Displaying 20 results from an estimated 600 matches similar to: "Configure Samba 3 to auth off a MIT KDC."
2010 May 04
0
Query re winbind, primary group enumeration from Active Directory and Services For Unix
Query re winbind, primary group enumeration from Active Directory and Services For Unix
I am wondering if anyone can explain to me how the GIDs work when using winbind to extract them from an ADS server.
I have Unix servers running AIX 5.3 ML-10, an ADS server running Win 2003-SP2 with SFU 3.5 installed.
I have been configuring the Unix servers as domain members and using winbind to extract the
2004 Sep 27
3
winbind still asks for password
Hello Brent,
I'm writing in regards to the thread you opened @ samba.org
concerning authenticating users against AD using winbind. Did you need
to manipulate the PAM modules? Currently when I run wbinfo -t I get
secret is good, and when I run wbinfo -u I get a list of all users but I
can't get SAMBA to accept my domain users.
Regards,
Jesse
2018 Feb 07
1
Samba Migration and AD integration
On Wed, 7 Feb 2018 10:02:10 +0000
Praveen Ghimire <PGhimire at sundata.com.au> wrote:
> Hi Rowland,
>
> Following the
> https://wiki.samba.org/index.php/Changing_the_DNS_Back_End_of_a_Samba_AD_DC,
> ran some tests migrating from Bind9 to Samba Internal with the
> following results
>
> Stopped the BIND, Samba-AD-DC services
>
> samba_upgradedns
2004 Mar 11
1
Samba File Server - AD-MIT KDC Trust
Hi,
I have a large client who has an MIT Kerberos realm set up. According
to MS guidelines, they have also set up a one way trust between their
AD domain and their MIT realm so that their users could continue using
their MIT kerberos login and password to access kerberized services on
their network. Essentially, users log into their PCs using their MIT
names/passwords but can access
2004 Oct 25
1
OpenSSH/Heimdal/MIT KDC problem/question
Hi,
I'm running OpenSSH 3.8 & 3.9, compiled against Heimdal 0.6.3 for it's
GSSAPI & AFS integration.
A couple weeks ago, we upgraded our MIT KDC from (ugh) Kerberos 5 1.0.6
to the lastest and greatest 1.3.5. However, it seems that as part of
the upgrade, our GSSAPI credentials passing in OpenSSH stopped working.
Actually, didn't completely stop... You can still do a
2003 Jan 24
1
Samba 3, Win2K, and MIT KDC -- possible?
After setting up Samba 3 I noticed the Windows 2000 box was
requesting a ticket from the KDC for HOST/<NETBIOS NAME>@MYREALM.COM
when it tried to connect to the Samba server. I presume that W2K is
sending the ticket it is granted along to the Samba server. If that
presumption is correct, is it possible to make Samba authenticate the
user with the Kerberos ticket they present? If so, how
2006 Jan 18
1
MIT KDC for Samba authentication?
Hi Samba Users,
I have Samba providing shares to several XP clients. The clients
currently authenticate using private/smbpasswd. I do not have an Active
Directory server nor any Windows servers.
I also have an MIT KDC. Various services have been Kerberised including
SSH (proper GSSAPI negotiation) and Apache (Basic auth). This is all
functioning correctly. The Apache login and SSH logins from
2003 Jun 20
1
Error "Could not fetch trust account password" in Samba 3 Beta..what do I need to do?
Specifics samba-3.0.0beta1-1.i386.rpm on RedHat 9 and smbpasswd
authentication, the machine is the PDC and security is set for user. The
machine account was setup on the fly and it appears in passwd, shadow, and
smbpasswd files as it should. However it seemed to take a very long time to
join the domain, about 1-1/2 minutes. I can browse the Samba PDC machine
and access the shares, etc. After
2013 Oct 01
1
How to configure statistics tracking
I'm trying to configure the dovecot statistics tracking option with Dovecot 2.1.12 on FreeBSD 9.1-RELEASE.
