升级至MacOS Sonoma 14.3后Samba共享身份验证失败问题
Samba 4.15.13-Ubuntu 与 macOS Sonoma 14.3 身份验证异常问题
问题现象
服务器为Samba 4.15.13-Ubuntu,此前各版本Mac及Windows客户端均可正常访问共享资源,升级至macOS Sonoma 14.3后出现以下身份验证异常:
- 长时间未修改密码的用户可正常登录;
- 修改密码后,新密码无法完成登录,改回旧密码则可正常访问(新旧密码长度一致且无特殊字符);
- 登录时,有时输入常规大小写用户名可行,有时需输入大写用户名才能成功。
相关日志
[2024/02/08 12:36:12.185684, 3] ../../libcli/auth/ntlm_check.c:492(ntlm_password_check) ntlm_password_check: Lanman passwords NOT PERMITTED for user testuser [2024/02/08 12:36:12.185714, 3] ../../libcli/auth/ntlm_check.c:637(ntlm_password_check) ntlm_password_check: LM password, NT MD4 password in LM field and LMv2 failed for user testuser [2024/02/08 12:36:12.185975, 2] ../../source3/auth/auth.c:345(auth_check_ntlm_password) check_ntlm_password: Authentication for user [testuser] -> [testuser] FAILED with error NT_STATUS_WRONG_PASSWORD, authoritative=1 [2024/02/08 12:36:12.186017, 2] ../../auth/auth_log.c:647(log_authentication_event_human_readable) Auth: [SMB2,(null)] user [SMB-SERVER][testuser] at [Thu, 08 Feb 2024 12:36:12.186007 CET] with [NTLMv2] status [NT_STATUS_WRONG_PASSWORD] workstation [VPN-MAN-40-99] remote host [ipv4:192.168.40.99:50378] mapped to [SMB-SERVER][testuser]. local host [ipv4:192.168.57.192:445] {"timestamp": "2024-02-08T12:36:12.186062+0100", "type": "Authentication", "Authentication": {"version": {"major": 1, "minor": 2}, "eventId": 4625, "logonId": "0", "logonType": 3, "status": "NT_STATUS_WRONG_PASSWORD", "localAddress": "ipv4:192.168.57.192:445", "remoteAddress": "ipv4:192.168.40.99:50378", "serviceDescription": "SMB2", "authDescription": null, "clientDomain": "SMB-SERVER", "clientAccount": "testuser", "workstation": "VPN-MAN-40-99", "becameAccount": null, "becameDomain": null, "becameSid": null, "mappedAccount": "testuser", "mappedDomain": "SMB-SERVER", "netlogonComputer": null, "netlogonTrustAccount": null, "netlogonNegotiateFlags": "0x00000000", "netlogonSecureChannelType": 0, "netlogonTrustAccountSid": null, "passwordType": "NTLMv2", "duration": 16017}} [2024/02/08 12:36:12.186098, 3] ../../auth/gensec/spnego.c:1443(gensec_spnego_server_negTokenTarg_step) gensec_spnego_server_negTokenTarg_step: SPNEGO(ntlmssp) login failed: NT_STATUS_WRONG_PASSWORD [2024/02/08 12:36:12.186114, 3] ../../source3/smbd/smb2_server.c:3954(smbd_smb2_request_error_ex) smbd_smb2_request_error_ex: smbd_smb2_request_error_ex: idx[1] status[NT_STATUS_LOGON_FAILURE] || at ../../source3/smbd/smb2_sesssetup.c:147
smb.conf 配置
[global] netbios name = smb-server workgroup = MYWORKGROUP server string = Samba Server log file = /var/log/samba/log.%m log level = 3 max log size = 1000 invalid users = nobody root printable = no security = USER server min protocol = SMB2 server max protocol = SMB3 client min protocol = SMB2 ntlm auth = yes passdb backend = smbpasswd smb encrypt = auto obey pam restrictions = yes smb passwd file = /etc/samba/smbpasswd unix password sync = yes pam password change = yes passwd program = /usr/bin/passwd %u passwd chat = *New*password* %n\n *Retype*new*password* %n\n *passwd:*all*authentication*tokens*updated*success fully* passwd chat debug = No
已完成的测试
testparm输出:
sudo testparm Load smb config files from /etc/samba/smb.conf Loaded services file OK. Weak crypto is allowed
- 重启Samba服务器或服务,问题未解决;
- 执行
pdbedit -L -w -u testuser与cat /etc/samba/smbpasswd |grep testuser,两者哈希值一致; - 仅macOS Sonoma 14.3客户端存在该问题,其他客户端均可正常登录。
寻求解决线索。
内容的提问来源于stack exchange,提问作者user4633410
相关产品推荐
相关产品推荐

