Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Samba/Winbind  "reading winbind reply failed" error

Posted on 2013-11-19
7
Medium Priority
?
3,834 Views
Last Modified: 2013-12-01
disclaimer: windows guy (but getting better at this nix thing)

I'm trying to set up FreeRadius (on debian 7, samba 3.6.6) to authenticate with AD

I've successfully joined the the radius machine to the domain (server 08 r2)
I can successfully wbinfo -u
I can successfully $ ntlm_auth --request-nt-key --domain=MYDOMAIN --username=user --password=password

so all seems good however when I run

radtest -t mschap user password localhost 0 testing123

I get Access-Reject ....[snip]...MS-CHAP-Error = "\000E=691 R=1"

The debug output shows

 Exec-Program output: Reading winbind reply failed! (0xc0000001)
..
..
MS-CHAP-Response is incorrect

My reading says that this may be a permissions issue (http://freeradius.1045715.n5.nabble.com/Reading-winbind-reply-failed-0xc0000001-td5713417.html) however I have added


the freeradius process (freerad) to /etc/group/winbindd_priv

and still see the error.

I've searched and found nothing else to try...

Any ideas?


(and yes all the services have been restarted - after each attempt to configure...)
0
Comment
Question by:SidFishes
  • 4
  • 3
7 Comments
 
LVL 19

Expert Comment

by:xterm
ID: 39660927
> however I have added the freeradius process (freerad) to /etc/group/winbindd_priv

Could you please paste the line that you modified or added in /etc/group so that I can check the syntax?
0
 
LVL 19

Expert Comment

by:xterm
ID: 39660928
I should clarify, you mentioned /etc/group/winbindd_priv, but /etc/group isn't a directory, it's a file, so what you're describing isn't actually possible.
0
 
LVL 36

Author Comment

by:SidFishes
ID: 39662590
"what you're describing isn't actually possible. "

Not what I meant. just referring to the winbindd_priv entry

 /etc/group > winbindd_priv

syntax is simple winbindd_priv:x:119:freerad
0
Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

 
LVL 19

Expert Comment

by:xterm
ID: 39665995
Please run this command and let me know what it finds:

  find /var/run/samba | xargs ls -l
0
 
LVL 36

Accepted Solution

by:
SidFishes earned 0 total points
ID: 39677869
Found the issue.

Despite what I read from several sources, the following is required.

in /etc/freeradius/modules > mschap

you need to edit & uncomment the line

with_ntdomain_hack = yes

This fixes a behaviour where windows sends the username in DOMAIN\user format but sends only the user back as the challenge response

This is clearly noted in the MSCHAP file comments, but I saw many posts saying it was not needed so I didn't try it (or I'd messed with so many settings on the previous install that it was broken when I tried it.)

on the fresh install, worked perfectly.
0
 
LVL 19

Expert Comment

by:xterm
ID: 39678053
Nice job!
0
 
LVL 36

Author Closing Comment

by:SidFishes
ID: 39687891
self-RTFM
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have a server on collocation with the super-fast CPU, that doesn't mean that you get it running at full power. Here is a preamble. When doing inventory of Linux servers, that I'm administering, I've found that some of them are running on l…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Suggested Courses

783 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question