samba does not provide netlogon infos

Bug #1319320 reported by Bobo The Monkey
32
This bug affects 6 people
Affects Status Importance Assigned to Milestone
samba
Unknown
Unknown
realmd (Ubuntu)
Invalid
Undecided
Unassigned
Trusty
New
Undecided
Unassigned
samba (Ubuntu)
Fix Released
Undecided
Unassigned
Trusty
Fix Released
Undecided
Unassigned
sssd (Ubuntu)
Invalid
Undecided
Unassigned
Trusty
Invalid
Undecided
Unassigned

Bug Description

When trying to join a domain using realmd, this is displayed:

sysoperator@mem4:~$ realm join --verbose test2dc.mdom.com
 * Resolving: _ldap._tcp.test2dc.mdom.com
 * Performing LDAP DSE lookup on: 192.168.15.23
 ! Received invalid or unsupported Netlogon data from server
realm: Cannot join this realm

This problem is well known and it has been fixed in Samba 4.1.7. Unfortunately, the samba version provided by apt is 4.1.6

This problem also surface when using SSSD, here's an extract of SSSD log file:

(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_get_generic_ext_step] (0x0400): calling ldap_search_ext with [(&(DnsDomain=test2dc.mdom.com)(NtVer=\14\00\00\00))][].
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_get_generic_ext_step] (0x1000): Requesting attrs: [netlogon]
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_get_generic_ext_step] (0x2000): ldap_search_ext called, msgid = 6
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_process_result] (0x2000): Trace: sh[0x1b60be0], connected[1], ops[0x1b6db50], ldap[0x1b61680]
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_process_result] (0x2000): Trace: ldap_result found nothing!
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_process_result] (0x2000): Trace: sh[0x1b60be0], connected[1], ops[0x1b6db50], ldap[0x1b61680]
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_process_message] (0x4000): Message type: [LDAP_RES_SEARCH_RESULT]
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [sdap_get_generic_ext_done] (0x0400): Search result: Success(0), no errmsg set
(Tue May 13 14:12:47 2014) [sssd[be[test2dc.mdom.com]]] [ad_master_domain_netlogon_done] (0x0080): No netlogon data available. Flat name might not be usable

Changed in samba (Ubuntu):
status: New → Confirmed
Revision history for this message
Brian Murray (brian-murray) wrote :

Do you know of an associated upstream (one from the samba bug tracker) bug? Or perhaps what commit to 4.1.7 fixed this? Thanks in advance.

tags: added: trusty
Revision history for this message
Bobo The Monkey (99b8b443) wrote :

Hello Brian,

here is a discussion about realmd problem:

http://comments.gmane.org/gmane.network.samba.internals/76719

and here is the samba-bugzilla with the alleged fixed in 4.1.7

https://bugzilla.samba.org/show_bug.cgi?id=10524

Revision history for this message
Timo Aaltonen (tjaalton) wrote :

ten patches.. samba should really gain a MRE to allow pushing point-releases as SRU

https://wiki.ubuntu.com/StableReleaseUpdates/MicroReleaseExceptions

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in realmd (Ubuntu):
status: New → Confirmed
Changed in sssd (Ubuntu):
status: New → Confirmed
Revision history for this message
przent (przent) wrote :

This bug prevents users to use Ubuntu in corporate networks. Should be definitely taken care off soon as this is a LTS version. Even more when the fix is that simple.

Revision history for this message
Timo Aaltonen (tjaalton) wrote :

not a bug in sssd nor realmd, closing these

Changed in sssd (Ubuntu):
status: Confirmed → Invalid
Changed in realmd (Ubuntu):
status: Confirmed → Invalid
Revision history for this message
Ian McMichael (ian-sigma-uk) wrote :

It appears this was fixed with the patch https://attachments.samba.org/attachment.cgi?id=9882 in Samba bug 10524 (https://bugzilla.samba.org/show_bug.cgi?id=10524) against their 4.1 code base. Is there any chance in getting this applied to the 14.04 LTS Samba release or the Utopic release back-ported?

Revision history for this message
Ben Vassie (vassie) wrote :

Can 4.1.7 be backported to 14.04?

Revision history for this message
Robie Basak (racb) wrote :

This is presumed fixed in Wily because it has 4.1.7, so I've marked it Fix Released and created a task to track status in Trusty.

Changed in samba (Ubuntu):
status: Confirmed → Fix Released
Changed in samba (Ubuntu Trusty):
status: New → Confirmed
Revision history for this message
Robie Basak (racb) wrote :

If someone can prepare a backport, please follow the steps at https://wiki.ubuntu.com StableReleaseUpdates#Procedure to have Trusty updated.

All the steps documented there need to be followed. In particular, I'm concerned that we:

1) Explain the bug well enough so the SRU team (who are probably not familiar with this package) can understand the real user impact in terms of use case so they can make a decision as to whether backporting the fix to stable releases justifies the regression risk to existing, unaffected users.

2) Make sure that the fixing this in a stable Ubuntu release does not regress existing users of the module not affected by this bug (eg. other architectures or ways of consuming this module).

3) Have a test case that can be followed by someone not familiar with the package for SRU verification purposes.

Revision history for this message
Rolf Leggewie (r0lf) wrote :

Trusty was updated to 4.3.8 at the beginning fo this month. Closing the trusty task for samba.

description: updated
Changed in samba (Ubuntu Trusty):
status: Confirmed → Fix Released
Revision history for this message
Timo Aaltonen (tjaalton) wrote :

closing the sssd task

Changed in sssd (Ubuntu Trusty):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.