Guro

Forum Replies Created

Viewing 15 posts - 1 through 15 (of 45 total)
  • Author
    Posts
  • in reply to: SSO between Enterprise Client and ECS #52358
    Guro
    Contributor

    Hello
    please send server and client side logs of kerberos errors to as for more detailed test.

    Usually problems relate to correct configuration. as alternate you can try use ssh connection protocol,

    please don’t forget enable EnableNXKerberosAuthentication 1, on server configure file.

    As you also have smartcard/PIN authentication, you also can extract public key from smartcard and register on server side as authorized_keys. for more details might be in:

    https://kb.nomachine.com/DT11R00187

    Thanks

    in reply to: SSO between Enterprise Client and ECS #52234
    Guro
    Contributor

    Hello

    there is no need for krb5 files. If you have kerberos ticket for windows, you can use select prefered library ‘Microsoft SSPI’ and if your user has kerberos ticket after Windows login, then this ticket might be used by NoMachine,

    thanks

    in reply to: SSO between Enterprise Client and ECS #52062
    Guro
    Contributor

    hello

    “Authentication is done with a smartcard and a PIN or a user/password pair in an Active Directory.

    ECS is connected to the same AD, I can get a ticket with kinit for my user/password.”

    We can recommend use kerberos authentication as client and server host in same ad domain.

    You need enable kerberos authentication on server by edit /usr/NX/etc/server.cfg and update keys

    #EnableNXKerberosAuthentication 0

    to

    EnableNXKerberosAuthentication 1

    Please ensure that AD user is correctly seen on server host:

    if commands: id ,  getent passwd | grep , su

    correctly list/switch on user. More details for kerberos authentication are available in https://kb.nomachine.com/DT07S00230

    Thanks

    in reply to: Cannot authorise changes in Settings #51366
    Guro
    Contributor

    Hello,
    please send nomachine server side logs to us. You can extract them using the instructions here: https://kb.nomachine.com/DT07S00243. Send them to forum[at]nomachine[dot]com. Please use the title of this topic as the subject of your email.

     

    Guro
    Contributor

    Also could you provide result of next command in administrator rights power shell window, please:
    net localgroup Administrators

    We need to be sure that nx user in Administrators groups as we suspect. Logs show:

    “6120 29444 2024-10-23 22:35:30 674.235 ImpersonationWorker: ERROR! Failed to launch nxserver process.

    6120 66060 2024-10-25 10:34:10 075.469 ExecuteServer: ERROR! Failed to duplicate input.

    6120 66060 2024-10-25 10:34:10 075.469 ExecuteServer: Error is ‘6’.”
    might be related.

    Guro
    Contributor

    hello

    Did you update Windows before noticing the fail on server side?

     

     

    in reply to: Can’t log into Win 11 PC from Mac, but can do reverse #50039
    Guro
    Contributor

    It’s also useful to know whether user Emile is a user of domain or windows AD?

    in reply to: Yubikey support #49683
    Guro
    Contributor

    hello

    “If there are no security risks to installing the debug package, then I’m happy for you to send it to me and use it.” –  It’s safe to install and use. It’s a regular package with extra debug enabled to allow us to go much deeper into why a particular error is happening so they will contain information about exchange protocol flow data, ssh key fingerprints and accepted encryption methods.

    ” Is the ssh tunnelling method I mentioned earlier in this thread sensible?” – Yes it is. You can see details here: https://kb.nomachine.com/AR10K00728

    “Is there a way to make the connection more stable with this approach?” – I think the session freeze needs further investigation. First, can you send us server side logs? Logs would also allow us to check why the connection is failing without an appropriate error even without adding yubikey as a device. You can extract them using the instructions here: https://kb.nomachine.com/DT07S00243.

    Send them to forum[at]nomachine[dot]com. Please use the title of this topic as the subject of your email. Thanks!

    in reply to: Yubikey support #49659
    Guro
    Contributor

    Hello

    Please could you provide exact information of NoMachine server you are trying to connect to?
    The free NoMachine version does not support SSH connections.

    Thanks

    in reply to: Yubikey support #49618
    Guro
    Contributor

    Hello

    To be able to provide more advises there is need to have more detailed log data. As for security reason, authentication logs are disabled by default.
    But if you are willing to install new debug package on your working machine and test the authentication process to provide us more detailed information about this error, we can send you a debug package.

    Thanks

    in reply to: Yubikey support #49604
    Guro
    Contributor

    hello

    As you use -i option for ssh to point to private key in system path, then you could point same path in the connection > ‘Use key-based authentication with a key you provided’.

    Does your advice still apply in that case?” – yes. Check key real path after modify player.cfg and set

     

    thanks

    in reply to: Yubikey support #49485
    Guro
    Contributor

    Hello

    ssh -I /pathtokeyfile

    Usually -I uses to access to pkcs11 module. For Yubico probably it should be libykcs11.dylib.

    If yes then you can use path to module in section “Use key-based authentication with PKCS11 smart card”,

    “Set an alternate security module”. there you can select absolute path to libykcs11.dylib.

    By default path might look like /usr/local/lib/libykcs11.dylib.

    If connection still fails, then please leave all settings as it but close all nomachine windows.

    Edit ~/.nx/config/player.cfg

    find line:

    <option key=”SSH client mode” value=”library” />

    and replace “library” to “native” like:

    <option key=”SSH client mode” value=”native” />

    also check if
    <option key=”SSH Client” value=”/usr/local/bin/ssh” />

    contain valid path to default ssh client. Finish and save edit content.

    Open nomachine windows again and do SSH protocol connection by smart card.

    Please inform as if it will helps and report errors if some appears.

    in reply to: Yubikey support #49441
    Guro
    Contributor

    Hello,

    My keys are resident keys stored on the Yubikey. I do have the public keys in ~/.ssh/authorized_keys on the server I’m trying to access.” – it looks good.

    Could you please provide us the command of poor ssh you use to login to the server (hiding all sensitive data)?

    Thanks

    in reply to: Reset Windows 11 #49407
    Guro
    Contributor

    Regarding the logs, we notice that you try to install NoMachine on the D:\ disk space, instead of the default C:\Program Files.

    Have you tested to install on the default path to compare the result?

    And is the D: space a real local disk partition, or some network drive mounted with some service?

    in reply to: Reset Windows 11 #49406
    Guro
    Contributor

    Hello Practice,

    Please also provide us the Windows build version: open the power shell and run the command
    winver
    It would be useful for us to have a screenshot of the appearing window (but with your private data censored).

Viewing 15 posts - 1 through 15 (of 45 total)