INFO: Current debug levels: all: 10 tdb: 10 printdrivers: 10 lanman: 10 smb: 10 rpc_parse: 10 rpc_srv: 10 rpc_cli: 10 passdb: 10 sam: 10 auth: 10 winbind: 10 vfs: 10 idmap: 10 quota: 10 acls: 10 locking: 10 msdfs: 10 dmapi: 10 registry: 10 scavenger: 10 dns: 10 ldb: 10 tevent: 10 auth_audit: 10 auth_json_audit: 10 kerberos: 10 drs_repl: 10 smb2: 10 smb2_credits: 10 dsdb_audit: 10 dsdb_json_audit: 10 dsdb_password_audit: 10 dsdb_password_json_audit: 10 dsdb_transaction_audit: 10 dsdb_transaction_json_audit: 10 dsdb_group_audit: 10 dsdb_group_json_audit: 10 ldapsrv: 10 lp_load_ex: refreshing parameters INFO: Current debug levels: all: 10 tdb: 10 printdrivers: 10 lanman: 10 smb: 10 rpc_parse: 10 rpc_srv: 10 rpc_cli: 10 passdb: 10 sam: 10 auth: 10 winbind: 10 vfs: 10 idmap: 10 quota: 10 acls: 10 locking: 10 msdfs: 10 dmapi: 10 registry: 10 scavenger: 10 dns: 10 ldb: 10 tevent: 10 auth_audit: 10 auth_json_audit: 10 kerberos: 10 drs_repl: 10 smb2: 10 smb2_credits: 10 dsdb_audit: 10 dsdb_json_audit: 10 dsdb_password_audit: 10 dsdb_password_json_audit: 10 dsdb_transaction_audit: 10 dsdb_transaction_json_audit: 10 dsdb_group_audit: 10 dsdb_group_json_audit: 10 ldapsrv: 10 Processing section "[global]" doing parameter abort shutdown script = doing parameter acl claims evaluation = AD DC only doing parameter ad dc functional level = 2008_R2 doing parameter add group script = doing parameter additional dns hostnames = doing parameter add machine script = doing parameter addport command = doing parameter addprinter command = doing parameter add share command = doing parameter add user script = doing parameter add user to group script = doing parameter afs token lifetime = 604800 doing parameter afs username map = doing parameter aio max threads = 100 doing parameter algorithmic rid base = 1000 doing parameter allow dcerpc auth level connect = No doing parameter allow dns updates = secure only doing parameter allow insecure wide links = No doing parameter allow nt4 crypto = No lpcfg_do_global_parameter: WARNING: The "allow nt4 crypto" option is deprecated doing parameter allow trusted domains = Yes doing parameter allow unsafe cluster upgrade = No doing parameter apply group policies = Yes doing parameter async dns timeout = 10 doing parameter async smb echo handler = No doing parameter auth event notification = No doing parameter auto services = doing parameter binddns dir = /var/lib/samba/bind-dns doing parameter bind interfaces only = Yes doing parameter browse list = Yes doing parameter cache directory = /var/cache/samba doing parameter change notify = Yes doing parameter change share command = doing parameter check password script = doing parameter client ipc max protocol = default doing parameter client ipc min protocol = default doing parameter client ipc signing = default doing parameter client lanman auth = No lpcfg_do_global_parameter: WARNING: The "client lanman auth" option is deprecated doing parameter client ldap sasl wrapping = seal doing parameter client max protocol = default doing parameter client min protocol = SMB2_02 doing parameter client netlogon ping protocol = cldap doing parameter client NTLMv2 auth = Yes lpcfg_do_global_parameter: WARNING: The "client NTLMv2 auth" option is deprecated doing parameter client plaintext auth = No lpcfg_do_global_parameter: WARNING: The "client plaintext auth" option is deprecated doing parameter client protection = default doing parameter client schannel = Yes lpcfg_do_global_parameter: WARNING: The "client schannel" option is deprecated doing parameter client signing = default doing parameter client smb encrypt = default doing parameter client smb3 encryption algorithms = AES-128-GCM, AES-128-CCM, AES-256-GCM, AES-256-CCM doing parameter client smb3 signing algorithms = AES-128-GMAC, AES-128-CMAC, HMAC-SHA256 doing parameter client use kerberos = desired doing parameter client use krb5 netlogon = default doing parameter client use spnego = Yes lpcfg_do_global_parameter: WARNING: The "client use spnego" option is deprecated doing parameter cluster addresses = doing parameter clustering = No doing parameter config backend = file doing parameter config file = doing parameter create krb5 conf = Yes doing parameter ctdbd socket = doing parameter ctdb locktime warn threshold = 0 doing parameter ctdb timeout = 0 doing parameter cups connection timeout = 30 doing parameter cups encrypt = No doing parameter cups server = doing parameter dcerpc endpoint servers = epmapper, wkssvc, samr, netlogon, lsarpc, drsuapi, dssetup, unixinfo, browser, eventlog6, backupkey, dnsserver doing parameter deadtime = 10080 doing parameter debug class = No doing parameter debug encryption = No doing parameter debug hires timestamp = Yes doing parameter debug pid = No doing parameter debug prefix timestamp = No doing parameter debug syslog format = No doing parameter winbind debug traceid = Yes doing parameter debug uid = No doing parameter dedicated keytab file = doing parameter default service = doing parameter defer sharing violations = Yes doing parameter delete group script = doing parameter deleteprinter command = doing parameter delete share command = doing parameter delete user from group script = doing parameter delete user script = doing parameter dgram port = 138 doing parameter disable netbios = No doing parameter disable spoolss = No doing parameter dns hostname = debian-client.example.net doing parameter dns forwarder = doing parameter dns port = 53 doing parameter dns proxy = Yes doing parameter dns update command = /usr/sbin/samba_dnsupdate doing parameter dns zone scavenging = No doing parameter dns zone transfer clients allow = doing parameter dns zone transfer clients deny = doing parameter domain logons = No lpcfg_do_global_parameter: WARNING: The "domain logons" option is deprecated doing parameter domain master = Auto doing parameter dos charset = CP850 doing parameter dsdb event notification = No doing parameter dsdb group change notification = No doing parameter dsdb password event notification = No doing parameter enable asu support = No doing parameter enable core files = Yes doing parameter enable privileges = Yes lpcfg_do_global_parameter: WARNING: The "enable privileges" option is deprecated doing parameter encrypt passwords = Yes lpcfg_do_global_parameter: WARNING: The "encrypt passwords" option is deprecated doing parameter enhanced browsing = Yes doing parameter enumports command = doing parameter eventlog list = doing parameter get quota command = doing parameter getwd cache = Yes doing parameter gpo update command = /usr/sbin/samba-gpupdate doing parameter guest account = nobody doing parameter himmelblaud hello enabled = No doing parameter himmelblaud hsm pin path = /var/lib/himmelblaud/hsm-pin doing parameter himmelblaud sfa fallback = No doing parameter host msdfs = Yes doing parameter