Displaying 20 results from an estimated 8000 matches similar to: "Problem accessing samba fileserver with smbclient using Kerberos"
2004 Jul 19
1
Windows 2003 AD/Kerberos Ticket error
I'm attempting to configure Samba 3.0.4 to work with Windows 2003 Active
Directory, mapping users' home directories automatically. Currently we
use this method in production with Windows 2000 but wish to migrate to
2003. The problem seems to be Kerberos related. I was able to join the
Linux box (RedHat 9) to the AD. I can do a "kinit <username>"
successfully. Klist shows a
2003 Dec 11
1
kerberos with W2K server
Hello,
The problem: With the command:
net ads join my_linux_box
my samba 3.0.1rc1 works fine with a W2k kerberos server
But i prefer use the ktpass command on w2k server (and our m$ guru).
The problem seems to be that samba dont use /etc/krb5.keytab.
The quick read of source and some mail in the archives gives me the
beleive that it use a memory keytab (and secrets.tdb ?).
I m not sure.
Could
2009 Feb 11
1
desactivating NTLM fallback when accessing a share and kerberos auth fails
Hello.
I have a print server member of an AD domain, and my users are
autenthicated through an external kerberos domain. My samba server FQDN
is 'etoile.msr-inria.inria.fr', and has 'cups.msr-inria.inria.fr' as DNS
alias.
For foreign visitors, everything works fine: when attempting to reach
\\cups, samba immediatly detect from given credentials than user comes
from an
2009 May 06
0
Kerberos tickets problem
I'm setting up a Solaris 10 server as a test samba server with AD
authentication. I'm running into a little bit of issue with Kerberos
tickets. The setup is as follows
Solaris-10, Windows AD-2003/R2, native Solaris (sparc) samba, Kerberos, LDAP
(shipped with the distro) and IMU on windows. My LDAP client is working
good and validates getent passwd <user> and can run ldaplist -l
2007 Feb 05
1
kerberos/Samba integration questions
I'm trying to integrate Samba with my kerberos configuration on Solaris 10
(with Samba 3.0.23d) and I have one basic issue - probably I don't
understand something. Hopefully one of you experts can help.
We have an AD based organization but we do a lot of Unix work on Solaris 10
and AIX 5.3 - I have about 75 *nix servers of various flavors. There's a lot
of value in SSO
2004 Apr 14
5
Samba 3.0.2a and ADS w2k3 Kerberos authentication problem
I am using Samba 3.0.2a as Domain member into ADS w2k3 domain. net ads
join -U administrator work fine.
This integration include support of kerberos ( krb5.conf) and winbind
wbinfo -u and -g works fine.
I am able to mapped Samba shares with IP address (\\192.168.0.x\share)
but it does not works if I use netbios name ( \\redhat9\share) the
system asks me for authentication but never I get into
2005 Aug 11
0
kerberos_kinit_password host/SUNDEV@LEXI.COM.MX failed: Client not found in Kerberos database
I'm using Solaris 8, samba 3, kerberos and
openldap. I'm anexing: log.smbd, smb.conf, krb5.conf,
nsswitch.conf and the ktpass command in AD.
Somebody can help me?
I get this output in log.smbd:
-----------------------------------
[2005/08/11 12:41:45, 0] smbd/server.c:main(802)
smbd version 3.0.20rc1 started.
Copyright Andrew Tridgell and the Samba Team
1992-2004
[2005/08/11
2008 Aug 08
2
[Bug 928] Kerberos/GSSAPI authentication does not work with multihomed hosts
https://bugzilla.mindrot.org/show_bug.cgi?id=928
Damien Miller <djm at mindrot.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |djm at mindrot.org
Blocks| |1481
--- Comment #4 from Damien Miller
2018 Nov 06
2
Samba CIFS Mounts with Kerberos Security: Write Access denied
Hi all,
I am testing different setups for Samba home share mounts via the
CIFS protocol on Linux clients with and without Keberos security (both
krb5 and krb5i). I am experiencing some strange behaviour in case of
Kerberos authentication:
In case of mounts (by root or the user itself) without Kerberos security (only
NTLMv2 authentication), local root and the owning user on the Linux client
2007 Mar 17
0
Kerberos + Windows XP + Samba
Dear list members,
i am trying to implement SSO solution on my windows network. Right
now, for testing purposes, i have setted a kerberos server to
authenticate my users. Using this kerberos server, i am able to log on
any of my unix workstations. Users information is retrieve from nis
and the authentication process is performed by keberos on its all.