I've seen on the wiki page the configuration settings needed for this but it does not say which configuration file these settings should be added to.
http://wiki2.dovecot.org/Statistics
I was hoping someone could tell me which file these settings should be added to? Do they all
2018 Feb 07
0
Samba Migration and AD integration
Hi Rowland,
Following the https://wiki.samba.org/index.php/Changing_the_DNS_Back_End_of_a_Samba_AD_DC, ran some tests migrating from Bind9 to Samba Internal with the following results
Stopped the BIND, Samba-AD-DC services
samba_upgradedns --dns-backend=SAMBA_INTERNAL
Reading domain information
DNS accounts already exist
Reading records from zone file
2005 Aug 05
2
samba with NTLM *and* kerberos authentication
We have an existing samba server with many userids, using NTLM
authentication (stored in OpenLDAP). We would like to add many other
userids, which will authenticate against an existing MIT kerberos server.
Each of our customers will have either an NTLM-based userid/password, or
a kerberos-based userid/password, but never both.
We would like both kinds of userids to work with the same samba
2008 Feb 12
1
RE: Delegation of authentication (S4U) and SAMBA
Hello,
Does samba support the use of S4U?
What do we need to configure in SAMBA or krb5 to support getting a
ticket obtained by S4U. We are using 3.0.25 and krb5-1.4.1
We are getting the following error:
decode_pac_data: Name in PAC [username@something1.something2.realmname]
does not match principal name in ticket
The ticket could be different than the PAC name because the
2016 Mar 28
0
no logon server
No takers thus far. These are the Samba 4.2 changes to which I
previously referred (https://www.samba.org/samba/history/samba-4.2.0.html) :
For the client side we have the following new options:
"require strong key" (yes by default), "reject md5 servers" (no by
default).
E.g. for Samba 3.0.37 you need "require strong key = no" and
for NT4 DCs
2006 Aug 30
1
joining to domain breaks kerberos authentication
Hi All,
I'm running samba-3.0.23b compiled on a Solaris 10
system compiled against MIT kerberos. I am experiencing
odd behaviour where joining the machine to the domain
using 'net rpc join' seems to break the kerberos principal
tickets and regular user authentication via kerberos ceases
to work.
My smb.conf is fairly minimal;
[global]
use kerberos keytab = yes
unix
2008 Sep 03
3
yet another World of Warcraft thread
hi, im having some problems on WoW.
it has been running on my fedora core 7 desktop PC perfectly out of the box, even in directX mode(i added the direct3d key to the registry).
im now trying to run it on my Fedora 9 laptop.
it is an intel x3100GMA.
the graphics are working after some messing with config.wtf, im experiencing random lockups that can happen anywhere between the character select
2004 Aug 24
0
smbclient, kerberos, and EMC
Hi Everyone,
I'm trying to get smbclient to cooperate with my new EMC Celerra (just
got it a little while ago) using kerberos. My windows domain
environment is win2000 + sp4, the EMC is "joined" to the domain.
I am using samba 3.0, fresh sources, and MIT KRB5 1.3.4, all freshly
built. I join the domain, etc. everything is happy. I use kinit
user@REALM to get my initial tgt.
2008 May 24
0
WoW + Wine Performance Problem
Here are the spec of my Laptop
OS - Ubuntu hardy 8.04 + with fully updated
Wine - 1.0rc1
Intel P4 3.0Ghz
1 gig ram
nVidia geforce fx 5200 64mb using newest drivers using envy came be 2 fps increase from last nvidia version I had installed.
Here is my Config.wtf file in WOW.
SET gxApi "opengl"
SET ffxDeath "0"
SET ffxGlow "0"
SET SoundOutputSystem "1"
2006 Jan 11
1
issues with security=domain
Hi Dear Samba Gurus,
We're planing to migrate the old samba server to a new samba server.
But the person who maintain old samba server have left, so we need to
figure out the configuration steps from the old config file. Now the things
that confused me now is the setting with "security=domain", the old samba
server config global sections are:
log level = 3
netbios
2003 May 15
0
Domain trust problem? (3.0 alpha 23)
Help!
I have two computers, both running HP-UX 11.0, both running 3.0 alpha23
(the second computer's samba trees were copied from the first, so they
are identical).
Mapping a drive from an XP SP1 computer has NO problems on the first HP
server. On the second one, it displays the message "Configuration
information could not be read from the domain controller, either because
the machine
2004 Sep 17
0
could not fetch trust account password for domain
Hi all,
I am a samba rookie with a problem. I have replaced an old server
with a new server, and copied over the original samba config which was
for samba file but the new server has samba 3.0.5 while the old
version was 2.0.7. I had problems connecting to samba, so I tried
using the supplied default config file and then migrated the original
settings to the new file. problems still persisted.