hostname lookups = No doing parameter idmap backend = tdb lpcfg_do_global_parameter: WARNING: The "idmap backend" option is deprecated doing parameter idmap cache time = 604800 doing parameter idmap gid = lpcfg_do_global_parameter: WARNING: The "idmap gid" option is deprecated doing parameter idmap negative cache time = 120 doing parameter idmap uid = lpcfg_do_global_parameter: WARNING: The "idmap uid" option is deprecated doing parameter include system krb5 conf = Yes doing parameter init logon delay = 100 doing parameter init logon delayed hosts = doing parameter interfaces = ens18 127.0.0.1 doing parameter iprint server = doing parameter kdc default domain supported enctypes = 0 doing parameter kdc enable fast = Yes doing parameter kdc force enable rc4 weak session keys = No doing parameter kdc supported enctypes = 0 doing parameter keepalive = 300 doing parameter kerberos encryption types = all doing parameter kerberos method = default doing parameter kernel change notify = Yes doing parameter kpasswd port = 464 doing parameter krb5 port = 88 doing parameter lanman auth = No lpcfg_do_global_parameter: WARNING: The "lanman auth" option is deprecated doing parameter large readwrite = Yes doing parameter ldap admin dn = doing parameter ldap connection timeout = 2 doing parameter ldap debug level = 0 doing parameter ldap debug threshold = 10 doing parameter ldap delete dn = No doing parameter ldap deref = auto doing parameter ldap follow referral = Auto doing parameter ldap group suffix = doing parameter ldap idmap suffix = doing parameter ldap machine suffix = doing parameter ldap max anonymous request size = 256000 doing parameter ldap max authenticated request size = 16777216 doing parameter ldap max search request size = 256000 doing parameter ldap page size = 1000 doing parameter ldap passwd sync = no doing parameter ldap replication sleep = 1000 doing parameter ldap server require strong auth = Yes doing parameter ldap ssl = start tls doing parameter ldap suffix = doing parameter ldap timeout = 15 doing parameter ldap user suffix = doing parameter lm announce = Auto doing parameter lm interval = 60 doing parameter load printers = Yes doing parameter local master = Yes doing parameter lock directory = /run/samba doing parameter lock spin time = 200 doing parameter log file = doing parameter logging = doing parameter log level = 10 doing parameter log nt token command = doing parameter logon drive = doing parameter logon home = \\%N\%U doing parameter logon path = \\%N\%U\profile doing parameter logon script = doing parameter log writeable files on exit = No doing parameter lpq cache time = 30 doing parameter lsa over netlogon = No lpcfg_do_global_parameter: WARNING: The "lsa over netlogon" option is deprecated doing parameter machine password timeout = 604800 doing parameter mangle prefix = 1 doing parameter mangling method = hash2 doing parameter map to guest = Never doing parameter max disk size = 0 doing parameter max log size = 5000 doing parameter max mux = 50 doing parameter max open files = 16384 doing parameter max smbd processes = 0 doing parameter max stat cache size = 512 doing parameter max ttl = 259200 doing parameter max wins ttl = 518400 doing parameter max xmit = 16644 doing parameter mdns name = netbios doing parameter message command = doing parameter min domain uid = 1000 doing parameter min receivefile size = 0 doing parameter min wins ttl = 21600 doing parameter mit kdc command = doing parameter multicast dns register = Yes doing parameter name cache timeout = 660 doing parameter name resolve order = lmhosts wins host bcast doing parameter nbt client socket address = 0.0.0.0 lpcfg_do_global_parameter: WARNING: The "nbt client socket address" option is deprecated doing parameter nbt port = 137 doing parameter ncalrpc dir = /run/samba/ncalrpc doing parameter netbios aliases = doing parameter netbios name = DEBIAN-CLIENT doing parameter netbios scope = doing parameter neutralize nt4 emulation = No doing parameter nmbd bind explicit broadcast = Yes doing parameter nsupdate command = /usr/bin/nsupdate -g doing parameter nt hash store = always doing parameter ntlm auth = ntlmv2-only doing parameter nt pipe support = Yes doing parameter ntp signd socket directory = /var/lib/samba/ntp_signd doing parameter nt status support = Yes doing parameter null passwords = No lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated doing parameter obey pam restrictions = No doing parameter old password allowed period = 60 doing parameter oplock break wait time = 0 doing parameter os2 driver map = doing parameter os level = 20 doing parameter pam password change = No doing parameter panic action = doing parameter passdb backend = tdbsam doing parameter passdb expand explicit = No doing parameter passwd chat = *new*password* %n\n *new*password* %n\n *changed* doing parameter passwd chat debug = No doing parameter passwd chat timeout = 2 doing parameter passwd program = doing parameter password hash gpg key ids = doing parameter password hash userPassword schemes = doing parameter password server = * doing parameter perfcount module = doing parameter pid directory = /run/samba doing parameter preferred master = Auto doing parameter prefork backoff increment = 10 doing parameter prefork children = 4 doing parameter prefork maximum backoff = 120 doing parameter preload modules = doing parameter printcap cache time = 750 doing parameter printcap name = doing parameter private dir = /var/lib/samba/private doing parameter raw NTLMv2 auth = No lpcfg_do_global_parameter: WARNING: The "raw NTLMv2 auth" option is deprecated doing parameter read raw = Yes doing parameter realm = EXAMPLE.NET doing parameter registry shares = No doing parameter reject aes netlogon servers = No doing parameter reject md5 clients = Yes lpcfg_do_global_parameter: WARNING: The "reject md5 clients" option is deprecated doing parameter reject md5 servers = Yes doing parameter remote announce = doing parameter remote browse sync = doing parameter rename user script = doing parameter require strong key = Yes doing parameter reset on zero vc = No doing parameter restrict anonymous = 0 doing parameter root directory = doing parameter rpc big endian = No doing parameter rpc server dynamic port range = 49152-65535 doing parameter rpc server port = 0 doing parameter rpc start on demand helpers = Yes doing parameter samba kcc command = /usr/sbin/samba_kcc doing parameter security = ADS doing parameter server max protocol = SMB3 doing parameter server min protocol = SMB2_02 doing parameter server multi channel support = Yes doing parameter server reject aes schannel = No doing parameter server role = auto doing parameter server schannel = Yes lpcfg_do_global_parameter: WARNING: The "server schannel" option is deprecated doing parameter server schannel require seal = Yes