Displaying 20 results from an estimated 300 matches similar to: "Getting host keys with samba"
2007 Mar 20
1
Bizzare behaviour of Samba+ADS - help needed
I have samba+ads working fine *HOWEVER* when I run net ads keytab create
it fails.
Using -d 10 the debug output says it cannot write to the file. This is
truly bizarre as I am running this as root!
e.g.
# /usr/local/opt/samba/samba-3.0.24/bin/net ads keytab create ; echo $?
183
And
/usr/local/opt/samba/samba-3.0.24/bin/net -d 10 ads keytab create ; echo
$?
Gives
[..snip..]
ads_get_kvno:
2007 Feb 14
1
Mutiple authentication databases with Samba in ADS mode
I have Samba with Kerberos in server = ads mode. I however, have a few
odd accounts that only exist under Unix. Is it possible to get samba to
"fall back" on the local smbpassword file for users not found in ADS?
If so how?
Thanks
2006 Dec 08
1
A mass O trouble with solaris 10 and Samba+ADS
I have been having a great deal of trouble compiling Samba on Solaris 10
with ADS support.
Kerberos compiles fine.
Samba does not configure with the standard Solaris LDAP libraries and
fails in the following way.:
checking for ldap_initialize... no
configure: error: Active Directory support requires ldap_initialize
And is caused by:
configure:35160: checking for ldap_initialize
2005 Sep 26
0
[Fwd: Re: Samba with Mysql, Compilation of version 3.0.11]
Hello again,
Related to previous bug, i have corrected few things from util.c,
3 char* data structures were defined more than one time so i commented
them in code, it seem to compile now...
data_path
state_path
cache_path
Thanks anyway.
Pierre
(C)ollen wrote:
> pdb_sql.c is the new mysql backend name
> (was pdb_mysql) so it does get compiled...
> but this output shows that you still
2004 Mar 16
3
samba 3, ADS, kerberos, keytab problem - Additional pre-authentication required
Hello List,
I am (unsuccessfully) trying to automatically get a valid kerberos
ticket for my linux box. I have - in a test environment:
- a windows 2000 server with Active directory and DNS properly set up.
- a suse linux 9.0 router with samba3.0.2.rc.1 and heimdal 0.6.-67.
- I am able to join the domain and get a valid ticket through kinit, if
I enter the Administrator's password or the
2019 Jul 10
0
Winbind issues with AD member file server
On 10/07/2019 17:20, Eric Shell via samba wrote:
> I agree that this sounds like, and indeed is, a recipe for disaster. I was
> going to explain some of the woes of our environment but I don't think it's
> actually relevant after looking at my problem a bit more. If I'm way off
> base I'm happy to be herded back, but please tolerate me as I share what I
> am seeing
2003 Sep 30
1
AD SAMBA Kerberos participation with other AD Kerberised services
Hi All,
anyone else found that adding a Samba server to an AD domain appears to be incompatible with using an AD Kerberos realm to provide other Kerberised services such as NFS from the same UNIX host?
Problem I have is that when you join an AD domain thorough Samba 3.x net command this creates a computer account in the AD to which the administrator does not know the account password. If you
2013 Apr 29
3
ktpass.sh error / How to generate a keytab for a new service (apache) with SAMBA4?
Hi,
I was trying to get a new keytab in samba4 for my apache service. So I
tried the following command:
sh ktpass.sh --out /etc/apache.keytab --princ
HTTP/myhost.samba.my.domain at SAMBA.MY.DOMAIN --pass VerySecure123 --enc
des-cbc-md5
I get the following error: Unable to find kvno for principal
HTTP/myhost.samba.my.domain at SAMBA.MY.DOMAIN
Am I doing something wron or shouldn't I be
2019 Jul 10
1
Winbind issues with AD member file server
>
> When I try to
> > access even an already-mounted NFS directory to which I have permission,
> > gssproxy complains:
> >
> > Jul 10 08:55:51 smb gssproxy: gssproxy[1469]: (OID: { 1 2 840 113554 1 2
> 2
> > }) Unspecified GSS failure. Minor code may provide more information,
> > Client 'host/smb.soe.ucsc.edu at AD.SOE.UCSC.EDU' not found in
2017 Jan 20
3
how to run ktpass with a Samba AD DC?
