Samba结合MIT Kerberos与OpenLDAP认证失败,报错NT_STATUS_NO_IMPERSONATION_TOKEN
Samba结合MIT Kerberos与OpenLDAP认证失败,报错NT_STATUS_NO_IMPERSONATION_TOKEN
我之前在Ubuntu 20.04上搭建的Samba+MIT Kerberos+OpenLDAP环境是完全正常工作的,甚至不确定Ubuntu 22.04初期是否也能正常运行,但大概一两年前突然失效了——毕竟带娃太忙,直到最近才有时间折腾。现在访问Samba共享时会触发以下错误:
session setup failed: NT_STATUS_NO_IMPERSONATION_TOKEN
历史正常配置
当时参考Ubuntu官方文档配置的smb.conf片段如下:
[global] # Change this to the workgroup/NT-domain name your Samba server will part of workgroup = EXAMPLE # The 'auto' setting here configures Samba based on the value of the # 'security' setting. server role = auto # Configure Samba to call out to Kerberos for all authentication. Because we're # not also configuring a passdb, Samba will look to the system accounts for all # authorization info (e.g. UIDs, groups, etc.). This setup was taken from # Ubuntu Server Guide. security = ads realm = EXAMPLE.COM kerberos method = dedicated keytab dedicated keytab file = /etc/samba/smbd.keytab idmap config * : backend = tdb idmap config * : range = 20001-30000 idmap config {{ domain | upper }} : backend = rfc2307 idmap config {{ domain | upper }} : range = 10000-20000
之前正常访问的流程是先获取Kerberos票据,再通过smbclient访问共享:
$ kinit Password for coolcat@EXAMPLE.COM: $ /usr/bin/smbclient //neatbox.example.com/share --use-kerberos=required --no-pass --directory somepath --command ls . D 0 Fri May 6 07:10:08 2022 .. D 0 Fri May 6 07:10:08 2022 stuff D 0 Fri May 6 07:10:08 2022 otherstuff D 0 Fri May 6 07:10:13 2022 957134040 blocks of size 1024. 620537476 blocks available
当前故障与排查
现在执行相同的smbclient命令会直接报错:
$ /usr/bin/smbclient //neatbox.example.com/share --use-kerberos=required --no-pass --directory somepath --command ls session setup failed: NT_STATUS_NO_IMPERSONATION_TOKEN
我查了好几个晚上的资料,怀疑是Samba 4.14版本左右的变更导致的,似乎和Kerberos票据中的PAC(特权属性证书)有关,但我并不是Kerberos专家,平时都是靠试错解决问题的。
核心疑问
想请教一下:Samba现在还支持MIT Kerberos+OpenLDAP这种认证组合吗?还是说这种方式已经被弃用或不再支持了?
附加日志信息
smbd服务启动后,日志里总会出现这条打印服务相关的错误:
Dec 24 20:53:29 eddings systemd[1]: Starting Samba SMB Daemon... Dec 24 20:53:29 eddings smbd[782101]: [2023/12/24 20:53:29.593145, 0] ../../source3/smbd/server.c:1734(main) Dec 24 20:53:29 eddings smbd[782101]: smbd version 4.15.13-Ubuntu started. Dec 24 20:53:29 eddings smbd[782101]: Copyright Andrew Tridgell and the Samba Team 1992-2021 Dec 24 20:53:29 eddings systemd[1]: Started Samba SMB Daemon. Dec 24 20:53:30 eddings smbd[782101]: [2023/12/24 20:53:30.244701, 0] ../../source3/printing/nt_printing.c:233(nt_printing_init) Dec 24 20:53:30 eddings smbd[782101]: nt_printing_init: error checking published printers: WERR_ACCESS_DENIED
偶尔还会出现一堆winbindd未运行的错误,但smbclient的认证失败似乎不会触发这些错误,所以我觉得大概率和当前问题无关:
Dec 24 11:06:27 eddings smbd[766136]: [2023/12/24 11:06:27.972690, 0] ../../source3/auth/auth_winbind.c:120(check_winbind_security) Dec 24 11:06:27 eddings smbd[766136]: check_winbind_security: winbindd not running - but required as domain member: NT_STATUS_NO_LOGON_SERVERS
备注:内容来源于stack exchange,提问作者Karl M. Davis
相关产品推荐
相关产品推荐

