On Wed, 2022-08-03 at 08:05 +0100, Rowland Penny via samba
wrote:> On Wed, 2022-08-03 at 09:50 +0300, Sami Hulkko via samba wrote:
> > Hi,
> >
> > The information on Samba Wiki for MIT Kerberos related fork is from
> > 4.7.
> > Is there anywhere information available for the current status?
>
> It isn't really a fork, it is just a different way of configuring the
> build and, while there have been a few updates, using a MIT based
> Samba
> DC is still considered experimental. Do not use one in production,
> only
> use one for testing purposes.
>
> Rowland
While the above is our correct official statement (and covers in
particular how much promise we give on any security issues, because
some of those have to be fixed in both places which is difficult),
since the efforts over Dec->Feb this year, things are much
better.
Extensive testsuites were written and they mostly pass, so there can be
some increased comfort if MIT Kerberos is an organisational
requirement.
There is no RODC support in the MIT KDC.
Andrew Bartlett
--
Andrew Bartlett (he/him) https://samba.org/~abartlet/
Samba Team Member (since 2001) https://samba.org
Samba Team Lead, Catalyst IT https://catalyst.net.nz/services/samba
Samba Development and Support, Catalyst IT - Expert Open Source
Solutions