similar to: [4.0] Inter-realm trust

Displaying 20 results from an estimated 5000 matches similar to: "[4.0] Inter-realm trust"

2012 Dec 21
1
[Samba4] Is VFS working in Samba 4.0.0?
Hello I'm testing Samba 4.0.0 (latest stable) as an AD DC. Here is how it was build: lvmtest samba # sbin/samba -b Samba version: 4.0.0 Build environment: Build host: Linux lvmtest 3.6.8-gentoo #3 SMP Wed Dec 5 14:27:26 CET 2012 i686 Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz GenuineIntel GNU/Linux Paths: BINDIR: /usr/local/samba/bin SBINDIR: /usr/local/samba/sbin CONFIGFILE:
2013 Feb 14
1
[Samba 4.0] Floating KVNO
Hello I'm using Samba 4.0.1 also to authenticate users via Kerberos. Once in a while however I have to regenerate a keytab, because for reasons unknown to me, the KVNO is increased by one. I'm not doing anything with an account the SPN is bound to. The KVNO seems to change automagically after few days and service cannot talk to the KDC unless I create a new keytab. What can cause the
2020 Feb 21
3
Mac OS and interpretation of @ in a username. Ex user@mds.xyz doesn't work on Mac OS but does on Win 10
On 2/21/2020 2:24 PM, Rowland penny via samba wrote: > On 21/02/2020 19:06, torch via samba wrote: >> Am I missing something?? I don?t see where you are using the ?@? >> symbol anywhere. >> Mac is probably interpreting the parameters ?valid users? and ?write >> list" (correctly, I think ;-) as a LIST of 3 users: joe, at, mds.xyz >> or bob, at, mds.xyz.
2020 Jul 24
2
samba4 kerberized nfs4 with sssd ad client
On 7/24/20 10:53 AM, Rowland penny via samba wrote: > On 24/07/2020 15:45, Jason Keltz via samba wrote: >> >> On 7/24/2020 7:25 AM, Peter Milesson via samba wrote: >>> >>> On 2020-07-24 12:57, Jason Keltz via samba wrote: >>>> Hi Rowland, >>>> >>>> In effect, I'm still using Samba on the DC, which is why I still
2020 Jul 24
2
samba4 kerberized nfs4 with sssd ad client
On 7/24/20 11:33 AM, Rowland penny via samba wrote: > On 24/07/2020 16:08, Robert Marcano via samba wrote: >> On 7/24/20 10:53 AM, Rowland penny via samba wrote: >>> On 24/07/2020 15:45, Jason Keltz via samba wrote: >>>> >>>> On 7/24/2020 7:25 AM, Peter Milesson via samba wrote: >>>>> >>>>> On 2020-07-24 12:57, Jason Keltz via
2010 Sep 28
0
cross-realm Kerberos trust with a third Windows domain
Here is our scenario. We have a Windows 2008 domain I'll call CORP and an MIT realm I'll call REALM. There is a one-way trust (AES enabled) such that users in the CORP domain can access REALM resources. If I log into a CORP workstation, I can access REALM resources as expected (including samba). We have a third Windows 2008 domain I'll call LAB. If I log into a LAB workstation
2015 Jun 30
2
gssproxy items...
Hi, I've been working on some systems trying to get kerberized nfsv4 and kerberized web services going on 7. Kerberized nfsv4 was working with 7.0, but with the 7.1 release it stopped working, the key difference between the two setups is that gssproxy wasn't being used with 7.0, but seems to be key with 7.1. The problem I am encountering with Kerberized NFSv4 is that the directory will
2020 Jul 24
1
samba4 kerberized nfs4 with sssd ad client
On 7/24/20 11:49 AM, Rowland penny via samba wrote: > On 24/07/2020 16:44, Robert Marcano via samba wrote: >> On 7/24/20 11:33 AM, Rowland penny via samba wrote: >>> On 24/07/2020 16:08, Robert Marcano via samba wrote: >>>> On 7/24/20 10:53 AM, Rowland penny via samba wrote: >>>>> On 24/07/2020 15:45, Jason Keltz via samba wrote:
2020 Feb 21
2
Mac OS and interpretation of @ in a username. Ex user@mds.xyz doesn't work on Mac OS but does on Win 10
Am I missing something? I don?t see where you are using the ?@? symbol anywhere. Mac is probably interpreting the parameters ?valid users? and ?write list" (correctly, I think ;-) as a LIST of 3 users: joe, at, mds.xyz or bob, at, mds.xyz. torch
2002 Mar 25
2
Using kerberized SSHD. Question.
