Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.100 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-04-2007, 03:34 PM
Mark_D's Avatar
Member
 
Join Date: Apr 2004
Location: Melb, Australia
Posts: 89
Unhappy [V7.100] SSO unable to join AD

Hi I've been following the various threads for this problem and have been unable to join my AD.
I have a MS SBS Server with a .local AD.
below are the setting that are configured.
Under AD authentification: I have Server Host(zmain), port 389, Bind user: CN=administrator,CN=users,DC=ncs,DC=local. Click apply, all OK.
DNS Request Routing from Astaro to SBS (working):zmain.ncs.local has address 172.16.10.1
DNS entry for roxy7 (Astaro) in SBS (working):roxy7.ncs.local has address 172.16.1.1
LAN Manager auth level set to: Send LM & NTLM - use NTLMv2 session security if negotiated
Using a LDAP Browser I can navigate the tree.
Using: host -t srv _ldap._tcp.dc._msdcs.ncs.local I receive:_ldap._tcp.dc._msdcs.ncs.local has SRV record 0 100 389 zmain.ncs.local.

Under SSO.
NCS.LOCAL (Which system put there after .100 upgrade) and have manually changed.
Admin User: I have tried every option that I can think of with administrator ie. administrator, ncs.local\administrator, NCS.LOCAL\administrator, CN=administrator, CN=administrator,CN=users,DC=ncs,DC=local.
Click Apply. and receive a number of "the running request has reached a timeout without finishing, do you want it to be aborted?" click no wait another 30 sec. "Then unable to complete backend request".
Note if I change the Domain to NCS I get an instant (15sec) "Joining the domain failed."

Tests completed so far:
1. DNS working.
2. LDAP working.
3. Looking in fallback log I get
2007:12:04-16:59:49 (none) [user:err] net: [2007/12/04 16:59:49, 0] utils/net_ads.c:ads_startup(289)
2007:12:04-16:59:49 (none) [user:err] net: ads_connect: Operations error
2007:12:04-17:00:29 (none) [user:err] net: [2007/12/04 17:00:29, 0] utils/net_ads.c:ads_startup(289)
2007:12:04-17:00:29 (none) [user:err] net: ads_connect: Operations error

Where have I gone wrong or what am I missing.

Thanks for any responses
Help
Mark
__________________
1x ASG v7.500 2.4 Intel 2Gb ram 7 nic
2x ASG v7.500 2.4 Intel 1Gb ram 3 nic

Last edited by Mark_D; 12-04-2007 at 03:57 PM.
  #2 (permalink)  
Old 12-04-2007, 10:02 PM
Simon Shaw's Avatar
Aussie moderator.
 
Join Date: Jun 2001
Location: Perth, Western Australia
Posts: 2,628
Default

I can only get SSO working using short domain name to join the AD.

ie PERTH and not the long name which is company.com.au
__________________
Simon Shaw
Systems Manager
Micromine PL

Intel 2.66GHz Quad Core, 4GB (2 x 2GB) PC-6400 800Mhz 4-4-4-12, WD 300GB 10K RPM VelociRaptor, Intel Pro/1000 Quad Port PCI-X
http://www.sputcorp.com/
  #3 (permalink)  
Old 12-04-2007, 10:15 PM
Senior Member
 
Join Date: Dec 2002
Location: Groves, Texas
Posts: 226
Default

I had to use the full domain name (DOMAIN.ORG) , and it had to be in CAPS. Weird.
__________________
Work - ASL 6.313- Unlimited - P4 3.4 GHz Dual Core - 2 Gigs Ram
Home - ASL 7.180 - 50 User - P4 2.8 Ghz - 1 Gig Ram

Accessing with IE7
(Switch to FireFox is not a valid answer to any problem)
  #4 (permalink)  
Old 12-04-2007, 10:58 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,429
Default

Hey Mark, I had an issue too... after some time with Astaro support, found that the winbindd process was "flipping out." A trip to /var/locks found that the file winbinddd.pid had an old timestamp on it (from yesterday)... manually deleting that file, then stopping and starting the http proxy (which causes winbindd to reinitialize) fixed my problem. It's the only system I've had the problem on, just got done updating a customer's system an hour or so ago and had no problem.

One Idea: check for a computer account matching the name of your Astaro in AD; delete it, make sure all your DCs are synced up, then try rejoining.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #5 (permalink)  
Old 12-04-2007, 11:00 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,429
Default

Mark: Also make sure your timezone setting on the Astaro matches your DC, and that the times are within 5 minutes of each other; Kerberos is quite sensitive about the time.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #6 (permalink)  
Old 12-04-2007, 11:04 PM
Senior Member
 
Join Date: Dec 2002
Location: Groves, Texas
Posts: 226
Default

Bruce -

Any suggestions on where to start looking if my Basic authentication fails, but AD SSO and AD web auth works?

My network is all Windows 2003 DCs running in 2003 native mode. Mixture of WinXp and Win2k computers. all exibit the same problem. Auth box pops up, name and password entered, fails auth. The log shows "DENIED" as a reson.

Have tried the domain\user method when entering the username, but it fails always.

I have rejoined the domain since 7.100, same results. Even tried using a different DC to authenticate against. Same thing.

I submitted a ticket, but they are looking at other things right now. Just trying to get an idea where to look.

Thanks,
__________________
Work - ASL 6.313- Unlimited - P4 3.4 GHz Dual Core - 2 Gigs Ram
Home - ASL 7.180 - 50 User - P4 2.8 Ghz - 1 Gig Ram

Accessing with IE7
(Switch to FireFox is not a valid answer to any problem)

Last edited by TXGARobert; 12-04-2007 at 11:07 PM.
  #7 (permalink)  
Old 12-04-2007, 11:42 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,429
Default

Don't know about Basic Authentication... my problem was with AD.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #8 (permalink)  
Old 12-05-2007, 12:37 AM
Mark_D's Avatar
Member
 
Join Date: Apr 2004
Location: Melb, Australia
Posts: 89
Default

Thanks Guy's for your response.
I did forget to mention that I checked the time zones and clocks are currently 12 sec out, I also tried adding and deleting computer name for astaro.
Checking /var/locks I found that the file winbinddd.pid did not exist.
I'm about to download a new iso of 7.100 and install on a new box to see what happens.

Any other suggestions out there?

Thanks again
Mark
__________________
1x ASG v7.500 2.4 Intel 2Gb ram 7 nic
2x ASG v7.500 2.4 Intel 1Gb ram 3 nic
  #9 (permalink)  
Old 12-11-2007, 05:21 PM
Junior Member
 
Join Date: Dec 2007
Posts: 10
Default

Hi,

I'm new to Astaro. I'm getting the same problem. Unable to join my AD domain (I was when using v7.011).
When I try to join the domain I get a failed message. A look at the computers account shows astaro's box hostame desactivated.

Fallback logs shows :
unable to determine machine account's DNS name in AD (nslookup for DC is ok) and

another one :
no dNSHostName attribute

maybe it'll help...
  #10 (permalink)  
Old 12-11-2007, 05:30 PM
svens's Avatar
Senior Member
 
Join Date: Nov 2005
Posts: 260
Default

Hi,
Quote:
Originally Posted by apave View Post
unable to determine machine account's DNS name in AD (nslookup for DC is ok)
Do you have the FQDN as hostname configured (means asg.domain.com instead of only 'asg'), and is the ASG in the same DNS domain as the Domain Controller?

Cheers,

Sven.
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:00 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.