Hi,
I found a strange error message in the messages log after logging in to Nethserver. It says " _netr_ServerAuthenticate3: netlogon_creds_sernetlogon_creds_server_check failed. Rejecting auth request from client M1 machine account M1$".
But in fact the user is logged in with all his file sharing rights.
Any idea, what this message i about?
I would like to know why the machine logon is rejected. In fact this win 7 client is a domain member. What creates this error message? Also the logon process takes a bit long what maybe has to do with it.
Does the NS PDC act as a wins server? Or is that obsolete?
Rasi, are the clocks of the two systems synchronized ?.
Tip: Log on as local Admin then try to synchronize the time of the win 7 client to the time of NS and then try again the logon in domain,
Thanks for the tip. But the time of NS and win 7 client are in sync. Any other ideas?
By the way, the whole error message starts with “rpc_server/netogon/srv_netlogon_nt.c:976”. Does that give a clue?
Hi Rasi, you can check the following and see if something is wrong.
Firewall is on on the win machine? (turn it off if it is)
Te win7 client takes the IP via dhcp with the correct DNS settings?
Also take a look on this join win clients to NS Domain maybe it help. Especially about the registry key.
Hi Bogdan,
the Howto “join win clients to NS Domain” says:
"After the NS is set up as AD, on this page the LDAP settings should be visible."
That is not the case here. NS is marked as PDC but no LDAP information. Has this changed or does something go wrong inside my NS?
Damned copy and paste! No, the correct error log says:
"rpc_server/netlogon/srv_netlog_nt.c:976(_netr_ServerAuthenticate3)
… smbd[28384]: _netr_ServerAuthenticate3: netlogon_creds_server_check failed. Rejecting auth request from client WSx machine account WSx$"
This message appears whenever a user logs in from whichever machine (all being Windows 7 clients).
The output of “rpm -qa | grep samba” is:
samba-winbind-clients-3.6.23-20.el6.x86_64
nethserver-samba-1.5.4-1.ns6.noarch
samba-common-3.6.23-20.el6.x86_64
samba-client-3.6.23-20.el6.x86_64
samba-winbind-3.6.23-20.el6.x86_64
samba-3.6.23-20.el6.x86_64
please, give us as much details about the history of your lan setup… I mean: were the clients already joined to another domain before being joined to NS?
tell us everything please…
meanwhile, just for test (and if you haven’t did it already), take a client, un-join it from the domain and re-add it and try again
Yes, before we used Zentyal with Samba4 as ADS. Of course, all clients were joined to this server before.
When I take a client out of the NS domain by joing it to a fake workgroup and rejoin it afterwards, the problem remains.
well… Windows can’t join a NT style domain after being part of a AD domain…
as you see, your users can login, but your setup isn’t working as expected.
this is not a NS issue but a windows’ one.
to make all thing work in the right way you’d reinstall all the clients from scratch.
BTW, to help us to help you, for the future, remember to tell us ALL the WHOLE story
remember we don’t know anything about your setup, your server, your clients, we can’t see what you see… so it’s up to you to be verbose since the beginning…