Done so with unix, i starting testing with
2001 Nov 05
0
[PATCH] Kerberos v5 support for protocol v1
The following patch
*) Adds a configure option to turn on the existing Kerberos v5 support in
the portable version
*) Extends the code to support MIT Kerberos in addition to Heimdal
The patch is against the current CVS tree. I've tested it against MIT Keberos
1.2.2, I'd appreciate it if someone could confirm that Heimdal works with the
portable configuration stuff.
Coming RSN -
2004 Sep 12
1
[Bug 928] Kerberos/GSSAPI authentication does not work with multihomed hosts
http://bugzilla.mindrot.org/show_bug.cgi?id=928
Summary: Kerberos/GSSAPI authentication does not work with
multihomed hosts
Product: Portable OpenSSH
Version: -current
Platform: Other
URL: http://marc.theaimsgroup.com/?l=openssh-unix-
dev&m=108008882620573
OS/Version: All
2006 Dec 11
0
"smbclient -k" fails, used to work - kinit still ok
Hi All,
I've run into a strange problem, which so far I haven't seen reported by anyone else recently.
A while back I set up a Linux box (SUSE 9.2) to authenticate (using kerberos) against a w2k3
AD domain. A nice side effect of this was that I could use "smbclient -k" and save typing in
my password again.
I didn't have cause to use smbclient for some time, until the other
2013 Oct 03
2
name mangling makes 8.3 unreadable unlike Windows fileserver
Hi,
I'm cross-posting here from serverfault.com in case anyone can help. I
just found a similar question on askubuntu.com also without an answer.
Switched recently from W2K3 to Samba4.0.9/CentOS6.4 for our fileshare
for WinXP clients.
Have an ancient (1995!) piece of software that uses 8.3 filename format.
After the switch, long filenames became useless in the context of the
2016 Feb 23
0
Kerberos Principal
You mean something like :
Create a user for a service.
samba-tool user create squid-proxy --description="Unprivileged user for SQUID-Proxy Services" --random-password
Disable password expiry.
samba-tool user setexpiry squid-proxy --noexpiry
setting HTTP SPN on the proxy user (proxy1)
samba-tool spn add HTTP/proxy1.internal.domain.tld squid-proxy
samba-tool spn add
2016 Feb 22
6
Kerberos Principal
Hi all,
I’m looking to add in a kerberos principal on my server for the AD domain.
I see there are ways to do this for user(s), but I don’t see how to add a principal for hosts.
In general, I’ld like to add something like the following to me 4.3.4 Domain:
ktpass -princ afpserver/fqdn at REALM -mapuser mapuser at domain +rndPass -out afpserver.keytab
This is for a netatalk server. I’ve never
2011 Mar 10
1
Dove cot+Kerberos
Hi All.
I have a problem with authorization users AD via kerberos in
Dovecot&Postfix.
Windows SRV 2008 Standart - AD
mail server: Gentoo + cyrus-sasl + postfix + dovecot with support
ldap&kerberos.
I am created a 4 keytabs on Windows box.
C:\Users\Admin>ktpass -princ host/srv-mail.cn.energy at CN.ENERGY -mapuser
ldapmail at CN.ENERGY -pass "superpasswd" -crypto RC4-HMAC-NT
2002 Nov 01
0
Re: Samba PDC and Kerberos(MIT or SEAM in Uinx, without microsoft ADS)
Hi, Thank you very much for you reply.
Some people think storing the sensitive information in the LDAP is not very
secure.They think the sensitive information and the public information should be
stored in seperate place.So we want the samba PDC authentication can integrete the
Kerberos authentication directly.
John
---- Original Message ----
From: Yura Pismerov
Date: Thu 10/31/02 18:39
2002 Oct 29
0
Re: Samba and Kerberos PDC(MIT or SEAM, without microsoft ADS)
Hi, Andrew,
Thank you very much. I have read some information about the samba PDC kerberos
authentication as below.
>> Anyone worked with a combination of Samba (TNG, or 2.x) running as a PDC for
>> a network of primarily NT workstations, with the passwords being
>> authenticated back into a Kerberos IV database? or a Kerberos V?
>
>> I'm trying to get this
2001 Dec 30
1
Extracting the trust account password (for use with Win2k's ktpass)?
Hello, all:
My Samba server is a member of a Windows 2000 AD domain.
Authentication to the Samba server is, of course, by encrypted NTLM
hashes. Authentication to the host itself, which runs Red Hat Linux
7.1, is by NIS (the AD domain controller is running Server for NIS).
I want to remove NIS (or at least the passwords from NIS). To
accomplish this, I wish to use pam_krb5 to authenticate users