Windows XP users can't access SMB/CIFS shares on MAC OSX10.4.4 Xserve bug?

The Xserves are new for us. This problem involves two of the 10.4 xerserves.
1 serves as an Open Directory System Master(10.4.3). 2 Serves as a file share & backup (10.4.4).
Both are production machines and cannot easily be restarted.
There is no Windows network, Active Directory or Windows domain in our network.
We created a SMB and AFP share on the file server which is a member of the Open Directory. (It is bound and kerberized to server 1).
The users all have accounts in the OD system and all passwords are Open Directory. Our users can ssh into the various xserves (including the file share server 2) and authenticate against OD.
We made the shares available via smb under Protocols --> Windows File Settings. We turned the Windows Service on in Server Admin. I'ts a standalone server and all the authentication types are checked under access.
The MAC (powerbook) users can access the share fine. The Windows users can't. The Windows laptops can see the file share server (through search - not visable is Network Neighborhood) but when they try and connect they are presented by an authentication box that just keeps cycling over and over regardless of what the user types as user name & passwd.
I tried to access the smb share with my powerbook(10.4.4) and have the same issue. I'm presented with an authentication box but authentication fails.
The Windows File Service Log shows:
auth.c:checkntlmpassword(312)
checkntlmpassword: Authentication for user [csmith] -> [csmith] FAILED with error NTSTATUS_WRONGPASSWORD
[2006/02/24 21:52:03, 1] authods.c:opendirectory_authuser(212)
User "csmith" failed to authenticate with "dsAuthMethodStandard:dsAuthSMBNTKey" (-14090)
[2006/02/24 21:52:03, 1] authods.c:opendirectory_smb_pwd_checkntlmv1(427)
opendirectorysmb_pwd_checkntlmv1: [-14090]opendirectoryauthuser
[2006/02/24 21:52:03, 2] /SourceCache/samba/samba-92.15/samba/source/auth/auth.c:checkntlmpassword(312)
checkntlmpassword: Authentication for user [csmith] -> [csmith] FAILED with error NTSTATUS_WRONGPASSWORD
[2006/02/24 21:52:03, 1] authods.c:opendirectory_authuser(212)
User "csmith" failed to authenticate with "dsAuthMethodStandard:dsAuthSMBNTKey" (-14090)
[2006/02/24 21:52:03, 1] authods.c:opendirectory_smb_pwd_checkntlmv1(427)
opendirectorysmb_pwd_checkntlmv1: [-14090]opendirectoryauthuser
[2006/02/24 21:52:03, 2] /SourceCache/samba/samba-92.15/samba/source/auth/auth.c:checkntlmpassword(312)
checkntlmpassword: Authentication for user [csmith] -> [csmith] FAILED with error NTSTATUS_WRONGPASSWORD
[2006/02/24 21:52:03, 2] /SourceCache/samba/samba-92.15/samba/source/smbd/server.c:exit_server(595)
Closing connections
I've googled this error and it seems that there a lot of engineers out there with the same problem but no answers. Could this be a bug with Apple's SMB process? Is there something I've missed? (I've looked at the smb.conf and have even turned off deny clear text passwords - I've even tried granting guest access) Anyone have any ideas?

On the server itself, run the following in the Terminal:
(from a few different sources):
run ps -auxw | grep Password
to see if Password service is running
Also check the logs in /Library/Logs/PasswordService
Try: id username
and see if you get some info returned.
Ex: id jimguy
You should get some info about uid, gid, groups.
sudo killall -USR1 DirectoryService
Then try to login from a client machine.
Be sure to re-issue
sudo killall -USR1 DirectoryService
in order to stop the (far more) verbose logging.
Then check the logs in /Library/Logs/DirectoryService
In Open Directory, you might want to revert to standalone (this will destory the existing OD setup) and then re-promote to OD Master. You'll lose all OD users however when doing so. If you don't have many, this may be best.
You'll want to verify the hostname, and forward & reverse DNS lookups before re-promoting, and watch for any errors when promoting to OD master
See, when you say "The real clue is that I'm unable to access the shares from my Powerbook G4 with my Open Directory account. I can log in to the file share as the local admin though and that's why I'm thinking there is a bug in the samba/OD relationship. " - that's the real clue indeed.
The local admin account, the first admin account you setup on the server, is indeed local, and resides in NetInfo, not Open Directory.
So something is afoul in your OD.

