Login issue on Windows XP, connecting to 10.4

I'm having a bit of a frusteration with my Windows XP system (as if that's a big suprise). I'm trying to connect to my mac mini via SMB and I'm getting the usual Windows logon box. I type a valid login and it pops back up with the the local computer name prefixed to the username. ie "WINDOWS\macuser" I don't think this is an issue with the mac itself, but with some stupid Windows network setting. Has anyone had this particular issue before? I didn't have it with my laptop but I sent that away for repair yesterday.

Mac Mini 1.42 Combo (Apple Certified Refurbished), Mac OS X (10.4.5)

Posted on Feb 23, 2006 5:48 PM

Reply
57 replies

Mar 19, 2006 3:55 AM in response to KingDaveRa

That's fairly simple. Easier than going the other way. Turn on Windows Sharing and Personal File Sharing in the Sharing pane of System Prefs . If the Windows user has the same username as the Mac user, he sees the entire home folder. If not, he sees the Shared folder. If you want to do more than that, get Sharepoints <http://www.versiontracker.com/dyn/moreinfo/macosx/12512> and set the share to whatever you want.

Of course, you do have to make sure that your Mac is in the proper Workgroup and on the proper subnet.

Let's see... go to System Preferences. Select Sharing. Turn on Personal File Sharing. Turn on Windows Sharing. Verify that there are now holes in the firewall. Go to WinBox. Go to My Network Places. Gen a new network place. There's my home folder. Log in. Enter Mac password, Win password is different. If Win password and Mac password are the same, don't have to enter password. Logged into the home folder. That took even less time than had connecting the other way.

If it doesn't Just Work™, it's likely that there's a config error somewhere.

Mar 19, 2006 5:21 AM in response to Charles Dyer

All that stuff is enabled.

I enabled logging level 2 in smb.conf

If i try and log into the share from my windows box, I get this:

[2006/03/19 13:14:49, 1] auth ods.c:opendirectory_smb_pwd_checkntlmv1(371)
opendirectory smb_pwd_checkntlmv1: [-14200]opendirectory user_auth_and_sessionkey key_length(0)
[2006/03/19 13:14:49, 2] /SourceCache/samba/samba-92.17/samba/source/auth/auth.c:check ntlmpassword(367)
check ntlmpassword: Authentication for user [dave] -> [dave] FAILED with error NT STATUS_WRONGPASSWORD

My short username is dave, and is enabled to connect. The password is set. If I try and change the password with smbpassd, I get:

Gordon:~ dave$ smbpasswd
Old SMB password:
New SMB password:
Retype new SMB password:
machine 127.0.0.1 rejected the (anonymous) password change: Error was : Wrong Password.
Failed to change password for dave

So I try it as root:

Gordon:/Users/dave root# smbpasswd dave
New SMB password:
Retype new SMB password:
[-14200]add recordattributes: authenticate_node error
odssam update_samaccount: [-14200]add recordattributes
Failed to modify entry for user dave.
Failed to modify password entry for user dave

So something is wrong.

I noticed that /private/var/db/samba/secrets.tdb hasn't changed since the 14th March, which is about when I got this Mac Mini. Obviously something isn't changing the file properly. Either way, it's not happy.

Mar 19, 2006 5:56 AM in response to KingDaveRa

I went to my local Apple Store and try to talk to a Genius about this, but the line was 6 hours long and when an Apple associate tried to ask a quick question for me, he got his head bit off. SO . . . I went over to a new G5 and tried to log in to my computer. I could get in using AFS to my whole user, not the Public Folder using Guest. I got a 550 error that the user was unknown. Of course the user is unknown, it's a Guest. Using \\xxx.xxx.xxx.xxx in Virtual PC - Windows XP, once again with my personal login, the whole user with one share (SharePoints), but not the Public Folder, same error. It seems that the process for the extreme will work in part, but not the basic access to the Public Folder as it has in previous OS's. The "something that is wrong" is really wrong and there is no reason for it. It's as if we're being locked out without a reason or explanation. It's just not working as Apple advertises.

Now to go from the Mac to a PC - No Problem. I get everything from a single click on an icon that I have placed in the Dock. One click and the volume mounts, a window opens and I have all access. At one point you could go from your machine back in to your machine using AFS. Now I get the login, do it, get window with all volumes listed, choose volume, click connect, remote volume icon pops up on desktop, window opens, system freezes requiring a hard reset. I use to do this successfully all the time, guiding myself, as I would walk others through the process over the phone. ALSO . . . in OS9 when networking several machines on a LAN, I would forget what machine I was on and log back into myself, get a listing of the volumes and mount any of them successfully. Now, no go. Apple . . . ?

Mar 19, 2006 6:05 AM in response to KingDaveRa

All that stuff is enabled.

I enabled logging level 2 in smb.conf

If i try and log into the share from my windows box,
I get this:

[2006/03/19 13:14:49, 1]
auth ods.c:opendirectory_smb_pwd_checkntlmv1(371)
opendirectory smb_pwd_checkntlmv1:
[-14200]opendirectory user_auth_and_sessionkey
key_length(0)
2006/03/19 13:14:49, 2]
/SourceCache/samba/samba-92.17/samba/source/auth/auth.
c:check ntlmpassword(367)
check ntlmpassword: Authentication for user
[dave] -> [dave] FAILED with error
NT STATUS_WRONGPASSWORD


Well... someone doesn't like your password.

My short username is dave, and is enabled to connect.
The password is set. If I try and change the password
with smbpassd, I get:

Gordon:~ dave$ smbpasswd
Old SMB password:
New SMB password:
Retype new SMB password:
machine 127.0.0.1 rejected the (anonymous) password
change: Error was : Wrong Password.
Failed to change password for dave


Okay, someone really doesn't like your password.

So I try it as root:

Gordon:/Users/dave root# smbpasswd dave
New SMB password:
Retype new SMB password:
[-14200]add recordattributes: authenticate_node
error
odssam update_samaccount:
[-14200]add recordattributes
Failed to modify entry for user dave.
Failed to modify password entry for user dave

So something is wrong.

I noticed that /private/var/db/samba/secrets.tdb
hasn't changed since the 14th March, which is about
when I got this Mac Mini. Obviously something isn't
changing the file properly. Either way, it's not
happy.


have you tried one of the clear cache/fix low-level stuff utilities, such as Onyx? Have you tried looking at the file in question and checking its permissions and its read/write status? How about the folder that it's in, and the folder that the folder is in, an so on? Can you delete the file and start from scratch? (Be really careful how you try that last one...) I once had a problem with the System Update log file: it wouldn't update, which, among other things, meant that every time SU ran it thought that I had a boatload of updates to run. I finally had to boot into root, kill that file, boot back into my normal user, and run SU one more time. Things were fixed. It might be as simple as deleting the offending file.

Mar 19, 2006 1:14 PM in response to TheGuyintheProjectionBooth

Just wanted to add my name to the list of people experiencing this problem - Mac Mini Core Duo in this case.

I should have searched more carefully before I posted - but full details here:

http://discussions.apple.com/thread.jspa?threadID=408626&tstart=0

One question: is there any way that we can be sure that this bug is on Apple's list of items to fix in the next release? Some kind of Bugzilla, perhaps? It's going to be pretty frustrating if 10.4.6 arrives and the problem still exists!

Chippy

Mar 19, 2006 8:18 PM in response to ChippyAft

I've solved my problem. (from the original post) I forgot that in 10.4 you have to enable SMB sharing, and then per user. I didn't set up the account I was trying to connect to when I set the computer up, so it seems like an obvious oversight. I realized that I'd been able to connect to one account from my laptop, but not the other.

Once I enabled SMB sharing for my account, I could connect to it from the laptop, but still not from my desktop. After a limited amount of cursing, I realized that my Windows XP user account on the desktop did not have a password. I added a password to the account and presto it works properly. Unfortunately it's working properly, and that means one less excuse to "need" a MacBook Pro 12" if/when they appear.

So in short, this is what I did in order to make things work.
1. Opened Sharing, selected Windows Sharing, clicked Accounts, enabled desired user accounts on Mac.
2. Added a password to Windows XP user account.
3. Connected to Mac from Windows box.

I hope this works for you Intel mini owners. I'm able to connect to my 20" Intel iMac at work through SMB on my laptop.

Mar 19, 2006 9:32 PM in response to rsolberg

Well good for you. It's good to see something working for some. And I mean for some. There are those of us that have been all through this and it still won't work.

But be warned. The glory may not be long lived. Enjoy it while you can.

Take Care.

P.S.
If you solve your own question can you give yourself the points? What if I'm also helpful?

Mar 20, 2006 10:20 AM in response to TheGuyintheProjectionBooth

What about me?! Mine certainly still doesn't work. The windows user has no bearing on the remote connection. If my local Username doesn't exist on the remote PC (i.e. the Mac Mini), then Windows will prompt for another username, which mine does. On any other samba setup I've had, I simply enter server\username and my password and it logs in. This isn't happening. The logs show samba thinks my password is wrong when it isn't, or at least, shouldn't be. I can't help but think the control panel app is not setting the samba password, but rather than saying it's failing it's not catching the error.

I'm going to try renaming the secrets file and see if that helps though. It looks like something has locked the file, or at least caused it issues.

Mar 24, 2006 5:53 PM in response to rsolberg

Ok folks...

This is a POSSIBLE EXPLAINATION... not a solution, though...
I own an iMac 17" intel and a MacMini intel core solo (as in my sig).
Both run on 10.4.5 preinstalled (of course) and have all the software updates dutifully applied (so far).
I look at Directory Access and I see:
iMac services -->
Active Directory 1.5.3
BSD FF and NIS 1.2.1
LDAPv3 1.7.3

MacMini services -->
Active Directory 1.5.4
BSD FF and NIS 1.2.2
LDAPv3 1.7.4

so THERE IS A DIFFERENCE IN SOME KEY PART OF THE NETWORK SERVICES!!!
I don't have a cure for this except trying to "downgrade" services on my MacMini, but I'd really prefer 10.4.6 to fix this!

Of course, accessing Windows Sharing from my Window$ box (XPSP2 Home) FAILS on the Mini while SUCCEDING on the iMac (not to mention the Powerbook...).

If I've been able to hint someone on this matter, feel free to evolve and expand this issue...

Andrea

Powerbook 15" (G4), iMac 17" (intel) & mini (intel) Mac OS X (10.4.5)

Mar 25, 2006 9:53 AM in response to rsolberg

I have a PPC Mac Mini (10.4.5) and Windows XP. After reading this thread I tried to get XP to mount the Mini drive using samba and it works fine. I can also mount the Windows shares from the Mini with no problem.

I have encrypted passwords turned off on samba

The only thing I had to do was open Windows sharing on the Mac firewall and enter a registry setting on XP telling it to allow unencrypted passwords.

[HKEY LOCALMACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkStation\Parameters]
"EnablePlainTextPassword"=dword:00000001

Also there is one other thing I have seen get in the way of Windows -> samba mounting (if using encrypted passwords). On XP under local security policies/Local security settings I have to set set Lan Manager authentication level to "send LM and NTLM responses"

My smb.conf file is pretty standard...

[global]
guest account = unknown
encrypt passwords = no
auth methods = guest opendirectory
passdb backend = opendirectorysam guest
printer admin = @admin, @staff
server string = surge-mini
unix charset = UTF-8-MAC
display charset = UTF-8-MAC
dos charset = 437
client ntlmv2 auth = no
defer sharing violations = no
use spnego = yes
os level = 8
vfs objects = darwin_acls
brlm = yes
security=user
workgroup = Workgroup
; Using the Computer Name to compute the NetBIOS name. Remove this comment to override
netbios name = surge-mini
[homes]
comment = User Home Directories
browseable = no
read only = no

[root]
path = /
public = yes
only guest = yes
writable = yes
printable = no

[printers]
path = /tmp
printable = yes

Hope this is useful...









Mar 25, 2006 12:07 PM in response to MoeBeans

It's a temporary workaround, but not really a 'fix' as such. Using plain passwords is a bad idea, especially on a big network. Even on my local LAN I don't like doing it and use encryption where I can; I can SSH and use SFTP to the Mac Mini, so I should be able to use the most secure SMB method possible.

Obviously, Apple have broken the encryption method for storing passwords, and Samba can't get them back out of the directory. Having said that, I even tried using a plain smbpasswd file, but that didn't work. I think this is going to require a patch.

Mar 26, 2006 11:17 AM in response to KingDaveRa

I agree totally, I thought he said he wanted to use unencrypted passwords. Must have misread.

I am actually using encrypted passwords with XP mounting the samba share on the Mac Mini as we speak. Works fine (and its a lot faster response from the server than using unencrypted). Not sure what the issue is with the Intel boxes but my PPC is working as it should.

Mac Mini Mac OS X (10.4.5) 1G RAM 90G Momentus 7200 HD 1.4GHz





This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Login issue on Windows XP, connecting to 10.4

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.