Advertisement
Guest User

Untitled

a guest
Jan 9th, 2023
56
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 17.44 KB | None | 0 0
  1. (2023-01-05 14:50:55): [krb5_child[22845]] [main] (0x0400): krb5_child started.
  2. (2023-01-05 14:50:55): [krb5_child[22845]] [unpack_buffer] (0x1000): total buffer size: [152]
  3. (2023-01-05 14:50:55): [krb5_child[22845]] [unpack_buffer] (0x0100): cmd [249] uid [438200029] gid [438200029] validate [true] enterprise principal [false] offline [false] UPN [daazeez@domain.COM]
  4. (2023-01-05 14:50:55): [krb5_child[22845]] [unpack_buffer] (0x0100): ccname: [KEYRING:persistent:438200029] old_ccname: [KEYRING:persistent:438200029] keytab: [/etc/krb5.keytab]
  5. (2023-01-05 14:50:55): [krb5_child[22845]] [k5c_setup_fast] (0x0100): Fast principal is set to [host/e-recondbtest.domain.com@domain.COM]
  6. (2023-01-05 14:50:55): [krb5_child[22845]] [find_principal_in_keytab] (0x4000): Trying to find principal host/e-recondbtest.domain.com@domain.COM in keytab.
  7. (2023-01-05 14:50:55): [krb5_child[22845]] [match_principal] (0x1000): Principal matched to the sample (host/e-recondbtest.domain.com@domain.COM).
  8. (2023-01-05 14:50:55): [krb5_child[22845]] [check_fast_ccache] (0x0200): FAST TGT is still valid.
  9. (2023-01-05 14:50:55): [krb5_child[22845]] [become_user] (0x0200): Trying to become user [438200029][438200029].
  10. (2023-01-05 14:50:55): [krb5_child[22845]] [main] (0x2000): Running as [438200029][438200029].
  11. (2023-01-05 14:50:55): [krb5_child[22845]] [set_lifetime_options] (0x0100): No specific renewable lifetime requested.
  12. (2023-01-05 14:50:55): [krb5_child[22845]] [set_lifetime_options] (0x0100): No specific lifetime requested.
  13. (2023-01-05 14:50:55): [krb5_child[22845]] [set_canonicalize_option] (0x0100): Canonicalization is set to [true]
  14. (2023-01-05 14:50:55): [krb5_child[22845]] [main] (0x0400): Will perform pre-auth
  15. (2023-01-05 14:50:55): [krb5_child[22845]] [tgt_req_child] (0x1000): Attempting to get a TGT
  16. (2023-01-05 14:50:55): [krb5_child[22845]] [get_and_save_tgt] (0x0400): Attempting kinit for realm [domain.COM]
  17. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259255: Getting initial credentials for daazeez@domain.COM
  18.  
  19. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259256: FAST armor ccache: MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  20.  
  21. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259257: Retrieving host/e-recondbtest.domain.com@domain.COM -> krb5_ccache_conf_data/fast_avail/krbtgt\/domain.COM\@
  22. domain.COM@X-CACHECONF: from MEMORY:/var/lib/sss/db/fast_ccache_domain.COM with result: -1765328243/Matching credential not found
  23.  
  24. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259259: Sending unauthenticated request
  25.  
  26. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259260: Sending request (183 bytes) to domain.COM
  27.  
  28. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259261: Initiating TCP connection to stream 10.10.20.180:88
  29.  
  30. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259262: Sending TCP request to stream 10.10.20.180:88
  31.  
  32. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259263: Received answer (487 bytes) from stream 10.10.20.180:88
  33.  
  34. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259264: Terminating TCP connection to stream 10.10.20.180:88
  35.  
  36. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259265: Response was from master KDC
  37.  
  38. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259266: Received error from KDC: -1765328359/Additional pre-authentication required
  39.  
  40. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259267: Upgrading to FAST due to presence of PA_FX_FAST in reply
  41.  
  42. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259268: FAST armor ccache: MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  43.  