lpcfg_do_global_parameter: WARNING: The "server schannel require seal" option is deprecated doing parameter server services = s3fs, rpc, nbt, wrepl, ldap, cldap, kdc, drepl, winbindd, ntp_signd, kcc, dnsupdate, dns doing parameter server signing = default doing parameter server smb3 encryption algorithms = AES-128-GCM, AES-128-CCM, AES-256-GCM, AES-256-CCM doing parameter server smb3 signing algorithms = AES-128-GMAC, AES-128-CMAC, HMAC-SHA256 doing parameter server string = Samba 4.22.4-Debian-4.22.4+dfsg-1~deb13u1 doing parameter server support krb5 netlogon = No doing parameter set primary group script = doing parameter set quota command = doing parameter show add printer wizard = Yes doing parameter shutdown script = doing parameter smb1 unix extensions = Yes doing parameter smb2 disable lock sequence checking = No doing parameter smb2 disable oplock break retry = No doing parameter smb2 leases = Yes doing parameter smb2 max credits = 8192 doing parameter smb2 max read = 8388608 doing parameter smb2 max trans = 8388608 doing parameter smb2 max write = 8388608 doing parameter smb3 directory leases = Auto doing parameter smbd profiling level = off doing parameter smb passwd file = /etc/samba/smbpasswd doing parameter smb ports = 445 139 doing parameter socket options = TCP_NODELAY doing parameter spn update command = /usr/sbin/samba_spnupdate doing parameter stat cache = Yes doing parameter state directory = /var/lib/samba doing parameter svcctl list = doing parameter sync machine password script = doing parameter sync machine password to keytab = doing parameter syslog = 1 lpcfg_do_global_parameter: WARNING: The "syslog" option is deprecated doing parameter syslog only = No lpcfg_do_global_parameter: WARNING: The "syslog only" option is deprecated doing parameter template homedir = /home/%D/%U doing parameter template shell = /bin/bash doing parameter time server = No doing parameter timestamp logs = Yes doing parameter tls ca directories = doing parameter tls cafile = tls/ca.pem doing parameter tls certfile = tls/cert.pem doing parameter tls crlfile = doing parameter tls dh params file = doing parameter tls enabled = Yes doing parameter tls keyfile = tls/key.pem doing parameter tls priority = NORMAL:-VERS-SSL3.0 doing parameter tls trust system cas = No doing parameter tls verify peer = as_strict_as_possible doing parameter unicode = Yes lpcfg_do_global_parameter: WARNING: The "unicode" option is deprecated doing parameter unix charset = UTF-8 doing parameter unix password sync = No doing parameter use mmap = Yes doing parameter username level = 0 doing parameter username map = doing parameter username map cache time = 0 doing parameter username map script = doing parameter usershare allow guests = No doing parameter usershare max shares = 100 doing parameter usershare owner only = Yes doing parameter usershare path = /var/lib/samba/usershares doing parameter usershare prefix allow list = doing parameter usershare prefix deny list = doing parameter usershare template share = doing parameter utmp = No doing parameter utmp directory = doing parameter winbind cache time = 300 doing parameter winbindd socket directory = /run/samba/winbindd doing parameter winbind enum groups = No doing parameter winbind enum users = No doing parameter winbind expand groups = 2 doing parameter winbind max clients = 200 doing parameter winbind max domain connections = 1 doing parameter winbind nested groups = Yes doing parameter winbind normalize names = No doing parameter winbind nss info = template doing parameter winbind offline logon = No doing parameter winbind reconnect delay = 30 doing parameter winbind refresh tickets = Yes doing parameter winbind request timeout = 60 doing parameter winbind rpc only = No doing parameter winbind scan trusted domains = No doing parameter winbind sealed pipes = Yes doing parameter winbind separator = winbind use default domain = Yes doing parameter winbind use default domain = No doing parameter winbind use krb5 enterprise principals = Yes doing parameter wins hook = doing parameter wins proxy = No doing parameter wins server = doing parameter wins support = No doing parameter workgroup = EXAMPLE doing parameter write raw = Yes doing parameter wsp property file = doing parameter wtmp directory = doing parameter idmap config example : range = 1000000 - 1999999 doing parameter idmap config example : backend = rid doing parameter idmap config * : range = 10000 - 19999 doing parameter idmap config * : backend = tdb doing parameter acl check permissions = Yes lpcfg_do_global_parameter: WARNING: The "acl check permissions" option is deprecated doing parameter acl flag inherited canonicalization = Yes doing parameter acl map full control = Yes doing parameter aio read size = 1 doing parameter aio write size = 1 doing parameter available = Yes doing parameter blocking locks = Yes lpcfg_do_global_parameter: WARNING: The "blocking locks" option is deprecated doing parameter block size = 1024 doing parameter browseable = Yes doing parameter case sensitive = Auto doing parameter create mask = 0744 doing parameter default devmode = Yes doing parameter directory mask = 0755 doing parameter dos filetimes = Yes doing parameter durable handles = Yes doing parameter ea support = Yes doing parameter follow symlinks = Yes doing parameter hide dot files = Yes doing parameter level2 oplocks = Yes doing parameter locking = Yes doing parameter mangled names = illegal doing parameter mangling char = ~ doing parameter map archive = Yes doing parameter max print jobs = 1000 doing parameter nt acl support = Yes doing parameter oplocks = Yes doing parameter posix locking = Yes doing parameter preserve case = Yes doing parameter printing = cups doing parameter read only = Yes doing parameter server smb encrypt = default doing parameter short preserve case = Yes doing parameter smbd getinfo ask sharemode = Yes doing parameter smbd max xattr size = 65536 doing parameter smbd search ask sharemode = Yes doing parameter store dos attributes = Yes doing parameter strict locking = Auto doing parameter strict sync = Yes doing parameter vfs mkdir use tmp name = Auto doing parameter volume serial number = -1 pm_process() returned Yes lp_servicenumber: couldn't find homes ldb: ltdb: tdb(/var/lib/samba/private/secrets.ldb): tdb_open_ex: could not open file /var/lib/samba/private/secrets.ldb: No such file or directory ldb: Unable to open tdb '/var/lib/samba/private/secrets.ldb': No such file or directory ldb: Failed to connect to '/var/lib/samba/private/secrets.ldb' with backend 'tdb': Unable to open tdb '/var/lib/samba/private/secrets.ldb': No such file or directory ldb: ltdb: tdb(/var/lib/samba/private/secrets.ldb): tdb_open_ex: could not open file /var/lib/samba/private/secrets.ldb: No such file or directory ldb: Unable to open tdb '/var/lib/samba/private/secrets.ldb': No