LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 07-02-2023, 04:39 PM   #1
simple40
LQ Newbie
 
Registered: Jul 2023
Posts: 3

Rep: Reputation: 0
SAMBA with FIPS


Good Morning,

I have enabled FIPS within my RHEL 8.8 box that is acting as a Standalone server. However when I enabled FIPS the Windows 10 and Windows 11 clients lose access to the Samba server. The error log shows "Failed to start SPNEGO handler for negprot OID list" each time. If I disabled FIPS then all works just fine but in my environment FIPS has to be enabled.

In addition I have tried multiple settings within the smb.conf to hard set SMB3/NTLMv2 but all result in the same thing. Has anyone gotten Samba working with FIPS enabled acting as a Standalone server? if so can you assist me with getting this working.

Thanks for your time
 
Old 07-02-2023, 08:03 PM   #2
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
I know little about using FIPS, but is it enabled on the Windows clients?
 
Old 07-02-2023, 09:13 PM   #3
simple40
LQ Newbie
 
Registered: Jul 2023
Posts: 3

Original Poster
Rep: Reputation: 0
Samba and FIPS

The windows clients have fips enabled as well
 
Old 07-02-2023, 09:42 PM   #4
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
Maybe share the working server smb.conf as well.
 
Old 07-02-2023, 10:06 PM   #5
simple40
LQ Newbie
 
Registered: Jul 2023
Posts: 3

Original Poster
Rep: Reputation: 0
Thumbs up SAMBA with FIPS

Here is what I have under global

[global]
workgroup = SAMBA
security = user
passdb backend = tdbsam
server min protocol = SMB3
server max protocol = SMB3_11
ntlm auth = ntlmv2-only
log file = /var/log/samba/test.log
log level = 10
server signing = mandatory
server smb3 signing algorithms = AES-128-GMAC, AES-128-CMAC


printing = cups
printcap name = cups
load printers = yes
cups options = raw


When the Windows Clients connects I get this error " Failed to start SPNEGO handler for negprot OID list"

If I turn FIPS off the clients can connect with no issues...it is only when I have FIPS enabled does it break. I have to take out server signing = mandatory and server smb3 signing algorithms but it still does the same thing and throws the same error.
 
Old 07-03-2023, 08:01 PM   #6
ferrari
LQ Guru
 
Registered: Sep 2003
Location: Auckland, NZ
Distribution: openSUSE Leap
Posts: 5,834

Rep: Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148Reputation: 1148
You might try liaising with the samba devs....
https://www.samba.org/samba/support/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fips abzs Linux - Software 0 09-06-2001 12:48 PM
after defrag, fips only frees 78MB from Win98se, but 2.17GB are available on HD pjs2550 Linux - Software 6 08-17-2001 02:15 PM
FIPS-HELLLLPPPP!!! tim1 Linux - Software 0 05-07-2001 06:16 AM
fips help devarapalli_s Linux - Software 1 03-11-2001 05:28 PM
Using Fips cnirrad Linux - Software 0 03-03-2001 04:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 03:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration