<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de-AT">
	<id>http://niki.hammler.net/w/index.php?action=history&amp;feed=atom&amp;title=Zarafa_ntlm_auth_problems</id>
	<title>Zarafa ntlm auth problems - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="http://niki.hammler.net/w/index.php?action=history&amp;feed=atom&amp;title=Zarafa_ntlm_auth_problems"/>
	<link rel="alternate" type="text/html" href="http://niki.hammler.net/w/index.php?title=Zarafa_ntlm_auth_problems&amp;action=history"/>
	<updated>2026-05-12T16:56:34Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in NOBAQ</subtitle>
	<generator>MediaWiki 1.35.13</generator>
	<entry>
		<id>http://niki.hammler.net/w/index.php?title=Zarafa_ntlm_auth_problems&amp;diff=1375&amp;oldid=prev</id>
		<title>Niki: Die Seite wurde neu angelegt: „One time, the SSO (Single Sign On) on my Zarafa server stopped working. The one thing I could find in the logs was:   Sam 24 Mär 2012 16:49:19 CET: Received erro…“</title>
		<link rel="alternate" type="text/html" href="http://niki.hammler.net/w/index.php?title=Zarafa_ntlm_auth_problems&amp;diff=1375&amp;oldid=prev"/>
		<updated>2012-03-30T17:33:14Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „One time, the SSO (Single Sign On) on my Zarafa server stopped working. The one thing I could find in the logs was:   Sam 24 Mär 2012 16:49:19 CET: Received erro…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;One time, the SSO (Single Sign On) on my Zarafa server stopped working. The one thing I could find in the logs was:&lt;br /&gt;
&lt;br /&gt;
 Sam 24 Mär 2012 16:49:19 CET: Received error from ntlm_auth:&lt;br /&gt;
 [2012/03/24 16:49:19.094636,  3] libsmb/ntlmssp.c:65(debug_ntlmssp_flags)&lt;br /&gt;
   Got NTLMSSP neg_flags=0xe20882b7&lt;br /&gt;
&lt;br /&gt;
 Sam 24 Mär 2012 16:49:19 CET: Authentication by plugin failed for user niki: Trying to authenticate failed: Disallowing NULL password for user   uid=niki,ou=int,ou=users,dc=intra,dc=nobaq,dc=net; username = niki&lt;br /&gt;
 Sam 24 Mär 2012 16:49:19 CET: Failed to authenticate user niki from 93.83.102.173 using program rundll32.exe&lt;br /&gt;
&lt;br /&gt;
NTLM itself is working:&lt;br /&gt;
&lt;br /&gt;
 ntlm_auth --username=niki&lt;br /&gt;
 password:&lt;br /&gt;
 NT_STATUS_OK: Success (0x0)&lt;br /&gt;
&lt;br /&gt;
Also, the permissions to winbindd_privileged, as required for the ntlmssp helper protocol are fine:&lt;br /&gt;
&lt;br /&gt;
 stat /var/run/samba/winbindd_privileged&lt;br /&gt;
   File: „/var/run/samba/winbindd_privileged“&lt;br /&gt;
   Size: 4096            Blocks: 8          IO Block: 4096   Verzeichnis&lt;br /&gt;
 Device: 12h/18d Inode: 3040278     Links: 2&lt;br /&gt;
 Access: (0750/drwxr-x---)  Uid: (    0/    root)   Gid: (  109/winbindd_priv)&lt;br /&gt;
 Access: 2012-03-29 20:18:43.000000000 +0200&lt;br /&gt;
 Modify: 2012-03-29 20:19:02.000000000 +0200&lt;br /&gt;
 Change: 2012-03-29 20:19:02.000000000 +0200&lt;br /&gt;
&lt;br /&gt;
The sources show that Zarafa calls the following command:&lt;br /&gt;
&lt;br /&gt;
 ntlm_auth -d0 --helper-protocol=squid-2.5-ntlmssp&lt;br /&gt;
&lt;br /&gt;
Using squid-2.5-ntlmssp requires a special protocol:&lt;br /&gt;
&lt;br /&gt;
 YR ...&lt;br /&gt;
&lt;br /&gt;
then the binary should respond:&lt;br /&gt;
&lt;br /&gt;
 TT ....&lt;br /&gt;
&lt;br /&gt;
However, with a higher log level in smb.conf, debug messages could be printed to stdout:&lt;br /&gt;
&lt;br /&gt;
 [2012/03/24 16:49:19.094636,  3] libsmb/ntlmssp.c:65(debug_ntlmssp_flags)&lt;br /&gt;
   Got NTLMSSP neg_flags=0xe20882b7&lt;br /&gt;
 TT ....&lt;br /&gt;
&lt;br /&gt;
Zarafa is does not expect this and terminates the session. As a conclusion,&lt;br /&gt;
&lt;br /&gt;
 log level = 2&lt;br /&gt;
&lt;br /&gt;
in /etc/smb.conf solves the issue whereas &amp;quot;log level = 3&amp;quot; is too much.&lt;/div&gt;</summary>
		<author><name>Niki</name></author>
	</entry>
</feed>