lp_load: refreshing parameters from /usr/local/samba/etc/smb.conf params.c:pm_process() - Processing configuration file "/usr/local/samba/etc/smb.conf" Processing section "[globals]" Processing section "[netlogon]" Processing section "[sysvol]" pm_process() returned Yes adding hidden service IPC$ adding hidden service ADMIN$ smbd version 4.0.0alpha3-GIT--e 71347dd-[SVN-SAMBA_4_0@26701] started. Copyright Andrew Tridgell and the Samba Team 1992-2007 SHARE backend [ldb] registered. SHARE backend [classic] registered. AUTH backend 'winbind_samba3' registered AUTH backend 'winbind' registered AUTH backend 'name_to_ntstatus' registered AUTH backend 'fixed_challenge' registered AUTH backend 'unix' registered AUTH backend 'anonymous' registered AUTH backend 'sam' registered AUTH backend 'sam_ignoredomain' registered GENSEC backend 'krb5' registered gensec subsystem fake_gssapi_krb5 is disabled GENSEC backend 'schannel' registered GENSEC backend 'spnego' registered gensec subsystem gssapi_spnego is disabled GENSEC backend 'gssapi_krb5' registered GENSEC backend 'gssapi_krb5_sasl' registered GENSEC backend 'ntlmssp' registered NTPTR backend 'simple_ldb' NTVFS backend 'simple' for type 0 registered NTVFS backend 'cifs' for type 0 registered NTVFS backend 'nbench' for type 0 registered NTVFS backend 'unixuid' for type 0 registered NTVFS backend 'unixuid' for type 1 registered NTVFS backend 'unixuid' for type 2 registered NTVFS backend 'cifsposix' for type 0 registered NTVFS backend 'default' for type 2 registered NTVFS backend 'xattr' registered NTVFS backend 'nfs4acl' registered NTVFS backend 'default' for type 1 registered NTVFS backend 'default' for type 0 registered NTVFS backend 'posix' for type 0 registered PROCESS_MODEL 'standard' registered PROCESS_MODEL 'single' registered DCERPC endpoint server 'wkssvc' registered DCERPC endpoint server 'drsuapi' registered DCERPC endpoint server 'spoolss' registered DCERPC endpoint server 'winreg' registered DCERPC endpoint server 'epmapper' registered DCERPC endpoint server 'srvsvc' registered DCERPC endpoint server 'netlogon' registered DCERPC endpoint server 'rpcecho' registered DCERPC endpoint server 'unixinfo' registered DCERPC endpoint server 'samr' registered DCERPC endpoint server 'remote' registered DCERPC endpoint server 'dssetup' registered DCERPC endpoint server 'lsarpc' registered smbd: using 'standard' process model dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncacn_np:[\pipe\epmapper]' dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncacn_ip_tcp:[135]' dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncalrpc:[EPMAPPER]' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncacn_np:[\pipe\srvsvc]' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncacn_np:[\pipe\wkssvc]' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncacn_np:[\pipe\rpcecho]' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncacn_np:[\pipe\samr]' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncacn_np:[\pipe\netlogon]' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\netlogon]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'spoolss' registered on endpoint 'ncacn_np:[\pipe\spoolss]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_np:[\pipe\protected_storage]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncacn_np:[\pipe\winreg]' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncacn_np:[\pipe\unixinfo]' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncalrpc:' ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so added interface ip=192.168.0.2 nmask=255.255.255.0 ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so added interface ip=192.168.0.2 nmask=255.255.255.0 ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so added interface ip=192.168.0.2 nmask=255.255.255.0 ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load partition from /usr/local/samba/modules/ldb/partition.so ldb: trying to load show_deleted from /usr/local/samba/modules/ldb/show_deleted.so ldb: trying to load linked_attributes from /usr/local/samba/modules/ldb/linked_attributes.so ldb: trying to load subtree_delete from /usr/local/samba/modules/ldb/subtree_delete.so ldb: trying to load subtree_rename from /usr/local/samba/modules/ldb/subtree_rename.so ldb: trying to load kludge_acl from /usr/local/samba/modules/ldb/kludge_acl.so ldb: trying to load objectclass from /usr/local/samba/modules/ldb/objectclass.so ldb: trying to load samldb from /usr/local/samba/modules/ldb/samldb.so ldb: trying to load extended_dn from /usr/local/samba/modules/ldb/extended_dn.so ldb: trying to load anr from /usr/local/samba/modules/ldb/anr.so ldb: trying to load ranged_results from /usr/local/samba/modules/ldb/ranged_results.so ldb: trying to load rootdse from /usr/local/samba/modules/ldb/rootdse.