such file or directory ldb: Failed to connect to '/var/lib/samba/private/secrets.ldb' with backend 'tdb': Unable to open tdb '/var/lib/samba/private/secrets.ldb': No such file or directory lp_load_ex: refreshing parameters Freeing parametrics: INFO: Current debug levels: all: 10 tdb: 10 printdrivers: 10 lanman: 10 smb: 10 rpc_parse: 10 rpc_srv: 10 rpc_cli: 10 passdb: 10 sam: 10 auth: 10 winbind: 10 vfs: 10 idmap: 10 quota: 10 acls: 10 locking: 10 msdfs: 10 dmapi: 10 registry: 10 scavenger: 10 dns: 10 ldb: 10 tevent: 10 auth_audit: 10 auth_json_audit: 10 kerberos: 10 drs_repl: 10 smb2: 10 smb2_credits: 10 dsdb_audit: 10 dsdb_json_audit: 10 dsdb_password_audit: 10 dsdb_password_json_audit: 10 dsdb_transaction_audit: 10 dsdb_transaction_json_audit: 10 dsdb_group_audit: 10 dsdb_group_json_audit: 10 ldapsrv: 10 Processing section "[global]" doing parameter abort shutdown script = doing parameter acl claims evaluation = AD DC only doing parameter ad dc functional level = 2008_R2 doing parameter add group script = doing parameter additional dns hostnames = doing parameter add machine script = doing parameter addport command = doing parameter addprinter command = doing parameter add share command = doing parameter add user script = doing parameter add user to group script = doing parameter afs token lifetime = 604800 doing parameter afs username map = doing parameter aio max threads = 100 doing parameter algorithmic rid base = 1000 doing parameter allow dcerpc auth level connect = No doing parameter allow dns updates = secure only doing parameter allow insecure wide links = No doing parameter allow nt4 crypto = No lpcfg_do_global_parameter: WARNING: The "allow nt4 crypto" option is deprecated doing parameter allow trusted domains = Yes doing parameter allow unsafe cluster upgrade = No doing parameter apply group policies = Yes doing parameter async dns timeout = 10 doing parameter async smb echo handler = No doing parameter auth event notification = No doing parameter auto services = doing parameter binddns dir = /var/lib/samba/bind-dns doing parameter bind interfaces only = Yes doing parameter browse list = Yes doing parameter cache directory = /var/cache/samba doing parameter change notify = Yes doing parameter change share command = doing parameter check password script = doing parameter client ipc max protocol = default doing parameter client ipc min protocol = default doing parameter client ipc signing = default doing parameter client lanman auth = No lpcfg_do_global_parameter: WARNING: The "client lanman auth" option is deprecated doing parameter client ldap sasl wrapping = seal doing parameter client max protocol = default doing parameter client min protocol = SMB2_02 doing parameter client netlogon ping protocol = cldap doing parameter client NTLMv2 auth = Yes lpcfg_do_global_parameter: WARNING: The "client NTLMv2 auth" option is deprecated doing parameter client plaintext auth = No lpcfg_do_global_parameter: WARNING: The "client plaintext auth" option is deprecated doing parameter client protection = default doing parameter client schannel = Yes lpcfg_do_global_parameter: WARNING: The "client schannel" option is deprecated doing parameter client signing = default doing parameter client smb encrypt = default doing parameter client smb3 encryption algorithms = AES-128-GCM, AES-128-CCM, AES-256-GCM, AES-256-CCM doing parameter client smb3 signing algorithms = AES-128-GMAC, AES-128-CMAC, HMAC-SHA256 doing parameter client use kerberos = desired doing parameter client use krb5 netlogon = default doing parameter client use spnego = Yes lpcfg_do_global_parameter: WARNING: The "client use spnego" option is deprecated doing parameter cluster addresses = doing parameter clustering = No doing parameter config backend = file doing parameter config file = doing parameter create krb5 conf = Yes doing parameter ctdbd socket = doing parameter ctdb locktime warn threshold = 0 doing parameter ctdb timeout = 0 doing parameter cups connection timeout = 30 doing parameter cups encrypt = No doing parameter cups server = doing parameter dcerpc endpoint servers = epmapper, wkssvc, samr, netlogon, lsarpc, drsuapi, dssetup, unixinfo, browser, eventlog6, backupkey, dnsserver doing parameter deadtime = 10080 doing parameter debug class = No doing parameter debug encryption = No doing parameter debug hires timestamp = Yes doing parameter debug pid = No doing parameter debug prefix timestamp = No doing parameter debug syslog format = No doing parameter winbind debug traceid = Yes doing parameter debug uid = No doing parameter dedicated keytab file = doing parameter default service = doing parameter defer sharing violations = Yes doing parameter delete group script = doing parameter deleteprinter command = doing parameter delete share command = doing parameter delete user from group script = doing parameter delete user script = doing parameter dgram port = 138 doing parameter disable netbios = No doing parameter disable spoolss = No doing parameter dns hostname = debian-client.example.net doing parameter dns forwarder = doing parameter dns port = 53 doing parameter dns proxy = Yes doing parameter dns update command = /usr/sbin/samba_dnsupdate doing parameter dns zone scavenging = No doing parameter dns zone transfer clients allow = doing parameter dns zone transfer clients deny = doing parameter domain logons = No lpcfg_do_global_parameter: WARNING: The "domain logons" option is deprecated doing parameter domain master = Auto doing parameter dos charset = CP850 doing parameter dsdb event notification = No doing parameter dsdb group change notification = No doing parameter dsdb password event notification = No doing parameter enable asu support = No doing parameter enable core files = Yes doing parameter enable privileges = Yes lpcfg_do_global_parameter: WARNING: The "enable privileges" option is deprecated doing parameter encrypt passwords = Yes lpcfg_do_global_parameter: WARNING: The "encrypt passwords" option is deprecated doing parameter enhanced browsing = Yes doing parameter enumports command = doing parameter eventlog list = doing parameter get quota command = doing parameter getwd cache = Yes doing parameter gpo update command = /usr/sbin/samba-gpupdate doing parameter guest account = nobody doing parameter himmelblaud hello enabled = No doing parameter himmelblaud hsm pin path = /var/lib/himmelblaud/hsm-pin doing parameter himmelblaud sfa fallback = No doing parameter host msdfs = Yes doing parameter hostname lookups = No doing parameter idmap backend = tdb lpcfg_do_global_parameter: WARNING: The "idmap backend" option is deprecated doing parameter idmap cache time = 604800 doing parameter idmap gid = lpcfg_do_global_parameter: WARNING: The "idmap gid" option is deprecated doing parameter idmap negative cache time = 120 doing parameter idmap uid = lpcfg_do_global_parameter: WARNING: The "idmap uid" option is deprecated doing parameter include system krb5 conf = Yes doing parameter init logon delay = 100 doing parameter init logon delayed hosts = doing parameter interfaces = ens18 127.0.0.1 doing parameter iprint server = doing parameter kdc default domain supported enctypes = 0 doing parameter kdc enable fast = Yes doing parameter kdc force enable rc4 weak session keys = No doing parameter kdc supported enctypes = 0 doing parameter keepalive = 300 doing parameter kerberos encryption types = all doing parameter kerberos method = default doing parameter kernel change notify = Yes doing parameter kpasswd port = 464 doing parameter krb5 port = 88 doing parameter lanman auth = No lpcfg_do_global_parameter: WARNING: The "lanman auth" option is deprecated doing parameter large readwrite = Yes doing parameter ldap admin dn = doing parameter ldap connection timeout = 2 doing parameter ldap debug level = 0 doing parameter ldap debug threshold = 10 doing parameter ldap delete dn = No doing parameter ldap deref = auto doing parameter ldap follow referral = Auto doing parameter ldap group suffix = doing parameter ldap idmap suffix = doing parameter ldap machine suffix = doing parameter ldap max anonymous request size = 256000 doing parameter ldap max authenticated request size = 16777216 doing parameter ldap max search request size = 256000 doing parameter ldap page size = 1000 doing parameter ldap passwd sync = no doing parameter ldap replication sleep = 1000 doing parameter ldap server require strong auth = Yes doing parameter ldap ssl = start tls doing parameter ldap suffix = doing parameter ldap timeout = 15 doing parameter ldap user suffix = doing parameter lm announce = Auto doing parameter lm interval = 60 doing parameter load printers = Yes doing parameter local master = Yes doing parameter lock directory = /run/samba doing parameter lock spin time = 200 doing parameter log file = doing parameter logging = doing parameter log level = 10 doing parameter log nt token command = doing parameter logon drive = doing parameter logon home = \\%N\%U doing parameter logon path = \\%N\%U\profile doing parameter logon script = doing parameter log writeable files on exit = No doing parameter lpq cache time = 30 doing parameter lsa over netlogon = No lpcfg_do_global_parameter: WARNING: The "lsa over netlogon" option is deprecated doing parameter machine password timeout = 604800 doing parameter mangle prefix = 1 doing parameter mangling method = hash2 doing parameter map to guest = Never doing parameter max disk size = 0 doing parameter max log size = 5000 doing parameter max mux = 50 doing parameter max open files = 16384 doing parameter max smbd processes = 0 doing parameter max stat cache size = 512 doing parameter max ttl = 259200 doing parameter max wins ttl = 518400 doing parameter max xmit = 16644 doing parameter mdns name = netbios doing parameter message command = doing parameter min domain uid = 1000 doing parameter min receivefile size = 0 doing parameter min wins ttl = 21600 doing parameter mit kdc command = doing parameter multicast dns register = Yes doing parameter name cache timeout = 660 doing parameter name resolve order = lmhosts wins host bcast doing parameter nbt client socket address = 0.0.0.0 lpcfg_do_global_parameter: WARNING: The "nbt client socket address" option is deprecated doing parameter nbt port = 137 doing parameter ncalrpc dir = /run/samba/ncalrpc doing parameter netbios aliases = doing parameter netbios name = DEBIAN-CLIENT doing parameter netbios scope = doing parameter neutralize nt4 emulation = No doing parameter nmbd bind explicit broadcast = Yes doing parameter nsupdate command = /usr/bin/nsupdate -g doing parameter nt hash store = always doing parameter ntlm auth = ntlmv2-only doing parameter nt pipe support = Yes doing parameter ntp signd socket directory = /var/lib/samba/ntp_signd doing parameter nt status support = Yes doing parameter null passwords = No lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated doing parameter obey pam restrictions = No doing parameter old password allowed period = 60 doing parameter oplock break wait time = 0 doing parameter os2 driver map = doing parameter os level = 20 doing parameter pam password change = No doing parameter panic action = doing parameter passdb backend = tdbsam doing parameter passdb expand explicit = No doing parameter passwd chat = *new*password* %n\n *new*password* %n\n *changed* doing parameter passwd chat debug = No doing parameter passwd chat timeout = 2 doing parameter passwd program = doing parameter password hash gpg key ids = doing parameter password hash userPassword schemes = doing parameter password server = * doing parameter perfcount module = doing parameter pid directory = /run/samba doing parameter preferred master = Auto doing parameter prefork backoff increment = 10 doing parameter prefork children = 4 doing parameter prefork maximum backoff = 120 doing parameter preload modules = doing parameter printcap cache time = 750 doing parameter printcap name = doing parameter private dir = /var/lib/samba/private doing parameter raw NTLMv2 auth = No lpcfg_do_global_parameter: WARNING: The "raw NTLMv2 auth" option is deprecated doing parameter read raw = Yes doing parameter realm = EXAMPLE.NET doing parameter registry shares = No doing parameter reject aes netlogon servers = No doing parameter reject md5 clients = Yes lpcfg_do_global_parameter: WARNING: The "reject md5 clients" option is deprecated doing parameter reject md5 servers = Yes doing parameter remote announce = doing parameter remote browse sync = doing parameter rename user script = doing parameter require strong key = Yes doing parameter reset on zero vc = No doing parameter restrict anonymous = 0 doing parameter root directory = doing parameter rpc big endian = No doing parameter rpc server dynamic port range = 49152-65535 doing parameter rpc server port = 0 doing parameter rpc start on demand helpers = Yes doing parameter samba kcc command = /usr/sbin/samba_kcc doing parameter security = ADS doing parameter server max protocol = SMB3 doing parameter server min protocol = SMB2_02 doing parameter server multi channel support = Yes doing parameter server reject aes schannel = No doing parameter server role = auto doing parameter server schannel = Yes lpcfg_do_global_parameter: WARNING: The "server schannel" option is deprecated doing parameter server schannel require seal = Yes lpcfg_do_global_parameter: WARNING: The "server schannel require seal" option is deprecated doing parameter server services = s3fs, rpc, nbt, wrepl, ldap, cldap, kdc, drepl, winbindd, ntp_signd, kcc, dnsupdate, dns doing parameter server signing = default doing parameter server smb3 encryption algorithms = AES-128-GCM, AES-128-CCM, AES-256-GCM, AES-256-CCM