Rowland Penny
2017-Jun-30 08:49 UTC
[Samba] Samba/Kerberos setup - how to enable alternative UPN
On Fri, 30 Jun 2017 10:09:16 +0200 "Mgr. Peter Tuharsky via samba" <samba at lists.samba.org> wrote:> Hi all, > > I have W2k8 AD and I need to join Samba fileserver. > > Since I'm new to the topic, I'm following a howto, and it says I must > first make Kerberos authenticate users and only then start configuring > Samba. But I cannot get over the Kerberos setup.Care to share the link to this howto ? You do not need to set up kerberos in any meaningful way You could do worse (and you already have) than to read the Samba documentation on how to do what you are trying to do: https://wiki.samba.org/index.php/Setting_up_Samba_as_a_Domain_Member> > The domain is named like ad.domain.com but there is alternative UPN > Suffix so that users are represented by UPN such as user at domain.comDon't really understand this, you have to use the dns domain name for the realm and I don't think you can do what you are suggesting Rowland
Mgr. Peter Tuharsky
2017-Jun-30 10:59 UTC
[Samba] Samba/Kerberos setup - how to enable alternative UPN
Hi, Rowland Even in the Samba howto You posted, the Samba setup follows just after DNS, Kerberos and time setup. AFAIK they are really prerequisities for Samba to work properly in AD environment. Or can Samba authenticate a user even when Kerberos dosen't? I don't hope so. Dňa 30.06.2017 o 10:49 Rowland Penny via samba napísal(a):> On Fri, 30 Jun 2017 10:09:16 +0200 > "Mgr. Peter Tuharsky via samba" <samba at lists.samba.org> wrote: > >> Hi all, >> >> I have W2k8 AD and I need to join Samba fileserver. >> >> Since I'm new to the topic, I'm following a howto, and it says I must >> first make Kerberos authenticate users and only then start configuring >> Samba. But I cannot get over the Kerberos setup. > Care to share the link to this howto ? > > You do not need to set up kerberos in any meaningful way > > You could do worse (and you already have) than to read the Samba > documentation on how to do what you are trying to do: > > https://wiki.samba.org/index.php/Setting_up_Samba_as_a_Domain_Member > >> The domain is named like ad.domain.com but there is alternative UPN >> Suffix so that users are represented by UPN such as user at domain.com > Don't really understand this, you have to use the dns domain name for > the realm and I don't think you can do what you are suggesting > > Rowland >
Rowland Penny
2017-Jun-30 11:23 UTC
[Samba] Samba/Kerberos setup - how to enable alternative UPN
On Fri, 30 Jun 2017 12:59:56 +0200 "Mgr. Peter Tuharsky via samba" <samba at lists.samba.org> wrote:> Hi, Rowland > > Even in the Samba howto You posted, the Samba setup follows just after > DNS, Kerberos and time setup. AFAIK they are really prerequisities for > Samba to work properly in AD environment. Or can Samba authenticate a > user even when Kerberos dosen't? I don't hope so. >Yes, Samba can authenticate without kerberos, it all depends on how you configure Samba. Can you post the link to the howto you referred to, I will have a look at it and report back ;-) Rowland
Apparently Analagous Threads
- Samba/Kerberos setup - how to enable alternative UPN
- [PATCH] Re: Samba 4.1.17 classic update w/LDAP - parsing error
- [PATCH] Re: Samba 4.1.17 classic update w/LDAP - parsing error
- [PATCH] Re: Samba 4.1.17 classic update w/LDAP - parsing error
- Windows pre-requisites for login with winbind?