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so ldb: trying to load objectguid from /usr/local/samba/modules/ldb/objectguid.so ldb: trying to load schema_fsmo from /usr/local/samba/modules/ldb/schema_fsmo.so ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes dreplsrv_partition[CN=Schema,CN=Configuration,DC=bits] loaded dreplsrv_partition[CN=Configuration,DC=bits] loaded dreplsrv_partition[DC=bits] loaded dreplsrv_refresh_partition(DC=bits) dreplsrv_refresh_partition(CN=Configuration,DC=bits) dreplsrv_refresh_partition(CN=Schema,CN=Configuration,DC=bits) dreplsrv_periodic_schedule(15) scheduled for: Tue Mar 25 13:27:31 2008 EDT ldb: schema_fsmo_init: we are master: yes ldb: trying to load naming_fsmo from /usr/local/samba/modules/ldb/naming_fsmo.so ldb: naming_fsmo_init: we are master: yes ldb: trying to load password_hash from /usr/local/samba/modules/ldb/password_hash.so ldb: trying to load pdc_fsmo from /usr/local/samba/modules/ldb/pdc_fsmo.so ldb: pdc_fsmo_init: we are master: yes Registered STORMHOLD<00> with 192.168.0.2 on interface 192.168.0.255 Registered STORMHOLD<03> with 192.168.0.2 on interface 192.168.0.255 Registered STORMHOLD<20> with 192.168.0.2 on interface 192.168.0.255 Registered BITS<1b> with 192.168.0.2 on interface 192.168.0.255 Registered BITS<1c> with 192.168.0.2 on interface 192.168.0.255 Registered BITS<00> with 192.168.0.2 on interface 192.168.0.255 dreplsrv_periodic_run(): schedule pull replication dreplsrv_periodic_run(): run pending_ops dreplsrv_periodic_schedule(300) scheduled for: Tue Mar 25 13:32:31 2008 EDT Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes smbsrv_accept Shutdown SMB signing switch message SMBnegprot (task_id 20418) Requested protocol [0][PC NETWORK PROGRAM 1.0] Requested protocol [1][LANMAN1.0] Requested protocol [2][Windows for Workgroups 3.1a] Requested protocol [3][LM1.2X002] Requested protocol [4][LANMAN2.1] Requested protocol [5][NT LM 0.12] Requested protocol [6][SMB 2.002] Starting GENSEC mechanism spnego Starting GENSEC submechanism gssapi_krb5 using SPNEGO Selected protocol [5][NT LM 0.12] Kerberos: AS-REQ administrator@bits from 192.168.0.100 for krbtgt/bits@bits LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@bits Kerberos: Looking for ENC-TS pa-data -- administrator@bits Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@bits single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@bits from 192.168.0.100 for krbtgt/bits@bits LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@bits Kerberos: Looking for ENC-TS pa-data -- administrator@bits Kerberos: ENC-TS Pre-authentication succeeded -- administrator@bits using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] switch message SMBsesssetupX (task_id 20418) Starting GENSEC mechanism spnego Starting GENSEC submechanism ntlmssp Got NTLMSSP neg_flags=0xe2088297 NTLMSSP_NEGOTIATE_UNICODE NTLMSSP_NEGOTIATE_OEM NTLMSSP_REQUEST_TARGET NTLMSSP_NEGOTIATE_SIGN NTLMSSP_NEGOTIATE_LM_KEY NTLMSSP_NEGOTIATE_NTLM NTLMSSP_NEGOTIATE_ALWAYS_SIGN NTLMSSP_NEGOTIATE_NTLM2 NTLMSSP_NEGOTIATE_128 NTLMSSP_NEGOTIATE_KEY_EXCH NTLMSSP_NEGOTIATE_56 switch message SMBsesssetupX (task_id 20418) Got user=[] domain=[] workstation=[SUNDOWN] len1=1 len2=0 auth_check_password_send: Checking password for unmapped user []\[]@[SUNDOWN] map_user_info: Mapping user []\[] from workstation [SUNDOWN] auth_check_password_send: mapped user is: [BITS]\[]@[SUNDOWN] auth_get_challenge: returning previous challenge by module random (normal) [0000] 3D 42 A0 F6 62 7F B8 C6 =B..b... auth_check_password_recv: anonymous authentication for user [NT AUTHORITY\ANONYMOUS LOGON] succeeded switch message SMBtconX (task_id 20418) dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncacn_np:[\pipe\epmapper]' dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncacn_ip_tcp:[135]' dcesrv_interface_register: interface 'epmapper' registered on endpoint 'ncalrpc:[EPMAPPER]' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncacn_np:[\pipe\srvsvc]' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'srvsvc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncacn_np:[\pipe\wkssvc]' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'wkssvc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncacn_np:[\pipe\rpcecho]' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'rpcecho' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncacn_np:[\pipe\samr]' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'samr' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncacn_np:[\pipe\netlogon]' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'netlogon' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\netlogon]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'lsarpc' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'spoolss' registered on endpoint 'ncacn_np:[\pipe\spoolss]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_np:[\pipe\protected_storage]' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'drsuapi' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncacn_np:[\pipe\winreg]' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'winreg' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsass]' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'dssetup' registered on endpoint 'ncalrpc:' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncacn_np:[\pipe\unixinfo]' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncacn_ip_tcp:' dcesrv_interface_register: interface 'unixinfo' registered on endpoint 'ncalrpc:' 192.168.0.100 closed connection to service IPC$ standard_terminate: reason[NT_STATUS_END_OF_FILE] Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 235 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes Received dgram packet of length 251 from 192.168.0.100:138 netlogon request to BITS<1c> from 192.168.0.100:138 ldb: naming_fsmo_init: we are master: yes ldb: pdc_fsmo_init: we are master: yes smbsrv_accept Shutdown SMB signing switch message SMBnegprot (task_id 20419) Requested protocol [0][PC NETWORK PROGRAM 1.0] Requested protocol [1][LANMAN1.0] Requested protocol [2][Windows for Workgroups 3.1a] Requested protocol [3][LM1.2X002] Requested protocol [4][LANMAN2.1] Requested protocol [5][NT LM 0.12] Starting GENSEC mechanism spnego Starting GENSEC submechanism gssapi_krb5 using SPNEGO Selected protocol [5][NT LM 0.12] Kerberos: AS-REQ administrator@bits from 192.168.0.100 for krbtgt/bits@bits LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@bits Kerberos: Looking for ENC-TS pa-data -- administrator@bits Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@bits single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@bits from 192.168.0.100 for krbtgt/bits@bits LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@bits Kerberos: Looking for ENC-TS pa-data -- administrator@bits Kerberos: ENC-TS Pre-authentication succeeded -- administrator@bits using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: No preauth found, returning PREAUTH-REQUIRED -- administrator@BITS single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: AS-REQ administrator@BITS from 192.168.0.100 for krbtgt/BITS@BITS LDB_lookup_spn_alias: no alias for service krbtgt applicable authsam_account_ok: Checking SMB password for user administrator@BITS logon_hours_ok: No hours restrictions for user administrator@BITS Kerberos: Client sent patypes: encrypted-timestamp, 128 Kerberos: Looking for PKINIT pa-data -- administrator@BITS Kerberos: Looking for ENC-TS pa-data -- administrator@BITS Kerberos: ENC-TS Pre-authentication succeeded -- administrator@BITS using arcfour-hmac-md5 Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, arcfour-hmac-md5, -133, -128, des-cbc-md5, des-cbc-crc, 24, -135 Kerberos: Using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable_ok, canonicalize, renewable, forwardable Kerberos: AS-REQ authtime: 2008-03-25T13:27:46 starttime: unset endtime: 2037-09-12T22:48:05 renew till: 2037-09-12T22:48:05 single_terminate: reason[NT_STATUS_END_OF_FILE] Kerberos: Failed to decrypt enc-authorization-data Kerberos: Failed parsing TGS-REQ from 192.168.0.100 single_terminate: reason[NT_STATUS_END_OF_FILE]