doing parameter server smb3 signing algorithms = AES-128-GMAC, AES-128-CMAC, HMAC-SHA256 doing parameter server string = Samba 4.22.4-Debian-4.22.4+dfsg-1~deb13u1 doing parameter server support krb5 netlogon = No doing parameter set primary group script = doing parameter set quota command = doing parameter show add printer wizard = Yes doing parameter shutdown script = doing parameter smb1 unix extensions = Yes doing parameter smb2 disable lock sequence checking = No doing parameter smb2 disable oplock break retry = No doing parameter smb2 leases = Yes doing parameter smb2 max credits = 8192 doing parameter smb2 max read = 8388608 doing parameter smb2 max trans = 8388608 doing parameter smb2 max write = 8388608 doing parameter smb3 directory leases = Auto doing parameter smbd profiling level = off doing parameter smb passwd file = /etc/samba/smbpasswd doing parameter smb ports = 445 139 doing parameter socket options = TCP_NODELAY doing parameter spn update command = /usr/sbin/samba_spnupdate doing parameter stat cache = Yes doing parameter state directory = /var/lib/samba doing parameter svcctl list = doing parameter sync machine password script = doing parameter sync machine password to keytab = doing parameter syslog = 1 lpcfg_do_global_parameter: WARNING: The "syslog" option is deprecated doing parameter syslog only = No lpcfg_do_global_parameter: WARNING: The "syslog only" option is deprecated doing parameter template homedir = /home/%D/%U doing parameter template shell = /bin/bash doing parameter time server = No doing parameter timestamp logs = Yes doing parameter tls ca directories = doing parameter tls cafile = tls/ca.pem doing parameter tls certfile = tls/cert.pem doing parameter tls crlfile = doing parameter tls dh params file = doing parameter tls enabled = Yes doing parameter tls keyfile = tls/key.pem doing parameter tls priority = NORMAL:-VERS-SSL3.0 doing parameter tls trust system cas = No doing parameter tls verify peer = as_strict_as_possible doing parameter unicode = Yes lpcfg_do_global_parameter: WARNING: The "unicode" option is deprecated doing parameter unix charset = UTF-8 doing parameter unix password sync = No doing parameter use mmap = Yes doing parameter username level = 0 doing parameter username map = doing parameter username map cache time = 0 doing parameter username map script = doing parameter usershare allow guests = No doing parameter usershare max shares = 100 doing parameter usershare owner only = Yes doing parameter usershare path = /var/lib/samba/usershares doing parameter usershare prefix allow list = doing parameter usershare prefix deny list = doing parameter usershare template share = doing parameter utmp = No doing parameter utmp directory = doing parameter winbind cache time = 300 doing parameter winbindd socket directory = /run/samba/winbindd doing parameter winbind enum groups = No doing parameter winbind enum users = No doing parameter winbind expand groups = 2 doing parameter winbind max clients = 200 doing parameter winbind max domain connections = 1 doing parameter winbind nested groups = Yes doing parameter winbind normalize names = No doing parameter winbind nss info = template doing parameter winbind offline logon = No doing parameter winbind reconnect delay = 30 doing parameter winbind refresh tickets = Yes doing parameter winbind request timeout = 60 doing parameter winbind rpc only = No doing parameter winbind scan trusted domains = No doing parameter winbind sealed pipes = Yes doing parameter winbind separator = winbind use default domain = Yes doing parameter winbind use default domain = No doing parameter winbind use krb5 enterprise principals = Yes doing parameter wins hook = doing parameter wins proxy = No doing parameter wins server = doing parameter wins support = No doing parameter workgroup = EXAMPLE doing parameter write raw = Yes doing parameter wsp property file = doing parameter wtmp directory = doing parameter idmap config example : range = 1000000 - 1999999 doing parameter idmap config example : backend = rid doing parameter idmap config * : range = 10000 - 19999 doing parameter idmap config * : backend = tdb doing parameter acl check permissions = Yes lpcfg_do_global_parameter: WARNING: The "acl check permissions" option is deprecated doing parameter acl flag inherited canonicalization = Yes doing parameter acl map full control = Yes doing parameter aio read size = 1 doing parameter aio write size = 1 doing parameter available = Yes doing parameter blocking locks = Yes lpcfg_do_global_parameter: WARNING: The "blocking locks" option is deprecated doing parameter block size = 1024 doing parameter browseable = Yes doing parameter case sensitive = Auto doing parameter create mask = 0744 doing parameter default devmode = Yes doing parameter directory mask = 0755 doing parameter dos filetimes = Yes doing parameter durable handles = Yes doing parameter ea support = Yes doing parameter follow symlinks = Yes doing parameter hide dot files = Yes doing parameter level2 oplocks = Yes doing parameter locking = Yes doing parameter mangled names = illegal doing parameter mangling char = ~ doing parameter map archive = Yes doing parameter max print jobs = 1000 doing parameter nt acl support = Yes doing parameter oplocks = Yes doing parameter posix locking = Yes doing parameter preserve case = Yes doing parameter printing = cups doing parameter read only = Yes doing parameter server smb encrypt = default doing parameter short preserve case = Yes doing parameter smbd getinfo ask sharemode = Yes doing parameter smbd max xattr size = 65536 doing parameter smbd search ask sharemode = Yes doing parameter store dos attributes = Yes doing parameter strict locking = Auto doing parameter strict sync = Yes doing parameter vfs mkdir use tmp name = Auto doing parameter volume serial number = -1 pm_process() returned Yes lp_servicenumber: couldn't find homes GENSEC backend 'gssapi_spnego' registered GENSEC backend 'gssapi_krb5' registered GENSEC backend 'gssapi_krb5_sasl' registered GENSEC backend 'spnego' registered GENSEC backend 'schannel' registered GENSEC backend 'ncalrpc_as_system' registered GENSEC backend 'sasl-EXTERNAL' registered GENSEC backend 'ntlmssp' registered GENSEC backend 'ntlmssp_resume_ccache' registered GENSEC backend 'http_basic' registered GENSEC backend 'http_ntlm' registered GENSEC backend 'http_negotiate' registered GENSEC backend 'krb5' registered GENSEC backend 'fake_gssapi_krb5' registered interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 finddcs: searching for a DC by DNS domain EXAMPLE.NET finddcs: looking for SRV records for _ldap._tcp.EXAMPLE.NET resolve_lmhosts: Attempting lmhosts lookup for name _ldap._tcp.EXAMPLE.NET<0x0> startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory dns_lookup_send_next: Sending DNS request #0 to 172.16.182.210 dns_cli_request_send: Asking 172.16.182.210 for _ldap._tcp.EXAMPLE.NET./1/33 via UDP [0000] 25 12 01 00 00 01 00 00 00 00 00 01 05 5F 6C 64 %....... ....._ld [0010] 61 70 04 5F 74 63 70 07 45 58 41 4D 50 4C 45 03 ap._tcp. EXAMPLE. [0020] 4E 45 54 00 00 21 00 01 00 00 29 10 00 00 00 00 NET..!.. ..)