Bug 5753 - pam_winbind fails with Internal module error (retval = 4, user = 'domain+user')
Summary: pam_winbind fails with Internal module error (retval = 4, user = 'domain+user')
Status: RESOLVED WORKSFORME
Alias: None
Product: Samba 3.0
Classification: Unclassified
Component: winbind (show other bugs)
Version: 3.0.28a
Hardware: x86 Linux
: P3 normal
Target Milestone: none
Assignee: Samba Bugzilla Account
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-09-11 12:01 UTC by sven bohm(mai laddress dead)
Modified: 2021-01-04 17:12 UTC (History)
0 users

See Also:


Attachments
winbind logfiles (3.92 KB, application/zip)
2008-09-12 12:49 UTC, sven bohm(mai laddress dead)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description sven bohm(mai laddress dead) 2008-09-11 12:01:38 UTC
We have a two domain (NT4) setup with a primary domain and a trusted domain. I'm trying to authenticate users on ssh using pam_winbind. Primary domain users can authenticate fine. Both primary and 'trusted domain' users can connect fine using smbclient. 

However, when a 'trusted domain' user tries to log on to ssh with the correct password, i get a internal module error (retval = 4, user = 'domain+user'). When the same user tries to log on with an wrong password I get an NT_STATUS_WRONG_PASSWORD.  

The same setup worked fine on version 3.0.22 (ubuntu dapper), I'm in the process of upgrading to hardy.
Comment 1 sven bohm(mai laddress dead) 2008-09-11 13:03:41 UTC
I did some testing with older versions and the problem started between version 3.0.24 and 3.0.26. That is 3.0.24 did not result in an internal module error, 3.0.26 did.
Comment 2 Guenther Deschner 2008-09-11 14:32:11 UTC
Can you please upload your winbindd logfiles ?
Comment 3 sven bohm(mai laddress dead) 2008-09-12 12:49:18 UTC
Created attachment 3573 [details]
winbind logfiles

attached are the winbind logfiles. To create the files I attempted one logon using a trusted domain account with a wrong password, followed by one attempt with the correct password. The internal module error is only thrown when the password is correct.
Comment 4 Björn Jacke 2021-01-04 17:12:04 UTC
this is known to be working in recent and supported samba versions