Displaying 20 results from an estimated 20000 matches similar to: "Samba 3 in MIT Kerberos Realm"
2004 Apr 10
3
Kerberos and Samba
Hi.
I've built an afs cell, a kerberos kdc, an openldap server, all
kerberized. Now all linux clients can login on the cell using k5
authentication, finding informations about their home dirs with ldap.
Their home reside on the afs cell, which allows r/w access since it
releases a token from the k5 ticket. All macosx clients can login as
well... but what about windows? ^___^;;;
2006 Jan 18
1
MIT KDC for Samba authentication?
Hi Samba Users,
I have Samba providing shares to several XP clients. The clients
currently authenticate using private/smbpasswd. I do not have an Active
Directory server nor any Windows servers.
I also have an MIT KDC. Various services have been Kerberised including
SSH (proper GSSAPI negotiation) and Apache (Basic auth). This is all
functioning correctly. The Apache login and SSH logins from
2004 Jan 26
5
Samba 3.0.2 and Windows 2003 ADS.
Hi.
I have installed samba 3.0.2 in my redhat 7.3, and Kerberos 1.2.4
I can make my Linux act as ADS Domain Membership whit out any problem,
When I made this command:
/usr/local/samba/bin/net ads join "Computers" -U<usuario>%<clave>
I get this message that tell me that everything is ok.
Using short domain name -- DOMAIN2003
Joined 'PROTON' to realm
2003 Oct 12
1
Samba 3.0 as NT4 PDC with MIT kerberos 1.3 (v5) for authentication?
Hi All-
Please pardon my repost of my usenet article in this list.
Previously, I asked if Samba 3.0 could be an Active Directory Domain
Controller (ADDC). I have the feeling that the answer is no. If so, then
I have this other question:
Can I use Samba as an NT4 PDC for making a Windows NT4 domain that
would host several M$ Windows XPP client computers as domain
clients/members, but have
2003 Jul 01
1
Printer driver upload from WindowsXP is broken since 3.0alpha22
Recently i've moved to samba 3.0 beta1 and noticed, that drivers for shared
printers couldn't be uploaded from WindowsXP GUI any more. After copying
files to \\smbserver\print$\W32X86 folders it says something like "Unable to
install HP LaserJet 2100 PCL6, Windows2000 or XP, Intel driver. Operation
could not be completed".
It works OK on samba3.0alpha20, but doesn't work
2005 Mar 02
1
MIT Kerberos tickets gone..
I have the following scenario.
Windows 2K Active Dir server, Samba 3.0.7 running on Solaris 2.8.
Running MIT Kerberos to join and authenticate with the AD. Things work ok,
can join the domain, and can access the samba server from trusted domains as
well as local domain.
However, when doing 'kinit' I have found that the default ticket life was
for 24 hours is seemed. After I reboot
2008 Nov 05
1
Samba, Solaris, Windows 2008 - Kerberos Guess Realm Wrong?
I've just built Samba 3.2.4 on Solaris 10, with ADS support. Domain join
to a Windows 2008 domain works perfectly, having pre-created the
servername in the appropriate OU.
In my winbind logs, I see the following (domain name obfuscated):
[2008/11/05 11:28:06, 3]
libsmb/cliconnect.c:cli_session_setup_spnego(839)
got principal=not_defined_in_RFC4178@please_ignore
[2008/11/05 11:28:06,
2025 Apr 09
1
Samba 4.2.15 and MIT Kerberos External Authentication
>
> It sounded like you had set up Samba as an AD DC using MIT instead of
> Hiemdal until here, now I am not so sure. It sounds like you have an
> existing Kerberos realm and you are trying to get a Samba AD DC to auth
> from that, if that is the case, then that is not how you are supposed
> to do it.
>
> If you want to see how to set up a DC with MIT, then the easiest way
2004 Mar 11
1
Samba File Server - AD-MIT KDC Trust
Hi,
I have a large client who has an MIT Kerberos realm set up. According
to MS guidelines, they have also set up a one way trust between their
AD domain and their MIT realm so that their users could continue using
their MIT kerberos login and password to access kerberized services on
their network. Essentially, users log into their PCs using their MIT
names/passwords but can access
2016 Aug 16
1
Possible to use MIT Kerberos yet?
Hey all,
$Dayjob currently uses MIT Kerberos. We also use Zimbra with Kerberos
auth, but Zimbra's LDAP is only internal to itself.