..... [0030] 00 00 00 ... dns_lookup_send_next: cancelling wait_subreq [0000] 25 12 85 80 00 01 00 02 00 00 00 01 05 5F 6C 64 %....... ....._ld [0010] 61 70 04 5F 74 63 70 07 45 58 41 4D 50 4C 45 03 ap._tcp. EXAMPLE. [0020] 4E 45 54 00 00 21 00 01 C0 0C 00 21 00 01 00 00 NET..!.. ...!.... [0030] 03 84 00 1A 00 00 00 64 01 85 06 64 65 76 64 63 .......d ...devdc [0040] 31 07 65 78 61 6D 70 6C 65 03 6E 65 74 00 C0 0C 1.exampl e.net... [0050] 00 21 00 01 00 00 03 84 00 1A 00 00 00 64 01 85 .!...... .....d.. [0060] 06 64 65 76 64 63 32 07 65 78 61 6D 70 6C 65 03 .devdc2. example. [0070] 6E 65 74 00 00 00 29 04 D0 00 00 00 00 00 00 net...). ....... finddcs: DNS SRV response 0 at '172.16.182.210' finddcs: DNS SRV response 1 at '172.16.182.211' &response->data.nt5_ex: struct NETLOGON_SAM_LOGON_RESPONSE_EX command : LOGON_SAM_LOGON_RESPONSE_EX (23) sbz : 0x0000 (0) server_type : 0x0001d3fd (119805) 1: NBT_SERVER_PDC 1: NBT_SERVER_GC 1: NBT_SERVER_LDAP 1: NBT_SERVER_DS 1: NBT_SERVER_KDC 1: NBT_SERVER_TIMESERV 1: NBT_SERVER_CLOSEST 1: NBT_SERVER_WRITABLE 1: NBT_SERVER_GOOD_TIMESERV 0: NBT_SERVER_NDNC 0: NBT_SERVER_SELECT_SECRET_DOMAIN_6 1: NBT_SERVER_FULL_SECRET_DOMAIN_6 0: NBT_SERVER_ADS_WEB_SERVICE 1: NBT_SERVER_DS_8 1: NBT_SERVER_DS_9 1: NBT_SERVER_DS_10 0: NBT_SERVER_HAS_DNS_NAME 0: NBT_SERVER_IS_DEFAULT_NC 0: NBT_SERVER_FOREST_ROOT domain_uuid : b19752ad-f794-4860-b2e5-a281915f5e20 forest : 'example.net' dns_domain : 'example.net' pdc_dns_name : 'devdc1.example.net' domain_name : 'EXAMPLE' pdc_name : 'DEVDC1' user_name : '' server_site : 'Default-First-Site-Name' client_site : 'Default-First-Site-Name' sockaddr_size : 0x00 (0) sockaddr: struct nbt_sockaddr sockaddr_family : 0x00000000 (0) pdc_ip : (null) remaining : DATA_BLOB length=0 next_closest_site : NULL nt_version : 0x00000005 (5) 1: NETLOGON_NT_VERSION_1 0: NETLOGON_NT_VERSION_5 1: NETLOGON_NT_VERSION_5EX 0: NETLOGON_NT_VERSION_5EX_WITH_IP 0: NETLOGON_NT_VERSION_WITH_CLOSEST_SITE 0: NETLOGON_NT_VERSION_AVOID_NT4EMUL 0: NETLOGON_NT_VERSION_PDC 0: NETLOGON_NT_VERSION_IP 0: NETLOGON_NT_VERSION_LOCAL 0: NETLOGON_NT_VERSION_GC lmnt_token : 0xffff (65535) lm20_token : 0xffff (65535) finddcs: Found matching DC 172.16.182.210 with server_type=0x0001d3fd lpcfg_load: refreshing parameters from /etc/samba/smb.conf Processing section "[global]" lpcfg_do_global_parameter: WARNING: The "allow nt4 crypto" option is deprecated lpcfg_do_global_parameter: WARNING: The "client lanman auth" option is deprecated lpcfg_do_global_parameter: WARNING: The "client NTLMv2 auth" option is deprecated lpcfg_do_global_parameter: WARNING: The "client plaintext auth" option is deprecated lpcfg_do_global_parameter: WARNING: The "client schannel" option is deprecated lpcfg_do_global_parameter: WARNING: The "client use spnego" option is deprecated lpcfg_do_global_parameter: WARNING: The "domain logons" option is deprecated lpcfg_do_global_parameter: WARNING: The "enable privileges" option is deprecated lpcfg_do_global_parameter: WARNING: The "encrypt passwords" option is deprecated lpcfg_do_global_parameter: WARNING: The "idmap backend" option is deprecated lpcfg_do_global_parameter: WARNING: The "idmap gid" option is deprecated lpcfg_do_global_parameter: WARNING: The "idmap uid" option is deprecated lpcfg_do_global_parameter: WARNING: The "lanman auth" option is deprecated INFO: Current debug levels: all: 10 tdb: 10 printdrivers: 10 lanman: 10 smb: 10 rpc_parse: 10 rpc_srv: 10 rpc_cli: 10 passdb: 10 sam: 10 auth: 10 winbind: 10 vfs: 10 idmap: 10 quota: 10 acls: 10 locking: 10 msdfs: 10 dmapi: 10 registry: 10 scavenger: 10 dns: 10 ldb: 10 tevent: 10 auth_audit: 10 auth_json_audit: 10 kerberos: 10 drs_repl: 10 smb2: 10 smb2_credits: 10 dsdb_audit: 10 dsdb_json_audit: 10 dsdb_password_audit: 10 dsdb_password_json_audit: 10 dsdb_transaction_audit: 10 dsdb_transaction_json_audit: 10 dsdb_group_audit: 10 dsdb_group_json_audit: 10 ldapsrv: 10 lpcfg_do_global_parameter: WARNING: The "lsa over netlogon" option is deprecated lpcfg_do_global_parameter: WARNING: The "nbt client socket address" option is deprecated lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated lpcfg_do_global_parameter: WARNING: The "raw NTLMv2 auth" option is deprecated lpcfg_do_global_parameter: WARNING: The "reject md5 clients" option is deprecated lpcfg_do_global_parameter: WARNING: The "server schannel" option is deprecated lpcfg_do_global_parameter: WARNING: The "server schannel require seal" option is deprecated lpcfg_do_global_parameter: WARNING: The "syslog" option is deprecated lpcfg_do_global_parameter: WARNING: The "syslog only" option is deprecated lpcfg_do_global_parameter: WARNING: The "unicode" option is deprecated lpcfg_do_global_parameter: WARNING: The "acl check permissions" option is deprecated lpcfg_do_global_parameter: WARNING: The "blocking locks" option is deprecated pm_process() returned Yes Security token SIDs (1): SID[ 0]: S-1-5-18 Privileges (0xFFFFFFFFFFFFFFFF): Privilege[ 0]: SeMachineAccountPrivilege Privilege[ 1]: SeTakeOwnershipPrivilege Privilege[ 2]: SeBackupPrivilege Privilege[ 3]: SeRestorePrivilege Privilege[ 4]: SeRemoteShutdownPrivilege Privilege[ 5]: SePrintOperatorPrivilege Privilege[ 6]: SeAddUsersPrivilege Privilege[ 7]: SeDiskOperatorPrivilege Privilege[ 8]: SeSecurityPrivilege Privilege[ 9]: SeSystemtimePrivilege Privilege[ 10]: SeShutdownPrivilege Privilege[ 11]: SeDebugPrivilege Privilege[ 12]: SeSystemEnvironmentPrivilege Privilege[ 13]: SeSystemProfilePrivilege Privilege[ 14]: SeProfileSingleProcessPrivilege Privilege[ 15]: SeIncreaseBasePriorityPrivilege Privilege[ 16]: SeLoadDriverPrivilege Privilege[ 17]: SeCreatePagefilePrivilege Privilege[ 18]: SeIncreaseQuotaPrivilege Privilege[ 19]: SeChangeNotifyPrivilege Privilege[ 20]: SeUndockPrivilege Privilege[ 21]: SeManageVolumePrivilege Privilege[ 22]: SeImpersonatePrivilege Privilege[ 23]: SeCreateGlobalPrivilege Privilege[ 24]: SeEnableDelegationPrivilege Rights (0x 0): interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 interpret_string_addr_internal: getaddrinfo failed for name ens18 (flags 32) [Temporary failure in name resolution] interpret_interface: Can't find address for ens18 added interface lo ip=127.0.0.1 bcast=127.255.255.255 netmask=255.0.0.0 resolve_lmhosts: Attempting lmhosts lookup for name devdc1.example.net<0x20> startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory Starting GENSEC mechanism spnego Starting GENSEC submechanism gssapi_krb5 Received smb_krb5 packet of length 310 Received smb_krb5 packet of length 244 kinit for