Bug 12992 - ssh using domain user failed with samba+winbind join windows AD
Summary: ssh using domain user failed with samba+winbind join windows AD
Status: RESOLVED DUPLICATE of bug 10490
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Winbind (show other bugs)
Version: 4.5.8
Hardware: x64 Linux
: P5 major (vote)
Target Milestone: ---
Assignee: Samba QA Contact
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-28 10:34 UTC by forward
Modified: 2017-08-29 03:18 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description forward 2017-08-28 10:34:55 UTC
I use winbind to join windows domain, and then execute ssh localhost -l domain_user, it reports following error in the log:

Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.668376,  0] ../lib/util/fault.c:78(fault_report)
Aug 28 17:18:14 dev winbindd[2338]:   ===============================================================
Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.669394,  0] ../lib/util/fault.c:79(fault_report)
Aug 28 17:18:14 dev winbindd[2338]:   INTERNAL ERROR: Signal 11 in pid 2338 (4.5.8-Debian)
Aug 28 17:18:14 dev winbindd[2338]:   Please read the Trouble-Shooting section of the Samba HOWTO
Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.670540,  0] ../lib/util/fault.c:81(fault_report)
Aug 28 17:18:14 dev winbindd[2338]:   ===============================================================
Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.671277,  0] ../source3/lib/util.c:791(smb_panic_s3)
Aug 28 17:18:14 dev winbindd[2338]:   PANIC (pid 2338): internal error
Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.672597,  0] ../source3/lib/util.c:902(log_stack_trace)
Aug 28 17:18:14 dev winbindd[2338]:   BACKTRACE: 27 stack frames:
Aug 28 17:18:14 dev winbindd[2338]:    #0 /usr/lib/x86_64-linux-gnu/libsmbconf.so.0(log_stack_trace+0x1c) [0x7f197bc64c0c]
Aug 28 17:18:14 dev winbindd[2338]:    #1 /usr/lib/x86_64-linux-gnu/libsmbconf.so.0(smb_panic_s3+0x20) [0x7f197bc64ce0]
Aug 28 17:18:14 dev winbindd[2338]:    #2 /usr/lib/x86_64-linux-gnu/libsamba-util.so.0(smb_panic+0x2f) [0x7f197f1c019f]
Aug 28 17:18:14 dev winbindd[2338]:    #3 /usr/lib/x86_64-linux-gnu/libsamba-util.so.0(+0x1b3b6) [0x7f197f1c03b6]
Aug 28 17:18:14 dev winbindd[2338]:    #4 /lib/x86_64-linux-gnu/libpthread.so.0(+0x110c0) [0x7f1980c570c0]
Aug 28 17:18:14 dev winbindd[2338]:    #5 /usr/lib/x86_64-linux-gnu/samba/libkrb5-samba4.so.26(krb5_storage_free+0x1) [0x7f197dc3af11]
Aug 28 17:18:14 dev winbindd[2338]:    #6 /usr/lib/x86_64-linux-gnu/samba/libkrb5-samba4.so.26(+0x36565) [0x7f197dc27565]
Aug 28 17:18:14 dev winbindd[2338]:    #7 /usr/lib/x86_64-linux-gnu/samba/libgse.so.0(+0x8966) [0x7f197a7b2966]
Aug 28 17:18:14 dev winbindd[2338]:    #8 /usr/lib/x86_64-linux-gnu/samba/libgse.so.0(gse_krb5_get_server_keytab+0x14b) [0x7f197a7b2eeb]
Aug 28 17:18:14 dev winbindd[2338]:    #9 /usr/lib/x86_64-linux-gnu/samba/libgse.so.0(+0xa9eb) [0x7f197a7b49eb]
Aug 28 17:18:14 dev winbindd[2338]:    #10 /usr/lib/x86_64-linux-gnu/samba/libgensec.so.0(gensec_start_mech+0xb1) [0x7f197a597401]
Aug 28 17:18:14 dev winbindd[2338]:    #11 /usr/lib/x86_64-linux-gnu/samba/libgensec.so.0(gensec_start_mech_by_oid+0x26) [0x7f197a597736]
Aug 28 17:18:14 dev winbindd[2338]:    #12 /usr/sbin/winbindd(kerberos_return_pac+0x39f) [0x562a9060cb7f]
Aug 28 17:18:14 dev winbindd[2338]:    #13 /usr/sbin/winbindd(winbindd_dual_pam_auth+0x1261) [0x562a9062c471]
Aug 28 17:18:14 dev winbindd[2338]:    #14 /usr/sbin/winbindd(+0x5b3b4) [0x562a906433b4]
Aug 28 17:18:14 dev winbindd[2338]:    #15 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0xaea3) [0x7f1978ec0ea3]
Aug 28 17:18:14 dev winbindd[2338]:    #16 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0x9277) [0x7f1978ebf277]
Aug 28 17:18:14 dev winbindd[2338]:    #17 /usr/lib/x86_64-linux-gnu/libtevent.so.0(_tevent_loop_once+0x9d) [0x7f1978ebb04d]
Aug 28 17:18:14 dev winbindd[2338]:    #18 /usr/sbin/winbindd(+0x5d7ac) [0x562a906457ac]
Aug 28 17:18:14 dev winbindd[2338]:    #19 /usr/sbin/winbindd(+0x5deb5) [0x562a90645eb5]
Aug 28 17:18:14 dev winbindd[2338]:    #20 /usr/lib/x86_64-linux-gnu/libtevent.so.0(tevent_common_loop_immediate+0xd4) [0x7f1978ebba14]
Aug 28 17:18:14 dev winbindd[2338]:    #21 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0xac8d) [0x7f1978ec0c8d]
Aug 28 17:18:14 dev winbindd[2338]:    #22 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0x9277) [0x7f1978ebf277]
Aug 28 17:18:14 dev winbindd[2338]:    #23 /usr/lib/x86_64-linux-gnu/libtevent.so.0(_tevent_loop_once+0x9d) [0x7f1978ebb04d]
Aug 28 17:18:14 dev winbindd[2338]:    #24 /usr/sbin/winbindd(main+0xbc8) [0x562a9060bee8]
Aug 28 17:18:14 dev winbindd[2338]:    #25 /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xf1) [0x7f19788e62b1]
Aug 28 17:18:14 dev winbindd[2338]:    #26 /usr/sbin/winbindd(_start+0x2a) [0x562a9060c57a]
Aug 28 17:18:14 dev winbindd[2338]: [2017/08/28 17:18:14.678071,  0] ../source3/lib/dumpcore.c:298(dump_core)
Aug 28 17:18:14 dev winbindd[2338]:   unable to change to /var/log/samba/cores/winbindd
Aug 28 17:18:14 dev winbindd[2338]:   refusing to dump core





[2017/08/28 17:18:14.448429,  3] ../source3/winbindd/winbindd_getpwnam.c:56(winbindd_getpwnam_send)
  getpwnam qianw\user02
[2017/08/28 17:18:14.449450,  3] ../source3/winbindd/winbindd_misc.c:396(winbindd_interface_version)
  [ 2930]: request interface version (version = 28)
[2017/08/28 17:18:14.449518,  3] ../source3/winbindd/winbindd_misc.c:429(winbindd_priv_pipe_dir)
  [ 2930]: request location of privileged pipe
[2017/08/28 17:18:14.449632,  3] ../source3/winbindd/winbindd_pam_auth.c:54(winbindd_pam_auth_send)
  [ 2930]: pam auth qianw\user02
[2017/08/28 17:18:14.687914,  5] ../source3/winbindd/winbindd_dual.c:579(winbind_child_died)
  Already reaped child 2338 died



my smb.conf:

[global]
     workgroup = QIANW
     security = ADS
     realm = QIANW.COM
     encrypt passwords = yes
     idmap config *:range = 16777216-33554431
     winbind trusted domains only = no
     winbind use default domain = yes
     kerberos method = secrets and keytab
     winbind refresh tickets = yes
     template shell = /bin/bash

     log file = /var/log/samba/%m.log
     log level = 5

any ideas on this issue?

Thanks.
Comment 1 Stefan Metzmacher 2017-08-28 11:56:49 UTC
I guess this is the same as #10490

*** This bug has been marked as a duplicate of bug 10490 ***
Comment 2 forward 2017-08-29 03:18:15 UTC
yes, the patch works!

Thanks for your help Stefan.