Samba/Winbind - Windows ActiveDirectory - Event log 4768 audit failure

Bug #1760406 reported by tom
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
samba (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Hi all,

I use a Ubuntu 16.04.4 LTS version with samba / winbind packages to get information of Active Directory (Users, group membership etc). This information are needed for my squid setup. The information are received well and the integration into squid.conf works fine. Unfortunately I have one big problem. I am seeing numerous amount of kerberos errors in DC event. Event id- 4768(Audit Failure)

A Kerberos authentication ticket (TGT) was requested.
Account Information:
Account Name: root
Supplied Realm Name: TEST.LOCAL
User ID: NULL SID
Service Information:
Service Name: krbtgt/TEST.LOCAL
Service ID: NULL SID

There is no user as root in my DC and there is no functionality breakup. It
is getting correct user name. But, by default first kerberos ticket
requested by root. Whenever samba is restarted or communicating with my
system. Audit failure logs are dumped. Over the time (day) there are a lot of such kerberos requests through my DC.

I think it might be a regression issue from samba while fixing badlock.

Could anyone help regarding this issue?

Thanks

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Thanks for filing this ticket in Ubuntu.

Unfortunately your report is too broad to be considered a bug, and feels more like a support request. Not only that, but support for windows audit logs.

I suggest you try to get help within the community at askubuntu.com, or perhaps the samba mailing list at https://lists.samba.org/mailman/listinfo/samba

Changed in samba (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.