DEBIAN-CLIENT$@EXAMPLE.NET succeeded gensec_update_send: gssapi_krb5[0x2cb018e0]: subreq: 0x2d0d2320 gensec_update_send: spnego[0x2d1c3420]: subreq: 0x2d1cb730 gensec_update_done: gssapi_krb5[0x2cb018e0]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0x2d0d2320/source4/auth/gensec/gensec_gssapi.c:1120]: state[2] error[0 (0x0)] state[struct gensec_gssapi_update_state (0x2d0d2500)] timer[(nil)] finish[source4/auth/gensec/gensec_gssapi.c:1131] gensec_update_done: spnego[0x2d1c3420]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0x2d1cb730/auth/gensec/spnego.c:1614]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0x2d1cb910)] timer[(nil)] finish[auth/gensec/spnego.c:2109] gensec_gssapi: NO credentials were delegated GSSAPI Connection will be cryptographically sealed gensec_update_send: gssapi_krb5[0x2cb018e0]: subreq: 0x2d0d2320 gensec_update_send: spnego[0x2d1c3420]: subreq: 0x2d1cb730 gensec_update_done: gssapi_krb5[0x2cb018e0]: NT_STATUS_OK tevent_req[0x2d0d2320/source4/auth/gensec/gensec_gssapi.c:1120]: state[2] error[0 (0x0)] state[struct gensec_gssapi_update_state (0x2d0d2500)] timer[(nil)] finish[source4/auth/gensec/gensec_gssapi.c:1138] gensec_update_done: spnego[0x2d1c3420]: NT_STATUS_OK tevent_req[0x2d1cb730/auth/gensec/spnego.c:1614]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0x2d1cb910)] timer[(nil)] finish[auth/gensec/spnego.c:2109] 2025-11-06 09:11:52.906|[I38887]| Found dn CN=DEBIAN-CLIENT,OU=Computers,DC=example,DC=net for samaccountname DEBIAN-CLIENT$ | {} dsdb_search: BASE flags=0x00042210 CN=DEBIAN-CLIENT,OU=Computers,DC=example,DC=net (objectClass=*) -> 1 gendb_search_v: NULL (&(objectSid=\01\04\00\00\00\00\00\05\15\00\00\00\E2d\DD\F9%/X@,\8B\B2P)(objectClass=domain)) -> 1 dsdb_search: BASE flags=0x00000200 NULL -> 1 dsdb_search_dn: flags=0x00000010 -> 1 gendb_search_v: DC=example,DC=net NULL -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> LDAP error 32 LDAP_NO_SUCH_OBJECT - '> <> (No such object) dsdb_search: SUB flags=0x00000010 DC=example,DC=net (&(objectClass=foreignSecurityPrincipal)(objectSID=S-1-5-11)) -> 1 dsdb_search: BASE flags=0x00000010 (&(objectClass=group)(groupType:1.2.840.113556.1.4.803:=1)) -> 1 dsdb_search: BASE flags=0x00000010 (&(objectClass=group)(groupType:1.2.840.113556.1.4.803:=1)) -> 1 dsdb_search_dn: flags=0x00000010 -> 1 dsdb_search_dn: flags=0x00000010 -> 1 Security token SIDs (7): SID[ 0]: S-1-5-21-4192036066-1079521061-1353878316-1107 SID[ 1]: S-1-5-21-4192036066-1079521061-1353878316-515 SID[ 2]: S-1-1-0 SID[ 3]: S-1-5-2 SID[ 4]: S-1-5-11 SID[ 5]: S-1-5-32-545 SID[ 6]: S-1-5-32-554 Privileges (0x 0): Rights (0x 0): 2025-11-06 09:11:52.917|[D46288]| get_gpo_list: query OU: [OU=Computers,DC=example,DC=net] for GPOs | {} 2025-11-06 09:11:52.917|[D15106]| get_gpo_link: no 'gPOptions' attribute found | {} 2025-11-06 09:11:52.918|[D00143]| gpo_parse_gplink: processing link | {} 2025-11-06 09:11:52.918|[D96793]| gpo_parse_gplink: link: LDAP://cn={ECD104C4-65B4-42D2-BFE9-112395AE1E6B},cn=policies,cn=system,DC=example,DC=net | {} 2025-11-06 09:11:52.918|[D63190]| gpo_parse_gplink: opt: 0 | {} 2025-11-06 09:11:52.919|[D85108]| add_gplink_to_gpo_list: added GPLINK #0 LDAP://cn={ECD104C4-65B4-42D2-BFE9-112395AE1E6B},cn=policies,cn=system,DC=example,DC=net to GPO list | {} 2025-11-06 09:11:52.919|[D80284]| get_gpo_list: query DC: [DC=example,DC=net] for GPOs | {} 2025-11-06 09:11:52.919|[D15106]| get_gpo_link: no 'gPOptions' attribute found | {} 2025-11-06 09:11:52.920|[D00143]| gpo_parse_gplink: processing link | {} 2025-11-06 09:11:52.920|[D13519]| gpo_parse_gplink: link: LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=example,DC=net | {} 2025-11-06 09:11:52.920|[D63190]| gpo_parse_gplink: opt: 0 | {} 2025-11-06 09:11:52.921|[D16410]| add_gplink_to_gpo_list: added GPLINK #0 LDAP://CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=example,DC=net to GPO list | {} 2025-11-06 09:11:52.923|[D12251]| get_gpo_list: query SITE: [CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=example,DC=net] for GPOs | {} 2025-11-06 09:11:52.923|[D22278]| get_gpo_link: no 'gPLink' attribute found for 'CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=example,DC=net' | {} Opening cache file at /run/samba/gencache.tdb sitename_fetch: Returning sitename for realm 'EXAMPLE.NET': "Default-First-Site-Name" internal_resolve_name: looking up devdc1.example.net#20 (sitename Default-First-Site-Name) namecache_fetch: name devdc1.example.net#20 found. remove_duplicate_addrs2: looking for duplicate address/port pairs Connecting to 172.16.182.210 at port 445 socket options: SO_KEEPALIVE=0, SO_REUSEADDR=0, SO_BROADCAST=0, TCP_NODELAY=1, TCP_KEEPCNT=9, TCP_KEEPIDLE=7200, TCP_KEEPINTVL=75, IPTOS_LOWDELAY=0, IPTOS_THROUGHPUT=0, SO_REUSEPORT=0, SO_SNDBUF=87040, SO_RCVBUF=131072, SO_SNDLOWAT=1, SO_RCVLOWAT=1, SO_SNDTIMEO=0, SO_RCVTIMEO=0, TCP_QUICKACK=1, TCP_DEFER_ACCEPT=0, TCP_USER_TIMEOUT=0 cli_session_setup_spnego_send: Connect to devdc1.example.net as DEBIAN-CLIENT$@EXAMPLE.NET using SPNEGO Starting GENSEC mechanism spnego Starting GENSEC submechanism gse_krb5 gensec_gse_client_prepare_ccache: No kinit required for DEBIAN-CLIENT$@EXAMPLE.NET to access cifs/devdc1.example.net, MEMORY:anonymous-0x2d1cc7b0-0 gensec_update_send: gse_krb5[0x2d1e0ae0]: subreq: 0x2d0d2320 gensec_update_send: spnego[0x2d1e41d0]: subreq: 0x2d1de320 gensec_update_done: gse_krb5[0x2d1e0ae0]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0x2d0d2320/source3/librpc/crypto/gse.c:1220]: state[2] error[0 (0x0)] state[struct gensec_gse_update_state (0x2d0d2500)] timer[(nil)] finish[source3/librpc/crypto/gse.c:1231] gensec_update_done: spnego[0x2d1e41d0]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0x2d1de320/auth/gensec/spnego.c:1614]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0x2d1de500)] timer[(nil)] finish[auth/gensec/spnego.c:2109] gensec_update_send: gse_krb5[0x2d1e0ae0]: subreq: 0x2cb691d0 gensec_update_send: spnego[0x2d1e41d0]: subreq: 0x2d1de320 gensec_update_done: gse_krb5[0x2d1e0ae0]: NT_STATUS_OK tevent_req[0x2cb691d0/source3/librpc/crypto/gse.c:1220]: state[2] error[0 (0x0)] state[struct gensec_gse_update_state (0x2cb693b0)] timer[(nil)] finish[source3/librpc/crypto/gse.c:1238] gensec_update_done: spnego[0x2d1e41d0]: NT_STATUS_OK tevent_req[0x2d1de320/auth/gensec/spnego.c:1614]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0x2d1de500)] timer[(nil)] finish[auth/gensec/spnego.c:2109] signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) signed SMB2 message (sign_algo_id=2) 2025-11-06 09:11:53.128|[I13546]| smb.conf [global] was changed | {'bind interfaces only': 'yes'} 2025-11-06 09:11:53.130|[I13546]| smb.conf [global] was changed | {'interfaces': 'ens18 127.0.0.1'} parse_gpt_ini: no name in /var/cache/samba/gpo_cache/EXAMPLE.NET/POLICIES/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI