Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MSLogon problem after new Windows updates #108

Open
adamcios opened this issue Sep 10, 2023 · 17 comments
Open

MSLogon problem after new Windows updates #108

adamcios opened this issue Sep 10, 2023 · 17 comments
Assignees
Labels
Author Ticket author answer is needed

Comments

@adamcios
Copy link

Mslogon and MSlogonII stop working on 22h2 Windows 10 version after new windows Updates (
When i try to use MSLogonACL.exe and import file which i used in last years
File to import mslogon_AD_default.ini
mslogon_AD_default.ini
allow 0x00000003 .\adminek
allow 0x00000003 ..\VNCEdit
allow 0x00000001 ..\VNCView

i get such info:
"C:\Program Files\uvnc bvba\UltraVNC\MSLogonACL.exe" /i /o "C:\Program Files\uvnc bvba\UltraVNC\mslogon_AD_default.ini"
Detected computername = KOMP3
account: KOMP3\adminek, mask: 3, type: allow
Detected domain = XXXXX
XXXXX\VNCEdit: SID not valid.
Detected domain = XXXXX
XXXXX\VNCView: SID not valid.
RegSetValueEx passed
deleting ACE_DATA linked lists

I try to check mslogon and mslogonII and i get such info in logs
Password authentication accepted from 192.168.12.1 (Interactive) (ID:1)
MSLogon authentication refused from 192.168.12.1 using XXXXX\vncadmin account (not authenticated)
Password authentication accepted from 192.168.12.1 (Interactive) (ID:1)
MSLogon authentication refused from 192.168.12.1 using vncadmin@xxxxx.lan account (not authenticated)

I checked everything I could and the result is still the same. Any suggestions?
oooo one more thing when i deinstall windows update
KB5028244
KB5028166
KB5028412
KB5027937
If KB5028244 is not installed, uninstall KB5028166
In some cases, if that doesn't work, you need to uninstall KB5028412 , KB5027937
But this is not a solution

@Neustradamus
Copy link

@RudiDeVos: Have you seen the @adamcios ticket?

@Neustradamus Neustradamus added the Rudi Rudi answer is needed label Sep 13, 2023
@Neustradamus Neustradamus added the Urgency Urgency label Sep 15, 2023
@RudiDeVos
Copy link
Member

Not a simple one..takes time

@RudiDeVos
Copy link
Member

RudiDeVos commented Sep 17, 2023

What do you see when you open "configure MS Logon Groups"
afbeelding

Doe you see the groups
Are you able to set slect them

In my case, when i don't have ..\VNCEdit i get the same error (SID not valid)

@adamcios
Copy link
Author

adamcios commented Sep 18, 2023

yes i can select groups and i see it but cant connect

@adamcios
Copy link
Author

one more thing. after last patch thuesday from september KB5030211 put the same changes like patches before and this should be uninstalled either.

@RudiDeVos
Copy link
Member

settings AD server/client to be able to test, to see if i can repeat it

@RudiDeVos
Copy link
Member

afbeelding
afbeelding

mslogon
21/09/2023 11:18:46 MSLogon authentication accepted from 127.0.0.1 using vnc@rudidom.local account (ViewOnly)
21/09/2023 11:18:50 Client 127.0.0.1 using vnc@rudidom.local account disconnected (ViewOnly) (ID:1)
authSSP

  • CUPSD2: Access is 1, user vnc@rudidom.local is authenticated, access granted is 0x1

First test on Windows Server 2022 Standard 21H2 seems to work, that was expected

@RudiDeVos
Copy link
Member

RudiDeVos commented Sep 21, 2023

testing on a 22H
Import works, connection works
Thu Sep 21 11:48:47 2023

  • CUPSD2: Access is 1, user vnc@rudidom.local is authenticated, access granted is 0x3
    21/09/2023 11:48:47 MSLogon authentication accepted from 127.0.0.1 using vnc@rudidom.local account (Interactive)

Need help...how do i get the updates installed while the PC and server say there is no update available.
Can't repeat it

afbeelding
afbeelding
afbeelding

@RudiDeVos
Copy link
Member

Updating AD server, to KB5030216 to test again

@RudiDeVos
Copy link
Member

RudiDeVos commented Sep 23, 2023

Last test, updated a win10 22H2
OS
afbeelding

Updates
afbeelding

Connection still working
23/09/2023 19:40:16 MSLogon authentication accepted from 127.0.0.1 using vnc@rudidom.local account (Interactive)

Running out of test, can't repeat it

@adamcios
Copy link
Author

adamcios commented Sep 25, 2023

its important that i have AD on SAMBA linux 4.17? And second it stop works on windows 10/11 workstation. We have more then 150 computers.

@RudiDeVos
Copy link
Member

ya... SAMBA you should have told this from te beginning.
Samba and 22H2 is a hell a lot of nas server had problems with 22H2.

Make sure you have the latest samba server, was fixed or should be in 4.17.4.

@adamcios
Copy link
Author

adamcios commented Sep 26, 2023

one server is
Version 4.17.4-Debian
i willl try to upgrade it to 4.17.10 version the newest in 4.17
but in other place i have Version 4.17.8-Debian

@Neustradamus
Copy link

@adamcios: look here:

Important to know that Microsoft has solved several vulnerabilities this summer and there were problems with very old Linux machines which are not up-to-date...

@Neustradamus Neustradamus added Author Ticket author answer is needed and removed Rudi Rudi answer is needed Urgency Urgency labels Sep 26, 2023
@Neustradamus
Copy link

@adamcios: Have you updated your machines?

@adamcios
Copy link
Author

i can do it in service time. so i can check one entity probably in few days. now i have version 4.17.8

@Neustradamus
Copy link

@adamcios: Samba versions have somes fixes in:

Can you try a good version?

Source:

Debian ticket:

Samba+:

And you can see Debian packages for each Debian versions:

Note there are new versions since, at this time:

  • 4.17.12 (2023-10-10)
  • 4.18.8 (2023-10-10)
  • 4.19.2 (2023-10-16)

Samba latest news:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Author Ticket author answer is needed
Development

No branches or pull requests

3 participants