You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Samba结合MIT Kerberos与OpenLDAP认证失败,报错NT_STATUS_NO_IMPERSONATION_TOKEN

Samba结合MIT Kerberos与OpenLDAP认证失败,报错NT_STATUS_NO_IMPERSONATION_TOKEN

我之前在Ubuntu 20.04上搭建的Samba+MIT Kerberos+OpenLDAP环境是完全正常工作的,甚至不确定Ubuntu 22.04初期是否也能正常运行,但大概一两年前突然失效了——毕竟带娃太忙,直到最近才有时间折腾。现在访问Samba共享时会触发以下错误:

session setup failed: NT_STATUS_NO_IMPERSONATION_TOKEN

历史正常配置

当时参考Ubuntu官方文档配置的smb.conf片段如下:

[global]
# Change this to the workgroup/NT-domain name your Samba server will part of
workgroup = EXAMPLE

# The 'auto' setting here configures Samba based on the value of the
# 'security' setting.
server role = auto

# Configure Samba to call out to Kerberos for all authentication. Because we're
# not also configuring a passdb, Samba will look to the system accounts for all
# authorization info (e.g. UIDs, groups, etc.). This setup was taken from
# Ubuntu Server Guide.
security = ads
realm = EXAMPLE.COM
kerberos method = dedicated keytab
dedicated keytab file = /etc/samba/smbd.keytab

idmap config * : backend = tdb
idmap config * : range = 20001-30000
idmap config {{ domain | upper }} : backend = rfc2307
idmap config {{ domain | upper }} : range = 10000-20000

之前正常访问的流程是先获取Kerberos票据,再通过smbclient访问共享:

$ kinit
Password for coolcat@EXAMPLE.COM:

$ /usr/bin/smbclient //neatbox.example.com/share --use-kerberos=required --no-pass --directory somepath --command ls
.                                   D        0  Fri May  6 07:10:08 2022
..                                  D        0  Fri May  6 07:10:08 2022
stuff                               D        0  Fri May  6 07:10:08 2022
otherstuff                          D        0  Fri May  6 07:10:13 2022
957134040 blocks of size 1024. 620537476 blocks available

当前故障与排查

现在执行相同的smbclient命令会直接报错:

$ /usr/bin/smbclient //neatbox.example.com/share --use-kerberos=required --no-pass --directory somepath --command ls
session setup failed: NT_STATUS_NO_IMPERSONATION_TOKEN

我查了好几个晚上的资料,怀疑是Samba 4.14版本左右的变更导致的,似乎和Kerberos票据中的PAC(特权属性证书)有关,但我并不是Kerberos专家,平时都是靠试错解决问题的。

核心疑问

想请教一下:Samba现在还支持MIT Kerberos+OpenLDAP这种认证组合吗?还是说这种方式已经被弃用或不再支持了?

附加日志信息

smbd服务启动后,日志里总会出现这条打印服务相关的错误:

Dec 24 20:53:29 eddings systemd[1]: Starting Samba SMB Daemon...
Dec 24 20:53:29 eddings smbd[782101]: [2023/12/24 20:53:29.593145,  0] ../../source3/smbd/server.c:1734(main)
Dec 24 20:53:29 eddings smbd[782101]:   smbd version 4.15.13-Ubuntu started.
Dec 24 20:53:29 eddings smbd[782101]:   Copyright Andrew Tridgell and the Samba Team 1992-2021
Dec 24 20:53:29 eddings systemd[1]: Started Samba SMB Daemon.
Dec 24 20:53:30 eddings smbd[782101]: [2023/12/24 20:53:30.244701,  0] ../../source3/printing/nt_printing.c:233(nt_printing_init)
Dec 24 20:53:30 eddings smbd[782101]:   nt_printing_init: error checking published printers: WERR_ACCESS_DENIED

偶尔还会出现一堆winbindd未运行的错误,但smbclient的认证失败似乎不会触发这些错误,所以我觉得大概率和当前问题无关:

Dec 24 11:06:27 eddings smbd[766136]: [2023/12/24 11:06:27.972690,  0] ../../source3/auth/auth_winbind.c:120(check_winbind_security)
Dec 24 11:06:27 eddings smbd[766136]:   check_winbind_security: winbindd not running - but required as domain member: NT_STATUS_NO_LOGON_SERVERS

备注:内容来源于stack exchange,提问作者Karl M. Davis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 13:35:30