I was trying to get authentication via kerberos working but I'm having
trouble trying to run ktpass as in step 6 here
http://robertan.com/home/2015/01/14/kerberos-auth-with-apachephp/
ktpass -princ HTTP/contoso.com at CONTOSO.COM -mapuser
CONTOSO\<USERNAME> -crypto all -ptype KRB5_NT_PRINCIPAL -pass
<PASSWORD> -out webpage.HTTP.keytab
I'm not sure of the
2001 Dec 30
1
Extracting the trust account password (for use with Win2k's ktpass)?
Hello, all:
My Samba server is a member of a Windows 2000 AD domain.
Authentication to the Samba server is, of course, by encrypted NTLM
hashes. Authentication to the host itself, which runs Red Hat Linux
7.1, is by NIS (the AD domain controller is running Server for NIS).
I want to remove NIS (or at least the passwords from NIS). To
accomplish this, I wish to use pam_krb5 to authenticate users
2016 Aug 03
0
FW: kerberos nfs4's principals and root access
Ah ok, you are using "public_html" from a default setup.
Now i understand what you exact want.
If you have the apache keytab created.
Create a cron job and run :
kinit -t /path/to/keytab as the www user.
Dont forget het disable the password change in the AD user for
the "apache Service user" account.
You probely also need to export some kerberos variables like :
2003 Dec 03
1
MIT Kerberos with Solaris
As Samba 3.x does not work with the Kerberos included with Solaris (it has no headers) I have to remove it and replace it with MIT kerberos. Does anyone know if Solaris kerberised services will still work normally (without modification) such as kerberised NFS? I briefly tested this and couldn't het it to work, but if someone has a definative answer it might save me a lot of trouble,
thanks
2007 Apr 23
1
Extracing "Interval of Time" in seconds in R
Dear List,
I want to let R calculate the time (run-time) it
requires to run a self-written simulation function. I
tried as follows: it
enables me to see the starting and finishing time
points.
#############################
"sim.result" <- function(nsim, ...){
Starting <- date()
... # calculations #
final.result <- ... # Output for display #
cat("# of Iterations used
2016 Aug 03
1
FW: kerberos nfs4's principals and root access
If not done, add the server to the AD.
Add the host and nfs to the COMPUTERNAME($) account.
And use winbind to refresh the keytab.
Stop samba,
remove the keytab, create the new with the new SPN's in it,
start samba.
And Use the second keytab for apache with only http as upn in it.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at
2016 Aug 03
1
FW: kerberos nfs4's principals and root access
Hi Rowland,
I've already read this article, but I never find how to indicate to
apache to read this file... After some research, I think I need to
install mod_auth_krb5 to specify at least how to find this keytab (even
if I don't need Apache authentication against Kerberos).
I will try this today and comme back to say if it works !
In fact i'm stuck between my two problems (root
2003 Dec 11
1
kerberos with W2K server
Hello,
The problem: With the command:
net ads join my_linux_box
my samba 3.0.1rc1 works fine with a W2k kerberos server
But i prefer use the ktpass command on w2k server (and our m$ guru).
The problem seems to be that samba dont use /etc/krb5.keytab.
The quick read of source and some mail in the archives gives me the
beleive that it use a memory keytab (and secrets.tdb ?).
I m not sure.
Could
2005 Jun 13
2
Can't maintain a connection to the Server 2003 ADS on a subdomain
Hello to every Samba expert out there,
We've been having a hard time figuring out a particular problem with Samba.
After joining the Server 2003 ADS, which is on a different subnet - just
going through a router, the membership would drop all of a sudden.
Everything works great when the Samba server is on the same subnet as the
Server 2003 ADS. I have posted some details on forums, here is a
2014 Jan 21
1
Generating keytabs for other hosts
Hi guys
am looking for some guidance on how I can generate some keytab files from a
samba 4 DC
I been following a tutorial that states some bits on the windows side such
as creating an spn
C:\Users\Administrator>setspn -A host/test.sondrel.com at SONDREL.COM Test
Registering ServicePrincipalNames for CN=Test,OU=Machines,DC=sondrel,DC=com
host/envy.sondrel.com at SONDREL.COM
Updated
2007 Feb 05
1
kerberos/Samba integration questions
I'm trying to integrate Samba with my kerberos configuration on Solaris 10
(with Samba 3.0.23d) and I have one basic issue - probably I don't
understand something. Hopefully one of you experts can help.
We have an AD based organization but we do a lot of Unix work on Solaris 10
and AIX 5.3 - I have about 75 *nix servers of various flavors. There's a lot
of value in SSO