I have a kerberized SSHD installed on HOST-1, a login server for the outside world. How can I make it so users are still authenticated via kerberos, even though they haven't yet received a ticket? The main reason for this is that a user who is at home, no vpn, but has an ssh client could then login and be authenticated by kerberos using password authentication, get a ticket, then be allowed
2012 Feb 20
1
Privilege Attribute Certificate (PAC) Disabled/Samba authentication
Hi, I'm currently attempting to setup a Linux Samba and Kerberized NFS server using a Windows 2008 R2 Domain controller as a KDC and I've run into an issue. Currently I can make Kerberized NFS or Samba fileserving work but not both at the same time. Specifically: The Linux kerberized NFS daemon (rpc.svcgssd) appears to only be able to deal with service tickets up to a certain size.
2019 May 13
1
Trust between Samba AD and FreeIPA Domain
Hello, maybe this is the wrong list, i don't know. But maybe somebody here can help me. I need only information about the trust between Samba AD ( Version 4.10) and FreeIPA Version 4.7 It is possible to build a trust between Samba and FreeIPA? With Samba from Fedora 30 and Ubuntu 19.04 it doesn't work, with Windows Server 2012 R2 everything was fine. If somebody here says it would work
2017 Mar 22
5
kerberized-nfs - any experts out there?
Is anyone on the list using kerberized-nfs on any kind of scale? I've been fighting with this for years. In general, when we have issues with this system, they are random and/or not repeatable. I've had very little luck with community support. I hope I don't offend by saying that! Rather, my belief is that these problems are very niche/esoteric, and so beyond the scope of typical
2001 Jul 17
2
Kerberos Books/Documents
Hey all, I've tried kerberizing SSH but I can't get it to login. I've read a lot of documentation, but I wish I could find a "cook-book" type of setup or how-to to get this beast working correctly, or to at least verify it's working per a specification. With that, I'm interested in what books/docs/etc does anyone recommend to get a good understanding of: 1.
2010 Aug 24
1
Fully kerberized mail system
Hello, Is it possible to use Dovecot in a fully kerberized mail system? We have configured authentication via kerberos, now we would like the imap deamon to access a kerberized nfs file system. Has any one any experiences? Regards, Matthew. -- Dr Matthew Williams MEng PhD MBCS Systems Administrator - IT Services - Bangor University Prifysgol Bangor Tel: (44) (0)1248 382414
2018 Jan 02
2
Legacy option for key length?
On 2 January 2018 at 17:08, Marc Haber <mh+openssh-unix-dev at zugschlus.de> wrote: > On Tue, Jan 02, 2018 at 04:03:34PM +1030, David Newall wrote: >> On 02/01/18 03:29, Michael Str?der wrote: >> > How high is the risk that this unmaintained device is added to >> > yet-another-bot-net in the Internet-of-shitty-devices or is used to >> > enter parts of your
2023 Feb 18
1
previous working smb.conf without winbind, now fails with samba 4.15.8 and winbind running
On Fri, Feb 17, 2023 at 2:29 PM Rowland Penny via samba <samba at lists.samba.org> wrote: > > > > On 17/02/2023 22:09, Bob Green via samba wrote: > > Apparently winbind is required to be running. Once winbind is running, > > samba reports failing to convert SID XXXXX to a UID. It seems samba is > > unable to offload uid/gid lookups to the kernel
2004 Mar 20
1
Not able to Map Network drive from Windows XP using Kerberized Samba 3.0
Hi all, I failed to map my network drive my,password is not accepted from windows XP using Kerberized Samba3.0. My server is Red Hat Enterprise Linux. Can some one help with the basic steps in mapping network drive from Windows XP? Or basic configuration with Kerberos 5. I am new to Kerberos 5. Zakaria __________________________________ Do you Yahoo!? Yahoo! Finance Tax Center - File
2014 Nov 25
2
TELNENT TO LOCALHOST IN CENTOS 7
On Nov 24, 2014, at 3:46 PM, Warren Young <wyml at etr-usa.com> wrote: > Now compare telnet: always vulnerable, all the time, since the day it was created, before most of the people on this list were born: Technically, you can run kerberized (krb5) telnet/telnetd, and it's not quite as insecure as unkerberized telnet. The telnet protocol supports security measures, but most people
2020 Jul 24
3
samba4 kerberized nfs4 with sssd ad client
On 7/24/2020 7:25 AM, Peter Milesson via samba wrote: > > On 2020-07-24 12:57, Jason Keltz via samba wrote: >> Hi Rowland, >> >> In effect, I'm still using Samba on the DC, which is why I still >> thought this was relevant on the mailing list. :) >> >> The reason in particular that I was looking at sssd client as opposed >> to winbind was that?