Similar Messages

  • Mac not seeing SMB/CIFS shares that others computers can see

    I set up a test that fails. There are three computers
    1) A Mac running "Tiger"
    2) PC running Windows 2000
    3) A Linux server running Samba
    Both Win2K and Linux export some SMB/CIFS shares
    The Mac can "see" the Win2K shared files but when the Mac tries to connect to the Linux server the finder hangs and has has to be killed. Going to a terminal on the Mac and I type "smbclient -L <Linuxsevername> I see all the services on the linux machine. So I try "smbclient //rabbit/wsfiles/" (Where the names rabbit and wsfiles where cut and pasted from the smbclient -L output.) and I get an "Invalid network name" error. Yes, I have cnnectivity to "rabbit", ping, ssh, X11 and FTP work fine
    On the Win2K PC I can access the Linux shares
    The Linux server can access it's own shares using "smbclient"
    Linux Samba must be working because I can access the shares from Win2K. Mac must be working because it can access shares from the PC. So I can argue that nothing could be broken but clearly something is. I have many years experiance with UNIX but have avoided PCs and PC networking.
    Anyone have a list of things I can check?

    Hi C JAbertson, check the logs in /Applications/Utilities/console see if they provide any clue to why.You are using SMB://rabbit/wsfiles/ format in the go to window? Have you got SMB enabled in Directory Access?
    Cheers.

  • Saving so that windows user can have access?

    I have my project all ready and those with quick time...loads up perfectly. However those who have windows have a long wait or pile will not come up. Do you know how i can save my final cut express project so that window users can have access to it?

    thank you. one last question....the quick time movie file can not be seen when opening on a windows. do you know if i need a quick time pro so that i can convert it? or is there a way that i don't know about?

  • Other user can't access to OBIEE 11G installed on a server

    Hello,
    We have installed OBIEE 11G on a server ( windows sever 2008 r2) with admin account, and it works fine, But others users can't access to obiee 11g ( administration icons are white in their sessions) even they have admin rights.
    Can anyone tell me what should we do??
    Thank you.

    Hi,
    This is the exact format how my tnsnames.ora file looks. sorry, I can ping it in command prompt now. In my connection pool i tried first DSN =  ab.bc.xy.zx, did not work. Then I saw oracle's default repository and changed my DSN to your suggested format starting from "DESCRPTION" to rest. Still no luck Do you think, i should put the same TNS in my local machine??
    ab.bc.xy.zx =
    (DESCRIPTION =
        #(ADDRESS = (PROTOCOL = TCP)(HOST = 10.20.30.110)(PORT = 1521))
        #(ADDRESS = (PROTOCOL = TCP)(HOST = 10.20.30.120)(PORT = 1521))
        (ADDRESS = (PROTOCOL = TCP)(HOST = 10.20.30.130)(PORT = 1521))
        (LOAD_BALANCE = yes)
        (CONNECT_DATA =
          (SERVER = DEDICATED)
          (SID = cap2)
    thanks,
    BK.

  • Hi! Windows 7 users can´t open the pdfs and jpegs that I have included into sent e-mails. How shall I resolve the problem?

    Hi!
    Prolems started after uploading the Lion in March. Now at least Windows 7 users can´t open any pdfs or jpegs that I have included into sent e-mails. They can see that they are included but can´t open them. What can I do?

    It's a bug in Outlook. Each version of Outlook has its own unique bug that prevents it form displaying email that didn't come from another Outlook user. Apple has attempted to dumb-down Mail and make it more complex in order to work around these issues, but Microsoft keeps changing the bugs in each version of Outlook instead of making an Internet Email standard compliant email client.
    Are they able to right-click on the image and save it from the contextual menu?
    Otherwise, make sure Send windows friendly, attachments at end of message are checked and send plain text.
    Or, zip the attachments and send that way.
    There is also a program called Attachment Tamer that many people have found useful.

  • If I copy a CD (either music or audio) on my Windows based Pc can I access the copy using itunes?

    If i copy a Cd (either music or audio) on my Windows based PC can I access the copy using itunes.  I have a ipod Nano, 7th generation.

    You should use iTunes to "rip" (encode) the songs directly into your iTunes library from the CDs.  This article provides a good description of how that is done using iTunes.
    http://www.macworld.com/article/1156861/howto_rip_cds.html
    If you use some other program to encode the content on those CDs, you can add any audio files that are in a format that iTunes can play (such as MP3 and AAC) to your iTunes library.  "Windows Media" files are not playable by iTunes, but the Windows version of iTunes can convert them while importing (as long as the files do not use DRM).

  • Why the apple store is so expensive and why the apple users can't access for free after spending huge amount in apple phone ?

    Why the apple store is so expensive and why the apple users can't access for free after spending huge amount in apple phone ?

    The Apple store is correct. The warranty is not international, and Apple will not accept or return iPhones shipped from a different country.  You need to ship the phone to somebody in Hong Kong who can take it in to Apple for repair, or pay a third party repair shop in the Philippines to fix it.

  • Open Directory users can't access shares

    Greetings all.
    I apologize if this has been covered, but I couldn't find a search term that would locate the issue.
    I have a 10.5.8 Server running on a MDD dual 1Ghz G4. I have it set up as an OD Master and providing time services, DNS, file sharing, portable home directories and calendaring for a small workgroup of 7 computers. At least that's the idea when it's functional.
    It is behind a NAT and only serves the local network.
    Until I have the user's data all transferred from local directories to portable home directories, I need to make it so that the users can access the shares.
    In testing, when I try to access a share, I get an error message that the login failed because the username or password was invalid.
    However, when I go look at the Password Service log, the user was authenticated and in good standing.
    Any ideas?
    Thank you,
    John

    maybe some additional information or rephrasing might help.
    I have users and groups set up with ACLs on the shares that are set up with automount over NFS. The shares should also be available via appleshare, but not automount.
    The users are configured now with Portable Home Directories.
    The client computers are bound to the Open Directory Master on which the shares reside.
    The server runs network time services and the client computers use that for their time service.
    The server also runs DNS, and the client computers use that DNS.
    Users can log into their Portable Home Directories ok.
    Users can not log into shares via "connect to server" as it says that the username/password is invalid, even though the password service log says that the user was authenticated and in good standing.
    Users can see the NFS automount shares at /Network/Servers/Library (where it is supposed to be), but they cannot write, even though the ACL gives the user account permission to do so.
    For the permissions on the automount, I can't tell if the user is not being detected as the authenticated user, and is therefore being given "everyone" permissions, or if the ACL is not working on the mount and so the user is being given ""everyone" permissions.
    Anyone have any idea how I can find out?
    As to why a user can't log in via "connect to server" I'm clueless.
    Thank you,
    John

  • HT1145 I can't see my files on my USB shared drive.  It shows there is lots of space taken up, but I can't access the files via my Mac.

    I can't see my files on my USB shared drive.  It shows there is lots of space taken up, but I can't access the files via my Mac.  How do I see them?  I also can't see them on my iPad using FileBrowser.

    You don't have access to it to configure it via Time Machine? You lost me on that one, Time Machine is used for Backup.
    Here is a basic article on the first setup and what you should see:
    http://support.apple.com/kb/HT1178
    To configure Time Capsule you should be using "Airport Utility" 5.3 or higher that is located in the Utilities folder. You can tell if its version 5.3 because the icon will have blue lines instead of orange lines like the older versions. Since you are running Leopard 10.5.6 and you ran Software Update you are probably already running the latest 5.3 version.
    The light flashing amber means you haven't entered enough information so that it can get to the internet. Once you have that info entered the light will turn green.
    If your absolutely sure your CAT5 cables are good you can try a hard reset. I think you have to push the reset button on the back and hold it for 5 seconds or so until the amber light blinks rapidly, then when you release the button it does the reset then.
    http://support.apple.com/kb/HT1300?locale=en_US
    Hope this helps! If not I would probably call AppleCare support or see if you can exchange it.
    -Dan

  • Can you access time capsule from a mac over the internet

    Can you access time capsule from a mac over the internet?

    Yes. See this thread about how to access the disk attached to a Time Capsule.  Access to the Time Capsule itself can be done similarly.

  • I install windows 8 professorial, can u tell now how to run mac os there is no other option to start it.

    i install windows 8 professorial, can u tell now how to run mac os there is no other option to start it.

    Press and hold the option key when you power up your computer. Then select OSx to boot.

  • SMB/CIFS share of encrypted windows directory

    I have a windows 8.1 pro stand alone computer. It has one directory that is encrypted. This computer shares that directory and others with a linux computer. Just after the windows 8.1 computer reboots, linux is unable to access the encrypted directory, but
    it can access other unencrypted directories. Once I log on the windows computer as a user with access to the encrypted directory, the linux computer is suddenly able access the encrypted folder. The linux computer can continue to access the encrypted directory
    from linux after the user logs off the windows computer.
    To be able to access the encrypted directory, I only need to log on to the windows console, i don't need to start any programs. It's as if windows cannot access some kind of key until the a user with access to the encrypted folder logs on to the windows
    system from the console. I've tried many different linux command line options for opening the windows share and it doesn't seem to change the behavior. It is typically mounted with:
    mount
    -t cifs //192.168.1.2/efsdirectory ~/mnt --verbose -o rw,user=username,uid=1000,gid=1000
    The behavior is identical if a directory above the efs directory is mounted.
    I searched all of the windows event logs for errors from the failed access to the encrypted directory, but I don't see any.
    Thanks for your help.

