Mint 18.3 + Windows AD = No Login for AD users

Questions about Wi-Fi and other network devices, file sharing, firewalls, connection sharing etc
Forum rules
Before you post read how to get help. Topics in this forum are automatically closed 6 months after creation.
Locked
stm_tech

Mint 18.3 + Windows AD = No Login for AD users

Post by stm_tech »

Hi all

I have an install of 18.3 running in a VM it is Cinnamon 32bit

I have installed PBIS and joined the domain.

pbis status shows that it is all ok.

I get the following output when I type systemctl status lwsmd.service
● lwsmd.service - BeyondTrust PBIS Service Manager
Loaded: loaded (/lib/systemd/system/lwsmd.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2018-03-27 08:42:27 BST; 16min ago
Process: 1005 ExecStart=/opt/pbis/sbin/lwsmd --start-as-daemon (code=exited, status=0/SUCCESS)
Main PID: 1030 (lwsmd)
CGroup: /system.slice/lwsmd.service
├─1030 /opt/pbis/sbin/lwsmd --start-as-daemon
├─1043 lw-container lwreg
├─1061 lw-container eventlog
├─1087 lw-container netlogon
├─1108 lw-container lwio
├─1146 lw-container lsass
└─1280 lw-container reapsysl

Mar 27 08:58:02 sysadmin-virtualbox lsass[1146]: [LwKrb5GetTgtImpl /builder/src-git/Platform/src/linux/lwadvapi/threaded/krbtgt.c:346] KRB5 Error code: -1765328360 (Message: Preauthentication failed)
Mar 27 08:58:02 sysadmin-virtualbox lsass[1384]: [lsass] Error: Failed to validate restricted membership. [Error code: 40041]


pbis status output
pbis status
LSA Server Status:

Compiled daemon version: 8.6.0.427
Packaged product version: 8.6.427.243473
Uptime: 0 days 0 hours 19 minutes 6 seconds

[Authentication provider: lsa-activedirectory-provider]

Status: Online
Mode: Un-provisioned
Domain: STTHOMASMORE.LOCAL
Domain SID:
Forest: Stthomasmore.local
Site: Default-First-Site-Name
Online check interval: 300 seconds
[Trusted Domains: 2]


[Domain: STTHOMASMORE]

DNS Domain: Stthomasmore.local
Netbios name: STTHOMASMORE
Forest name: Stthomasmore.local
Trustee DNS name:
Client site name: Default-First-Site-Name
Domain SID:
Domain GUID:
Trust Flags: [0x001d]
[0x0001 - In forest]
[0x0004 - Tree root]
[0x0008 - Primary]
[0x0010 - Native]
Trust type: Up Level
Trust Attributes: [0x0000]
Trust Direction: Primary Domain
Trust Mode: In my forest Trust (MFT)
Domain flags: [0x0001]
[0x0001 - Primary]

[Domain Controller (DC) Information]

DC Name: xxx.Stthomasmore.local
DC Address: 172.16.xxx.xxx
DC Site: Default-First-Site-Name
DC Flags: [0x0000f1fd]
DC Is PDC: yes
DC is time server: yes
DC has writeable DS: yes
DC is Global Catalog: yes
DC is running KDC: yes

[Global Catalog (GC) Information]

GC Name: xxx.Stthomasmore.local
GC Address: 172.16.xxx.xxx
GC Site: Default-First-Site-Name
GC Flags: [0x0000f1fd]
GC Is PDC: yes
GC is time server: yes
GC has writeable DS: yes
GC is running KDC: yes

If I try to login with a domain user I get access denied
I have created the home directory for the user
the user is in the allowed user list
pbis authenticate-user is working fine

ANY help from this point forward would be appreciated.
Last edited by LockBot on Wed Dec 28, 2022 7:16 am, edited 1 time in total.
Reason: Topic automatically closed 6 months after creation. New replies are no longer allowed.
deepakdeshp
Level 20
Level 20
Posts: 12337
Joined: Sun Aug 09, 2015 10:00 am

Re: Mint 18.3 + Windows AD = No Login for AD users

Post by deepakdeshp »

If I have helped you solve a problem, please add [SOLVED] to your first post title, it helps other users looking for help.
Regards,
Deepak

Mint 21.1 Cinnamon 64 bit with AMD A6 / 8GB
Mint 21.1 Cinnamon AMD Ryzen3500U/8gb
Locked

Return to “Networking”