I see various things on the wiki that say "We need MIT Kerberos support
cleaned up for a 4.0 release"
https://wiki.samba.org/index.php/MIT_Build
https://wiki.samba.org/index.php/Samba4/MIT_KDC
And the "How to build a domain controller"
2018 Aug 31
1
migrate from existing MIT kerberos / openldap
Dear all,
is it possible to migrate from an existing MIT kerberos / openldap setup
to samba AD? We can re-create the accounts through a script, but it
would be nice to be able to keep passwords for users and machine
accounts / keytabs which are in our existing KDC. Thanks for any insights,
Christian
2019 Jan 10
1
Realm trust between Samba AD and MIT kerberos realm
Hi all,
I was hoping to setup a realm trust between a Samba AD domain and a
kerberos realm running mit-krb5, however it looks like that isn't
currently supported. Is that correct, or am I missing something (I'm
running Samba 4.9.4)?
Having noticed that "samba-tool domain trust" only seems to cater for
trusts involving other AD domains, I tried to workaround that (in the
2020 Oct 01
2
Kerberos ticket lifetime
On 01/10/2020 00:23, Jason Keltz via samba wrote:
>
> Remy,
>
> On the domain controller (samba-ad-dc), I have in the config: kdc:user
> ticket lifetime = 24
I do not recognise that smb.conf option, could this be another freebsd
change that was never sent upstream or, if it was, it was rejected ?
>
> When I login to the client (which is using pam_winbind module), I have
2002 Dec 16
1
samba 2.2.7 & MIT Kerberos 1.2.6
Hi,
I'm new to this list so I apologise if this has been asked before.
I'm trying to compile samba 2.2.7 with kerberos support. I have MIT
Kerberos 1.2.6 installed and working as a KDC but when I samba wont compile
with
--with-krb5 configure works ok and finds the kerberos install but when I do
a make I get this error on linking smbd:
/usr/local/lib/libkadm5srv.so: undefined reference
2020 Sep 30
3
Kerberos ticket lifetime
> On 30 Sep 2020, at 21:42, Jason Keltz via samba <samba at lists.samba.org> wrote:
>
>
> On 9/30/2020 3:01 PM, Remy Zandwijk via samba wrote:
>>>>> On the client, add:
>>>>>
>>>>> gensec_gssapi:requested_life_time = <int> # seconds
>>>>>
>>>>> to smb4.conf. E.g. a ticket life time of one hour:
2025 Apr 09
1
Samba 4.2.15 and MIT Kerberos External Authentication
>>* The local on
*>>* site domain is a realm that has a list of usernames and samba
*>>* accounts but authentication is off loaded onto an external realm and
*>>* there is a one way trust relationship where the local samba server
*>>* trusts the external realm -- all that is required is that there is a
*>>* local username and username map on local samba server.
2007 Oct 12
2
default kerberos realm??
Hello list,
I am trying to join a win2k domain with Samba, with security = ads. My
member server is a Debian Etch. I get the following error when trying
to join the domain:
#net ads join -U administrator
administrator's password:
[2007/10/12 12:04:19, 0] libsmb/cliconnect.c:cli_session_setup_spnego(785)
--
Frank Van Damme A: Because it destroys the flow of the conversation
2023 Apr 14
2
Is LDAP + Kerberos without Active Directory no longer supported?
On 14/04/2023 17:48, Daniel Lakeland via samba wrote:
> On 4/14/23 09:16, Rowland Penny via samba wrote:
>>
>>
>> This intrigued me, so I went and tried this and you need three computers:
>>
>> A samba AD DC (perhaps a computer just running a KDC, but I didn't try
>> this)
>> A Samba Unix domain member running as a fileserver
>> A Samba
2004 Oct 11
6
NT4 RAS Dial-in with Samba 3 PDC
Hi,
I am searching for information on how to set up an NT4 RAS server to
authenticate users against a Samba 3 PDC. Right now we have 2 domain
controllers and the plan is to phase them out. We want to set up samba
as the PDC, but we need RAS to work for the time being. Is there a way
to do this? We are going to use the LDAP backend for samba. Is it
also possible to have our NT4 BDC stay
2003 May 20
1
Kerberos TGT support in Samba 3.0
Hi,
What is/will be the support for Kerberos TGT tickets in Samba 3.0 ?
I am trying to find a way to authenticate users on both Windows and unix
stations against the same KDC (MIT) and it would help if Samba was able to
grant access based on TGT tickets delivered to the windows client and then
deliver accounting information to the stations.
I am afraid this follow no standart protocol, but i