Displaying 6 results from an estimated 6 matches for "globdomus".
Did you mean:
globdomuser
2017 Aug 22
3
Winbind with krb5auth for trust users
Hi,
I'm having trouble realizing a krb5auth with pam_winbind with trusted
domain users (external trust) on our clients. The client is joined to a
local domain, which has a "external trust" to a global domain.
The following things are working for all users (local and trusted domain):
"wbinfo -i"
"wbinfo --pam-logon"
"wbinfo -a"
"kinit"
2017 Aug 22
2
Winbind with krb5auth for trust users
...in) running on Windows Server
> 2012. The client is running on OpenSUSE Leap 42.3. The samba
> version is 4.6.5.
>
> Right now I'm a step before nfs. At first I just want to
> authorize users with krb5auth.
>
> The error is:
>
> mlrlinux:~ # wbinfo -K GLOBALDOM\\globdomuser Enter
> GLOBALDOM\globdomuser's password:
> plaintext kerberos password authentication for
> [GLOBALDOM\globdomuser] failed (requesting cctype: FILE)
> wbcLogonUser(GLOBALDOM\globdomuser): error code was
> NT_STATUS_NO_LOGON_SERVERS (0xc000005e) error message was: No
> l...
2017 Aug 22
0
Winbind with krb5auth for trust users
...>> 2012. The client is running on OpenSUSE Leap 42.3. The samba
>> version is 4.6.5.
>>
>> Right now I'm a step before nfs. At first I just want to
>> authorize users with krb5auth.
>>
>> The error is:
>>
>> mlrlinux:~ # wbinfo -K GLOBALDOM\\globdomuser Enter
>> GLOBALDOM\globdomuser's password:
>> plaintext kerberos password authentication for
>> [GLOBALDOM\globdomuser] failed (requesting cctype: FILE)
>> wbcLogonUser(GLOBALDOM\globdomuser): error code was
>> NT_STATUS_NO_LOGON_SERVERS (0xc000005e) error messag...
2017 Aug 22
2
Winbind with krb5auth for trust users
...is the
proxy for the auth process. In case of "wbinfo -K" all communication is
between the client and a trusted domain controller and the client do not
have any rights/credentials there. Perhaps, that's way I'm getting a
No logon servers Could not authenticate user [GLOBALDOM\globdomuser]
with Kerberos
error message.
Regards,
Andreas
Am 22.08.2017 um 14:30 schrieb Andreas Hauffe via samba:
> Hi,
>
> I already added the two lines in smb.conf for my last test.
>
> Andreas
>
> [global]
> security = ADS
> workgroup = LOC
> realm...
2017 Aug 22
0
Winbind with krb5auth for trust users
...auth process. In case of "wbinfo -K" all
> communication is between the client and a trusted domain controller
> and the client do not have any rights/credentials there. Perhaps,
> that's way I'm getting a
>
> No logon servers Could not authenticate user [GLOBALDOM\globdomuser]
> with Kerberos
>
Ah, I do not think that Samba supports one way trusts (yet)
Rowland
2017 Aug 22
2
Winbind with krb5auth for trust users
On Tue, 22 Aug 2017 13:51:24 +0200
Andreas Hauffe via samba <samba at lists.samba.org> wrote:
> Hi,
>
> sorry for not reading the comment above idmap config. I uninstalled
> and reinstalled samba and configs to remove all old id mappings and
> so on. Then changed all configs as adviced. The id mapping is working
> correctly (wbinfo -i) for local and trusted domain. But I