Displaying 2 results from an estimated 2 matches for "verify_pac".
2016 Dec 02
6
Samba and kerberized NFSv4
> Does it work if you manually add userPrincipalName=CLIENT02.DOMAIN.TLD to your clients ldap entry and reexport the keytab?
I already thought about trying that. So by now, I tried tweaking the client's LDAP entry.
Adding
userPrincipalName=CLIENT02.DOMAIN.TLD
does not succeeed, however, after reviewing the ldap filter once again, I added
userPrincipalName=nfs/client02.domain.tld at
2016 Dec 02
0
Samba and kerberized NFSv4
...will not be accepted (not all of the
principals require this and I'm not sure wether it was the
client or the server who needed this...).
Motivated by your mail, I'm currently trying (once again) to
get NFSv4 working with Samba DC: but for now it seems, that
there's still a bug in the verify_pac() function - at least I
could not make it work without a patch I posted 5 years ago:
https://lists.samba.org/archive/samba-technical/2011-June/078193.html
Without the patch, mount works, but as soon as a user tries to
access a directory/file access is denied with an "unknown error 22"....