  44. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259269: Retrieving host/e-recondbtest.domain.com@domain.COM -> krb5_ccache_conf_data/fast_avail/krbtgt\/domain.COM\@
  45. domain.COM@X-CACHECONF: from MEMORY:/var/lib/sss/db/fast_ccache_domain.COM with result: -1765328243/Matching credential not found
  46.  
  47. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259270: Getting credentials host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM using cca
  48. che MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  49.  
  50. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259271: Retrieving host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM from MEMORY:/var/l
  51. ib/sss/db/fast_ccache_domain.COM with result: 0/Success
  52.  
  53. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259272: Armor ccache sesion key: aes256-cts/D6D9
  54.  
  55. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259274: Creating authenticator for host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM, s
  56. eqnum 0, subkey aes256-cts/81ED, session key aes256-cts/D6D9
  57.  
  58. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259276: FAST armor key: aes256-cts/6E04
  59.  
  60. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259278: Sending unauthenticated request
  61.  
  62. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259279: Encoding request body and padata into FAST request
  63.  
  64. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259280: Sending request (2180 bytes) to domain.COM
  65.  
  66. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259281: Initiating TCP connection to stream 10.10.20.180:88
  67.  
  68. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259282: Sending TCP request to stream 10.10.20.180:88
  69.  
  70. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259283: Received answer (161 bytes) from stream 10.10.20.180:88
  71.  
  72. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259284: Terminating TCP connection to stream 10.10.20.180:88
  73.  
  74. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259285: Response was from master KDC
  75.  
  76. (2023-01-05 14:50:55): [krb5_child[22845]] [sss_child_krb5_trace_cb] (0x4000): [22845] 1672926655.259286: Received error from KDC: -1765328347/Clock skew too great
  77.  
  78. (2023-01-05 14:50:55): [krb5_child[22845]] [get_and_save_tgt] (0x0400): krb5_get_init_creds_password returned [-1765328347] during pre-auth.
  79. (2023-01-05 14:50:55): [krb5_child[22845]] [k5c_send_data] (0x0200): Received error code 0
  80. (2023-01-05 14:50:55): [krb5_child[22845]] [pack_response_packet] (0x2000): response packet size: [4]
  81. (2023-01-05 14:50:55): [krb5_child[22845]] [k5c_send_data] (0x4000): Response sent.
  82. (2023-01-05 14:50:55): [krb5_child[22845]] [main] (0x0400): krb5_child completed successfully
  83. (2023-01-05 14:50:58): [krb5_child[22846]] [main] (0x0400): krb5_child started.
  84. (2023-01-05 14:50:58): [krb5_child[22846]] [unpack_buffer] (0x1000): total buffer size: [165]
  85. (2023-01-05 14:50:58): [krb5_child[22846]] [unpack_buffer] (0x0100): cmd [241] uid [438200029] gid [438200029] validate [true] enterprise principal [false] offline [false] UPN [daazeez@domain.COM]
  86. (2023-01-05 14:50:58): [krb5_child[22846]] [unpack_buffer] (0x0100): ccname: [KEYRING:persistent:438200029] old_ccname: [KEYRING:persistent:438200029] keytab: [/etc/krb5.keytab]
  87. (2023-01-05 14:50:58): [krb5_child[22846]] [switch_creds] (0x0200): Switch user to [438200029][438200029].
  88. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_krb5_cc_verify_ccache] (0x2000): TGT not found or expired.
  89. (2023-01-05 14:50:58): [krb5_child[22846]] [switch_creds] (0x0200): Switch user to [0][0].
  90. (2023-01-05 14:50:58): [krb5_child[22846]] [k5c_check_old_ccache] (0x4000): Ccache_file is [KEYRING:persistent:438200029] and is not active and TGT is valid.
  91. (2023-01-05 14:50:58): [krb5_child[22846]] [k5c_precreate_ccache] (0x4000): Recreating ccache
  92. (2023-01-05 14:50:58): [krb5_child[22846]] [k5c_setup_fast] (0x0100): Fast principal is set to [host/e-recondbtest.domain.com@domain.COM]
  93. (2023-01-05 14:50:58): [krb5_child[22846]] [find_principal_in_keytab] (0x4000): Trying to find principal host/e-recondbtest.domain.com@domain.COM in keytab.
