
Posts: n/a

 
      05-23-2006, 08:26 PM
On 2006-05-23 16:04:01 -0400, Steven <ms at x-wired dot net.nz> said:

> I am running a Linux box with mounts to a windows fileserver. This
> fileserver was just a domain member, I recently restructured things and
> the fileserver is now a domain controller. Since I upgraded smbclient
> can no longer authenticate correctly to the server. I have found the
> reason in KB article 870987.
> http://support.microsoft.com/kb/870987
>
> My question is, is there any work-around?
>
> At this stage I am looking to demote the server to a member server again.


Are you sure that's the problem you are experiencing? Generally, Linux
boxes don't do Kerberos against Active Directory unless they've been
specifically configured to do so, and then their communication is with
a DC (KDC in the Kerberos world).

More likely, iMHO, is the configuration for the "LAN Manager
authentication level" policy setting. It's probably been bumped up to
NTLM v2 only or similar, and now your Samba client can't authenticate.
Have a look at the Local Security Policy and see what the settings are
for SMB signing and LAN Manager authentication levels.

Also, I just read earlier today that smb.conf has a "client ntlmv2 auth
= yes" setting that may fix this problem as well. I have not had the
opportunity to test that myself yet.

HTH.

--
Regards,
Scott Lowe
ePlus Technology Inc.

 
Reply With Quote
 
Steven
Guest
Posts: n/a

 
      05-24-2006, 08:20 AM
Thankyou for your input on this.

It Appears the Policy
Digitally sign commenications (if client agrees)
had to be disabled.

This this seems to be a work-around to the problem. Without an in depth
understanding of how this, it seems that smbclient cantdigitally sign the
communications even though it agrees, possibly due to the fix in the below KB
article.

You are right that NTLM is bumped up to v2, and I had tried both reducing it
on the server and adding the extra client ntlmv2 auth = yes.
What made me think that it is the bug below, is the fact that smbclient
authenticated without a problem - well you can see the correct user is
connected in Computer Management - and that when i reset the users password,
the first transaction would succeed and subsequent ones would fail.
"Scott Lowe" wrote:

> On 2006-05-23 16:04:01 -0400, Steven <ms at x-wired dot net.nz> said:
>
> > I am running a Linux box with mounts to a windows fileserver. This
> > fileserver was just a domain member, I recently restructured things and
> > the fileserver is now a domain controller. Since I upgraded smbclient
> > can no longer authenticate correctly to the server. I have found the
> > reason in KB article 870987.
> > http://support.microsoft.com/kb/870987
> >
> > My question is, is there any work-around?
> >
> > At this stage I am looking to demote the server to a member server again.

>
> Are you sure that's the problem you are experiencing? Generally, Linux
> boxes don't do Kerberos against Active Directory unless they've been
> specifically configured to do so, and then their communication is with
> a DC (KDC in the Kerberos world).
>
> More likely, iMHO, is the configuration for the "LAN Manager
> authentication level" policy setting. It's probably been bumped up to
> NTLM v2 only or similar, and now your Samba client can't authenticate.
> Have a look at the Local Security Policy and see what the settings are
> for SMB signing and LAN Manager authentication levels.
>
> Also, I just read earlier today that smb.conf has a "client ntlmv2 auth
> = yes" setting that may fix this problem as well. I have not had the
> opportunity to test that myself yet.
>
> HTH.
>
> --
> Regards,
> Scott Lowe
> ePlus Technology Inc.
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Network Service on Windows Server 2008 cannot mount a share steve.nickels@gmail.com Windows Networking 0 10-01-2008 04:50 PM
Mount an NFS share with a password? Cork Soaker Linux Networking 8 08-08-2008 01:12 PM
Mount Local Disk on Network Share. Neebski Windows Networking 0 02-23-2008 06:22 AM
mount windows NFS share from linux syntax reader@newsguy.com Windows Networking 1 09-04-2006 09:55 PM
Cannot mount network share Steven Windows Networking 1 05-23-2006 08:08 PM



1 2 3 4 5 6 7 8 9 10 11