As far as I can tell, prior to accepting a connection:
dns_send_req: Failed to resolve _ldap._tcp.dc._
msdcs.AVERAGEURL.COM
(Success)
ads_dns_lookup_srv: Failed to send DNS query (NT_STATUS_UNSUCCESSFUL)
[ ... ]
Could not look up dc's for domain
AVERAGEURL.COM
ads_connect: leaving with: No logon servers
Those records (*._msdcs.) don't exist all right...
And while the socket is connected:
Starting GENSEC mechanism spnego
Starting GENSEC submechanism gse_krb5
name_to_fqdn: lookup for ELASTIC failed. /* Reverse DNS and forward DNS
IS resolving properly here... one thing to note: this is an IPv6 only
host */
Security token: (NULL)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
obtaining PAC via GSSAPI gss_get_name_attribute failed: The operation or
option is not available or unsupported: No such file or directory
Unable to find PAC in ticket from
ky...@AVERAGEURL.COM, failing to allow
access
Checking the process with strace isn't really useful either, unfortunately:
open("/etc/krb5.keytab", O_RDONLY) = 33
[ ... ]
open("/dev/urandom", O_RDONLY) = 33
open("/dev/urandom", O_RDONLY) = 33
open("/dev/urandom", O_RDONLY) = 33
open("/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 33
open("/usr/share/locale/en_US.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1
ENOENT (No such file or directory)
[ ... ]
open("/usr/share/locale/en_US/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = 33
[ ... ]
open("/var/tmp/cifs_0", O_RDWR) = 33
open("/usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so",
O_RDONLY|O_CLOEXEC) = 35
open("/dev/urandom", O_RDONLY) = 34
open("/dev/urandom", O_RDONLY) = 34
open("/dev/urandom", O_RDONLY) = 34
obtaining PAC via GSSAPI gss_get_name_attribute failed: The operation or
option is not available or unsupported: No such file or directory
open("/etc/krb5.conf", O_RDONLY) = 33
open("/dev/urandom", O_RDONLY) = 33
open("/etc/krb5.conf", O_RDONLY) = 33
open("/dev/urandom", O_RDONLY) = 33
--- SIGTERM {si_signo=SIGTERM, si_code=SI_USER, si_pid=958, si_uid=0} ---
+++ killed by SIGTERM +++
Full logs:
http://averageurl.com/samba/samba-log.gz
http://averageurl.com/samba/samba-strace-log.gz
I've already changed the keys out, so I'm not too worried about what key
data is actually in those logs.
--Kyle