[Bug 1357471] Re: Samba4 AD DC randomly dies, error: "Did not manage to negotiate mandetory feature SIGN for dcerpc auth_level 6".

Jorge Albarenque jorgito1412 at gmail.com
Mon Jul 27 13:03:27 UTC 2015


I can confirm that applying the patch provided in
https://bugzilla.samba.org/show_bug.cgi?id=11164 does not fix the issue.

The "Did not manage to negotiate..." error message is gone but the other
message "Failed to bind..." still spams the logs and replication is
broken as per "samba-tool drs showrepl".

I can also confirm that what triggers this are network connectivity
interruptions between the DCs. After connectivity is restored,
replication is not reestablished until Samba is restarted

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to samba in Ubuntu.
https://bugs.launchpad.net/bugs/1357471

Title:
  Samba4 AD DC randomly dies, error: "Did not manage to negotiate
  mandetory feature SIGN for dcerpc auth_level 6".

Status in samba package in Ubuntu:
  Confirmed

Bug description:
  Hello!

  I'm using Samba4 AD DC, from Ubuntu 14.04.1, it works almost
  flawlessly but, almost everyday, it dies.

  The error log begins to show:

  "Did not manage to negotiate mandetory feature SIGN for dcerpc
  auth_level 6"

  Then, the replication stops working, the domain stops responding and
  Windows guests do not authenticate, it becomes really messy.

  Here is the workaround:

  ---
  rm /var/log/samba/* ; service samba-ad-dc restart
  ---

  More info:

  https://lists.samba.org/archive/samba/2014-May/181193.html

  Issue: "samba" process uses excessive CPU time and generates high IO Wait. log.samba has many entries stating "Did not manage to negotiate mandetory feature SIGN for dcerpc":
  http://ghanima.net/doku.php?id=wiki:ghanima:healthandsecurity:samba4

  Thanks!
  Thiago

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1357471/+subscriptions



More information about the foundations-bugs mailing list