Koozali.org: home of the SME Server

Domain login broken after - windows update KB5028166

Offline tdbsoft

  • *
  • 81
  • +0/-0
    • http://www.tdb.com.au
Domain login broken after - windows update KB5028166
« on: July 12, 2023, 04:28:01 AM »
Hi everyone,

I just wanted to report it seems windows update KB5028166 has completely broken domain login on SME 10.1 as well as the older SME 9.2.

It seems once the update is applied. you will get a trust relationship error when logging in on your windows 10 computers.

In our case i was able to roll-back KB5028166 and hide the update with a tool. but i was wondering if anyone else has experienced this problem? and know of a better long-term fix.

I tried the following...
*Re-applying Registry fixes
*Updating SME 10.1 to latest Samba packages
*restarts of both SME 10.1 and windows clients

I know the list is bit lean - unfortunately we working a few different issues currently. but i will try some more items when we get a chance

Offline bunkobugsy

  • *
  • 263
  • +4/-0
Re: Domain login broken after - windows update KB5028166
« Reply #1 on: July 12, 2023, 09:09:32 AM »
For Windows 11 remove and block KB 5028185. Wonder if this can be worked around with a registry patch.

Having no network connection to PDC seems to allow logins for the moment. (aka pull the network cable to login)

https://support.microsoft.com/en-us/topic/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25#one-5021130
« Last Edit: July 12, 2023, 09:31:07 AM by bunkobugsy »

Offline nicolatiana

  • ****
  • 721
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #2 on: July 12, 2023, 09:34:20 AM »
+1


I join to the party: received alreadry three calls from customers  :(
Consulente di Smeserver.it -  Soluzioni e supporto su Sme server in Italia.

Offline jayraym

  • 8
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #3 on: July 12, 2023, 09:40:31 AM »
same here. Will test to remove KB5028166

Offline cno

  • *
  • 35
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #4 on: July 12, 2023, 09:50:21 AM »
same here

what i did
rebooted in safe mode
removed last quality update

hold shift while restarting >advanced > and remove last quality update when done “continue to windows
........................

Offline bunkobugsy

  • *
  • 263
  • +4/-0
Re: Domain login broken after - windows update KB5028166
« Reply #5 on: July 12, 2023, 09:54:05 AM »
Can be checked by signing in to Windows under the local administrator account, start the PowerShell console,
and run the   Test-ComputerSecureChannel -Verbose    cmdlet.

Offline nicolatiana

  • ****
  • 721
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #6 on: July 12, 2023, 10:02:11 AM »
Tested on W11: removed KB5028185 and then disabled with wushowhide.diagcab

https://www.tenforums.com/tutorials/8280-hide-show-windows-updates-windows-10-a.html


The tool is warned as "deprecated" but is still working for both 10 and 11.
After hidding I've forced an update and KB5028185 was not retrieved.
« Last Edit: July 12, 2023, 10:20:10 AM by nicolatiana »
Consulente di Smeserver.it -  Soluzioni e supporto su Sme server in Italia.

Offline jayraym

  • 8
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #7 on: July 12, 2023, 10:24:05 AM »
Yep, looks like it's the KB5028185 that needs to be removed, it worked for me.
I'm new to Linux/Samba/Koozali so I have a question: how does it usually work? Does a patch comes out fairly quickly or something like that? No one wants to block windows security updates for too long obviously.

Offline nicolatiana

  • ****
  • 721
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #8 on: July 12, 2023, 10:45:26 AM »
Should we open a bug on BT ?
Consulente di Smeserver.it -  Soluzioni e supporto su Sme server in Italia.

Offline nicolatiana

  • ****
  • 721
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #9 on: July 12, 2023, 10:50:21 AM »
Server side it was:
[2023/07/12 03:37:19.106022,  0] rpc_server/netlogon/srv_netlog_nt.c:976(_netr_ServerAuthenticate3)
  _netr_ServerAuthenticate3: netlogon_creds_server_check failed. Rejecting auth request from client PIGRECO-42 machine account PIGRECO-42$
[2023/07/12 03:37:19.121343,  0] rpc_server/srv_pipe.c:1925(api_rpcTNP)
  api_rpcTNP: \netlogon: NETR_LOGONGETCAPABILITIES failed.
Consulente di Smeserver.it -  Soluzioni e supporto su Sme server in Italia.



Offline ReetP

  • *
  • 3,703
  • +5/-0
Re: Domain login broken after - windows update KB5028166
« Reply #12 on: July 12, 2023, 04:53:31 PM »
Should we open a bug on BT ?

You can, and add notes there.

Note this too - not sure if we need to modify Samba settings.

https://access.redhat.com/security/cve/cve-2022-38023
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline john56

  • ***
  • 143
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #13 on: July 12, 2023, 07:03:29 PM »
have we to do it ? add this to smb.conf ?
Code: [Select]
reject md5 clients = yes

Offline nicolatiana

  • ****
  • 721
  • +0/-0
Re: Domain login broken after - windows update KB5028166
« Reply #14 on: July 12, 2023, 07:14:30 PM »
This is from the Samba mailing list:
Quote
"I am not convinced this is a Samba problem. It could be that Samba isn't providing something that Windows now expects, or Samba is providing something that Windows doesn't expect, but I think it is more likely that it has something to do with the 130 CVE's that Microsoft shipped yesterday:
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul
It wouldn't be the first time Microsoft broke something while fixing something else.
By all means open a bug report, Samba may need to change something to get things working again, but it will probably require level 10 logs and network traces to workout just what is going on."
Consulente di Smeserver.it -  Soluzioni e supporto su Sme server in Italia.