  94. (2023-01-05 14:50:58): [krb5_child[22846]] [match_principal] (0x1000): Principal matched to the sample (host/e-recondbtest.domain.com@domain.COM).
  95. (2023-01-05 14:50:58): [krb5_child[22846]] [check_fast_ccache] (0x0200): FAST TGT is still valid.
  96. (2023-01-05 14:50:58): [krb5_child[22846]] [become_user] (0x0200): Trying to become user [438200029][438200029].
  97. (2023-01-05 14:50:58): [krb5_child[22846]] [main] (0x2000): Running as [438200029][438200029].
  98. (2023-01-05 14:50:58): [krb5_child[22846]] [set_lifetime_options] (0x0100): No specific renewable lifetime requested.
  99. (2023-01-05 14:50:58): [krb5_child[22846]] [set_lifetime_options] (0x0100): No specific lifetime requested.
  100. (2023-01-05 14:50:58): [krb5_child[22846]] [set_canonicalize_option] (0x0100): Canonicalization is set to [true]
  101. (2023-01-05 14:50:58): [krb5_child[22846]] [main] (0x0400): Will perform online auth
  102. (2023-01-05 14:50:58): [krb5_child[22846]] [tgt_req_child] (0x1000): Attempting to get a TGT
  103. (2023-01-05 14:50:58): [krb5_child[22846]] [get_and_save_tgt] (0x0400): Attempting kinit for realm [domain.COM]
  104. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890073: Getting initial credentials for daazeez@domain.COM
  105.  
  106. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890074: FAST armor ccache: MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  107.  
  108. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890075: Retrieving host/e-recondbtest.domain.com@domain.COM -> krb5_ccache_conf_data/fast_avail/krbtgt\/domain.COM\@
  109. domain.COM@X-CACHECONF: from MEMORY:/var/lib/sss/db/fast_ccache_domain.COM with result: -1765328243/Matching credential not found
  110.  
  111. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890077: Sending unauthenticated request
  112.  
  113. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890078: Sending request (183 bytes) to domain.COM
  114.  
  115. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890079: Initiating TCP connection to stream 10.10.20.180:88
  116.  
  117. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890080: Sending TCP request to stream 10.10.20.180:88
  118.  
  119. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890081: Received answer (487 bytes) from stream 10.10.20.180:88
  120.  
  121. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890082: Terminating TCP connection to stream 10.10.20.180:88
  122.  
  123. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890083: Response was from master KDC
  124.  
  125. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890084: Received error from KDC: -1765328359/Additional pre-authentication required
  126.  
  127. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890085: Upgrading to FAST due to presence of PA_FX_FAST in reply
  128.  
  129. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890086: FAST armor ccache: MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  130.  
  131. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890087: Retrieving host/e-recondbtest.domain.com@domain.COM -> krb5_ccache_conf_data/fast_avail/krbtgt\/domain.COM\@
  132. domain.COM@X-CACHECONF: from MEMORY:/var/lib/sss/db/fast_ccache_domain.COM with result: -1765328243/Matching credential not found
  133.  
  134. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890088: Getting credentials host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM using cca
  135. che MEMORY:/var/lib/sss/db/fast_ccache_domain.COM
  136.  
  137. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890089: Retrieving host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM from MEMORY:/var/l
  138. ib/sss/db/fast_ccache_domain.COM with result: 0/Success
  139.  
  140. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890090: Armor ccache sesion key: aes256-cts/D6D9
  141.  
  142. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890092: Creating authenticator for host/e-recondbtest.domain.com@domain.COM -> krbtgt/domain.COM@domain.COM, s
  143. eqnum 0, subkey aes256-cts/01AC, session key aes256-cts/D6D9
  144.  
  145. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890094: FAST armor key: aes256-cts/B88C
  146.  
  147. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890096: Sending unauthenticated request
  148.  
  149. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890097: Encoding request body and padata into FAST request
  150.  
  151. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890098: Sending request (2180 bytes) to domain.COM
  152.  
  153. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890099: Initiating TCP connection to stream 10.10.20.180:88
  154.  
  155. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890100: Sending TCP request to stream 10.10.20.180:88
  156.  
  157. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890101: Received answer (161 bytes) from stream 10.10.20.180:88
  158.  
  159. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890102: Terminating TCP connection to stream 10.10.20.180:88
  160.  
  161. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890103: Response was from master KDC
  162.  
  163. (2023-01-05 14:50:58): [krb5_child[22846]] [sss_child_krb5_trace_cb] (0x4000): [22846] 1672926658.890104: Received error from KDC: -1765328347/Clock skew too great
  164.  
  165. (2023-01-05 14:50:58): [krb5_child[22846]] [get_and_save_tgt] (0x0020): 1709: [-1765328347][Clock skew too great]
  166. (2023-01-05 14:50:58): [krb5_child[22846]] [map_krb5_error] (0x0020): 1838: [-1765328347][Clock skew too great]
  167. (2023-01-05 14:50:58): [krb5_child[22846]] [k5c_send_data] (0x0200): Received error code 1432158229
  168. (2023-01-05 14:50:58): [krb5_child[22846]] [pack_response_packet] (0x2000): response packet size: [4]
  169. (2023-01-05 14:50:58): [krb5_child[22846]] [k5c_send_data] (0x4000): Response sent.
  170. (2023-01-05 14:50:58): [krb5_child[22846]] [main] (0x0400): krb5_child completed successfully
  171. (2023-01-05 14:50:58): [krb5_child[22847]] [main] (0x0400): krb5_child started.
  172. (2023-01-05 14:50:58): [krb5_child[22847]] [unpack_buffer] (0x1000): total buffer size: [165]
  173. (2023-01-05 14:50:58): [krb5_child[22847]] [unpack_buffer] (0x0100): cmd [241] uid [438200029] gid [438200029] validate [true] enterprise principal [false] offline [true] UPN [daazeez@domain.COM]
  174. (2023-01-05 14:50:58): [krb5_child[22847]] [unpack_buffer] (0x0100): ccname: [KEYRING:persistent:438200029] old_ccname: [KEYRING:persistent:438200029] keytab: [/etc/krb5.keytab]
  175. (2023-01-05 14:50:58): [krb5_child[22847]] [switch_creds] (0x0200): Switch user to [438200029][438200029].
  176. (2023-01-05 14:50:58): [krb5_child[22847]] [sss_krb5_cc_verify_ccache] (0x2000): TGT not found or expired.
  177. (2023-01-05 14:50:58): [krb5_child[22847]] [switch_creds] (0x0200): Switch user to [0][0].
  178. (2023-01-05 14:50:58): [krb5_child[22847]] [k5c_check_old_ccache] (0x4000): Ccache_file is [KEYRING:persistent:438200029] and is not active and TGT is valid.
  179. (2023-01-05 14:50:58): [krb5_child[22847]] [become_user] (0x0200): Trying to become user [438200029][438200029].
  180. (2023-01-05 14:50:58): [krb5_child[22847]] [main] (0x2000): Running as [438200029][438200029].
  181. (2023-01-05 14:50:58): [krb5_child[22847]] [set_lifetime_options] (0x0100): No specific renewable lifetime requested.
  182. (2023-01-05 14:50:58): [krb5_child[22847]] [set_lifetime_options] (0x0100): No specific lifetime requested.
  183. (2023-01-05 14:50:58): [krb5_child[22847]] [main] (0x0400): Will perform offline auth
  184. (2023-01-05 14:50:58): [krb5_child[22847]] [create_empty_ccache] (0x1000): Existing ccache still valid, reusing
  185. (2023-01-05 14:50:58): [krb5_child[22847]] [k5c_send_data] (0x0200): Received error code 0
  186. (2023-01-05 14:50:58): [krb5_child[22847]] [pack_response_packet] (0x2000): response packet size: [52]
  187. (2023-01-05 14:50:58): [krb5_child[22847]] [k5c_send_data] (0x4000): Response sent.
  188. (2023-01-05 14:50:58): [krb5_child[22847]] [main] (0x0400): krb5_child completed successfully
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement