Upgrade 9.2.1.5 to 9.3, AD users can no longer login

Status
Not open for further replies.

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
I've checked that CIFS is setup right and Active Directory seems to have joined the domain correctly. When I check from the command line my AD users are listed. They are not shown using the GUI though and attempting to map the shared folder doesn't accept login credentials. I could reboot back to the old version and I assume my users would at least be able to see their data again, but I'd prefer to get it working again with the new version. What might I have missed?
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
Do these error messages help at all?

Jun 3 14:24:25 nas01 smbd[4743]: STATUS=daemon 'smbd' finished starting up and ready to serve connectionsgss_accept_sec_context failed with [ Miscellaneous failure (see text): Failed to find cifs/NAS01.gsslinc.local@GSSLINC.LOCAL(kvno 3) in keytab MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
Jun 3 14:24:25 nas01 smbd[4744]: STATUS=daemon 'smbd' finished starting up and ready to serve connectionsgss_accept_sec_context failed with [ Miscellaneous failure (see text): Failed to find cifs/NAS01.gsslinc.local@GSSLINC.LOCAL(kvno 3) in keytab MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
Jun 3 14:24:25 nas01 smbd[4745]: STATUS=daemon 'smbd' finished starting up and ready to serve connectionsgss_accept_sec_context failed with [ Miscellaneous failure (see text): Failed to find cifs/NAS01.gsslinc.local@GSSLINC.LOCAL(kvno 3) in keytab MEMORY:cifs_srv_keytab (arcfour-hmac-md5)]
Jun 3 14:24:36 nas01 smbd[4746]: STATUS=daemon 'smbd' finished starting up and ready to serve connectionsUsername GSSLINC\Administrator is invalid on this system
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
9.2.1.6 and newer have significant changes to Samba.

Honestly, I'd try reconfiguring it from scratch (maybe I'm just naïve, but I assume that the Active Directory setup makes such a thing a bit more palatable?). Maybe someone has less aggressive advice, though.
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
I'm really afraid of doing something that loses the data... We've got several TB on that share and I don't really want to have to try and restore from backup that volume. I thought when I did the upgrade that there was a 'go back to the old' option during boot, but it's not there, so I can't even go back to where I was this morning. You can imagine the wolves at my office door this afternoon since no one can get to any of their data...
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
Looks like there are permission issues with /usr/local/etc/smb4.conf. (Jun 3 15:12:05 nas01 root: /usr/local/etc/rc.d/samba_server: WARNING: /usr/local/etc/smb4.conf is not readable.) I've chmod to 777 to see if that helps...
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
Looks like there are permission issues with /usr/local/etc/smb4.conf. (Jun 3 15:12:05 nas01 root: /usr/local/etc/rc.d/samba_server: WARNING: /usr/local/etc/smb4.conf is not readable.) I've chmod to 777 to see if that helps...
Chmod doesn't work at all, starting with 9.2.1.6.

As for losing data, that won't happen. Worst case, permissions are screwed up a bit. You'll notice you're already in the worst-case scenario.
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
I'm extracting the 9.2.1.5 build to a USB drive, going to try and boot from that drive then restore the database to see if I can get back to where I was this morning. :(
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
And that didn't work... 9.2.1.5 wouldn't launch directory services and CIFS would start but couldn't be shut off. I don't remember having this much trouble when I first set this system up, or when I upgraded it to 9.2.1.5. :(

Is there any chance I can get AD working by starting from a blank slate with 9.3? There have to be people who are using it, aren't there? Or is FreeNAS only for test systems and 'it doesn't really matter if it's down for a few days' scenarios?
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
And that didn't work... 9.2.1.5 wouldn't launch directory services and CIFS would start but couldn't be shut off. I don't remember having this much trouble when I first set this system up, or when I upgraded it to 9.2.1.5. :(

Is there any chance I can get AD working by starting from a blank slate with 9.3? There have to be people who are using it, aren't there? Or is FreeNAS only for test systems and 'it doesn't really matter if it's down for a few days' scenarios?
It works, that's for sure. The problem is that you're dealing with an intersection of several things: ZFS, FreeBSD running as a sort of black box, Samba (great project, horrible documentation) and the FreeNAS middleware.

At this point, you don't really have anything to lose by trying 9.3, so give it a shot and configure it carefully according to the manual. The transition to Samba 4 in 9.2.1.6 was often problematic, but things should work better from here on.
 

billsey

Dabbler
Joined
Jun 3, 2015
Messages
36
OK, I started today by running the wizard, then reset permissions to the defaults, then noticed there was an update this morning so installed that on the 9.3 setup. Something started working again! Now I'm manually resetting permissions to what they need to be instead of the current 'Everyone' (note, defaults of AD should include Domain Admins with full permissions, or else you have to figure out how to get Windows to use the local root account). it's been a bit more than 45 minutes so far on the permissions change, but once it's done I can deal with modifying for specific folders...

Wish I knew what made it work, though I'm guessing it was the update.
 
Status
Not open for further replies.
Top