    Hi,
    Thanks for your help.
    if all your systems are in Domain or not.
    The windows and linux computers are not on a windows domain, just the same workgroup that is named "workgroup".
    Also please help confirm if "encrypted" means encrypted by EFS (or Bitlocker).
    The directory that i'm trying to access is encrypted with EFS. Since this is a desktop computer, it does not use bitlocker
    What's the exact username here in your command? Is it the same account as the one you logged on Windows 8.1?
    the username in the unix mount command is the same one used to log onto the windows system. The linux username is different, but that's specified in the mount command with the UID and GID.
    The problem occurs after a full reboot, I have disabled the windows 8.1 fast reboot 'feature'.
    I'll check tonight, but is it possible that the "Encrypting file system service" is not starting when I mount the drive? Perhaps it only starts when I log on. I noticed that this service is set to 'automatic' on another (windows 7) computer.
    Here's a timeline of what happens:
    1) Log off of the windows computer. Reboot. (not fast boot)
    2)
    mount drive on linux computer
    3)  brouse directory structure on linux. Can open files that are not in encrypted directories. Cannot open files that are in encrypted directories.
    4) log onto windows machine
    5) brouse directory structure. Now I can open files that are in encrypted directories.
    6) log off windows machine
    7) brouse directory structure. I can still open files that are in encrypted directories.
    Looking at the windows logs, I can see 2 login entries exactly when I mount the drive:
    Special privileges
    assigned to new logon.
    Subject:
    Security ID:   
    HOSTNAME\USERNAME
    Account Name:   
    USERNAME
    Account Domain:   
    HOSTNAME
    Logon ID:   
    0x43C3B
    Privileges:   
    SeSecurityPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeTakeOwnershipPrivilege
    SeDebugPrivilege
    SeSystemEnvironmentPrivilege
    SeLoadDriverPrivilege
    SeImpersonatePrivilege
    An account was successfully
    logged on.
    Subject:
    Security ID:   
    NULL SID
    Account Name:   
    Account Domain:   
    Logon ID:   
    0x0
    Logon Type:   
    3
    Impersonation Level:   
    Impersonation
    New Logon:
    Security ID:   
    HOSTNAME\USERNAME
    Account Name:   
    USERNAME
    Account Domain:   
    HOSTNAME
    Logon ID:   
    0x43C3B
    Logon GUID:   
    {00000000-0000-0000-0000-000000000000}
    Process Information:
    Process ID:   
    0x0
    Process Name:   
    Network Information:
    Workstation Name:   
    Source Network Address:   
    192.168.1.7
    Source Port:   
    58432
    Detailed Authentication
    Information:
    Logon Process:   
    NtLmSsp
    Authentication Package:   
    NTLM
    Transited Services:   
    Package Name (NTLM only):   
    NTLM V2
    Key Length:   
    0
    Thanks again.

  • SSRS 2005 why some users can't access report server.

    There is one user who can't access report server by clicking a link to a report. A window will pop up asking for login. Even he enters login, the window will keep coming back. I have set the user for that report and assigned the 'Browser' role to the user.
    Other users don't have this problem. E.g. for another user I also set him up for the report and assigned 'Browser' role but he can access the same report no problem.

    Hi thotwielder,
    As per my understanding, I think this issue can be caused by the following two reasons:
    The report server can be blocked by Firewall. If Windows Firewall is turned on, the port that the report server is configured to use is most likely closed. Indications that a port might be closed are the appearance of a blank Web page after requesting a
    report, or a blank page when you attempt to open Report Manager from a remote client computer. In this scenario, we can try to open port 80 in Windows Firewall on both report server and client computers.
    The report server can be blocked by browser. We should ass the report server URL to trusted site in the browser.
    We can also grant the user access to site-wide operations with system-level row in report manager to check the issue again.
    Please double-check we have been grand the user the browser role on the report. We can navigate to Security property of the report to check the issue.
    Reference:
    Configure a Firewall for Report Server Access
    Configure a Native Mode Report Server for Local Administration (SSRS)
    Grant User Access to a Report Server (Report Manager)
    Thanks,
    Katherine Xiong
    Katherine Xiong
    TechNet Community Support

  • Server 4: Local user can't access restricted website

    Hello.
    One of our locally hosted websites (LAN-only) is set up to require restricted access via OS X Server's "Access Group" setting. It contains a number of OD-based users and a single local user (the machine's admin user). All OD-based users can access the website (after supplying their credentials), but the single local user can't (keeps rejecting the credentials). This worked fine for this user under 10.9 Server—the issue has only been introduced after the 10.10 upgrade.
    The only thing I'm able to find in the logs is:
    [Thu Oct 23 13:03:23.125136 2014] [apple_digest:error] [pid 1971] [client XXX.XXX.XXX.XXX:XXXXX] Access to / failed, reason: user 'XXX' does not meet 'require'ments for user to be allowed access
    [Thu Oct 23 13:03:23.125276 2014] [authz_core:error] [pid 1971] [client XXX.XXX.XXX.XXX:XXXXX] AH01631: user XXX: authorization failure for "/":
    I've confirmed the correct credentials being used (as it's the same user used to physically access the server itself).
    Anyone have any ideas what might be wrong?
    Thanks,
    Kristin.

    I opted to use ".com.na" in which case the Internal Domain Name and Internet Website
    now has the same name.
    This ends up with a split-DNS stup for internal and external resolution which requires extra administration tasks and attention from the administrators.
    When attempting to open the extarnal website eg. "www.company.com.na" from a client PC within the internal "company.com.na" Domain, I keep getting error "403 - Forbidden: Access is denied. You do not have permission to view
    this directory or page using the credentials that you supplied."
    I should also mention, the website is hosted by an ISP and not locally.
    I added a "www" Host record in the Forward Lookup Zone, I have added the url and ip address to the Hosts file on a client pc (Windows 7) and even tried setting up Split-Brains DNS. Nothing seems to work.
    Running a Tracert takes me to the correct public ip address of the website, but I keep getting this 403 error.
    This means that you are able to reach the Website but it is responding with the access denied error message. That should be checked on the middleware level so if this is IIS running then I would recommend asking them in IIS forum: http://forums.iis.net/
    If this is a Website that is completely managed by your ISP then I would recommend checking with them.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Multiple Users Can't Access Time Capsule Data

    My wife and I have two separate Apple MacBooks that share a Time Capsule. We have different account names on these respective computers. I initially set up my Time Capsule and created folders that I can access from Finder.app when I connect over our wireless network. In Airport Utility.app, under the "Disks" tab, I set up the shared disks "with device password", so that she and I can mutually access all the data on the Time Capsule. However, when I try to access it from her computer, I click on the Time Capsule in Finder.app and get this dumb Sharepoint icon--a total dead end. I created another account on her computer with the same name as the account on my own computer, and from that account, I'm able to access all of the data on the Time Capsule. This therefore seems to be a permissions issue, but I've checked all of the files and folders on the Time Capsule and ensured that they all have "everyone read & write" access, so there should be no restrictions on access to this data.
    Why are the volumes on my Time Capsule sensitive to the user accessing them? How do I set up data repositories on the Time Capsule that can be accessible to all users on my network? I'm out of ideas.

    Are both computers actually running Mavericks??
    This is very typical Yosemite problem.
    For some reason which I don't yet understand Yosemite is horrible at handling network drives.
    dumb Sharepoint icon
    Sharepoint is a dlink app?? If you have ever had some app loaded that uses a different product to apple then it can mess your access.
    WD share stuff seems to be the worst and causes no end of problems.
    What you are seeing btw is the TC is not a NAS.. you are trying to use it as one.. but it isn't.

Maybe you are looking for

  • How to Combine Packages into one & run them as one Main Package ?

    Greetings - I am trying to combine two packages into one if possible, this way I can execute one Main_Package. In other words, I have this Package that FTP files called Package_1 and another package that refreshes data called Package_2. I want to be

  • Dynamic Menus for Navigation

    i have a question about Dynamic Menus for Navigation... i am a new in jsf/adf... and i want a suggestion about my new application i am trying to do: my boss has give me all the items that the menu will have.... and this menu will be the same for all

  • Glonass support in Lumia 800

    Does anyone know what is the situation with the Glonass support in Lumia 800? According ot Wikipedia the support is there. However, it is not listed in the speca in Nokia pages. Apparently the Snapdragon processor does support Glonass and since Nokia

  • FaceTime doesn't work after the latest iphone update. How do i fix it?

    When I enter my apple id and password it says its incorrect even though I know it is correct and even works to sign into my itunes

  • Select from  Berkeley DB through java code not working

    Hi, I have developed an application using Jdeveloper 11g where in the Database Navigator I have created a new connection say Conn1 ,selected Generic Jdbc as the connection type and org.sqlite.Jdbc as the Driver Class.The JDBC URL is for example jdbc: