Displaying 20 results from an estimated 20000 matches similar to: "samba creating keytabs... ( possible bug, can someone confirm this )"
2017 Feb 01
1
winbind question. (challenge/response password authentication)
Hai,
Im setting up a new proxy and im testing a bit around.
Goal is, get everyting working with minimal changes to the system.
Setup: Debian 8 with NFS nfsv3 and v4 (krb) automounts, winbind 4.5.3 , squid 3.5.24 (with ssl support)
Which is basicly a copy of my other proxy but a new install with more systemd and less packages used.
Working:
- ssh logins with AD users.
2016 Sep 16
2
Exporting keytab for SPN failure
On Fri, 16 Sep 2016 13:00:52 -0700
Robert Moulton via samba <samba at lists.samba.org> wrote:
> Achim Gottinger via samba wrote on 9/15/16 1:20 AM:
> >
> >
> > Am 15.09.2016 um 09:35 schrieb Rowland Penny via samba:
> >> On Wed, 14 Sep 2016 16:23:27 -0500
> >> Michael A Weber via samba <samba at lists.samba.org> wrote:
> >>
>
2017 Feb 07
2
samba creating keytabs... ( possible bug, can someone confirm this )
Hm instresting way.
Whats the difference in createing the HTTP/spn with net ads or samba tool
( besides de found bug )
I'll go try this out.
You remember the "squid" spn/upn problem, this solved it also.
The squid kerberos group plugin now correctly detects the HTTP spn.
Thanks for trying out.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba
2016 Sep 16
2
Exporting keytab for SPN failure
Am 16.09.2016 um 23:00 schrieb Robert Moulton via samba:
> Rowland Penny via samba wrote on 9/16/16 1:43 PM:
>> On Fri, 16 Sep 2016 13:00:52 -0700
>> Robert Moulton via samba <samba at lists.samba.org> wrote:
>>
>>> Achim Gottinger via samba wrote on 9/15/16 1:20 AM:
>>>>
>>>>
>>>> Am 15.09.2016 um 09:35 schrieb Rowland Penny
2016 Sep 16
2
Exporting keytab for SPN failure
Am 17.09.2016 um 00:29 schrieb Robert Moulton via samba:
> Achim Gottinger via samba wrote on 9/16/16 3:05 PM:
>>
>>
>> Am 16.09.2016 um 23:00 schrieb Robert Moulton via samba:
>>> Rowland Penny via samba wrote on 9/16/16 1:43 PM:
>>>> On Fri, 16 Sep 2016 13:00:52 -0700
>>>> Robert Moulton via samba <samba at lists.samba.org> wrote:
2016 Sep 16
2
Exporting keytab for SPN failure
Achim Gottinger via samba wrote on 9/16/16 4:14 PM:
>
>
> Am 17.09.2016 um 00:54 schrieb Achim Gottinger via samba:
>>
>>
>> Am 17.09.2016 um 00:29 schrieb Robert Moulton via samba:
>>> Achim Gottinger via samba wrote on 9/16/16 3:05 PM:
>>>>
>>>>
>>>> Am 16.09.2016 um 23:00 schrieb Robert Moulton via samba:
2016 Sep 17
2
Exporting keytab for SPN failure
Am 17.09.2016 um 02:19 schrieb Achim Gottinger via samba:
>
>
> Am 17.09.2016 um 01:23 schrieb Robert Moulton:
>> Achim Gottinger via samba wrote on 9/16/16 4:14 PM:
>>>
>>>
>>> Am 17.09.2016 um 00:54 schrieb Achim Gottinger via samba:
>>>>
>>>>
>>>> Am 17.09.2016 um 00:29 schrieb Robert Moulton via samba:
2016 Dec 02
4
Samba and kerberized NFSv4
Hi Marcel
thx. for your fast response. I didn't manage to follow up sooner. I had already verbose logging turned on but I don't seem to find the real reason, why the domain controller searchs for a userPrincipalName instead of servicePrincipalName.
Because I wasn't sure whether it is the nfs client process or the server process that failed to get the kerberos ticket when I tried the
2019 Nov 05
7
Failed to find cifs/fs-share@dom.corp (kvno 109) in keytab
Ok,
Your keytab looks ok now.
oldsamba.dom.corp is an alias for fs-a.oldsamba.dom.corp.
fs-a.dom.corp has address 10.0.0.2
i would have expected here.
oldsamba.dom.corp is an alias for fs-a.dom.corp.
fs-a.dom.corp has address 10.0.0.2
Or was that a typo? I assuming a typo..
About your setup from the script outpout.
Change this one.
/etc/hosts
10.0.0.2 fs-a.dom.corp fs-a oldsamba #
2016 Sep 17
2
Exporting keytab for SPN failure
On Fri, Sep 16, 2016 at 6:08 PM, Achim Gottinger via samba
<samba at lists.samba.org> wrote:
>
>
> Am 17.09.2016 um 02:36 schrieb Achim Gottinger via samba:
>>
>>
>>
>> Am 17.09.2016 um 02:19 schrieb Achim Gottinger via samba:
>>>
>>>
>>>
>>> Am 17.09.2016 um 01:23 schrieb Robert Moulton:
>>>>
>>>>
2020 Jul 14
1
Error trying to access samba sharing using netbios name
am getting this error in smbd.log when user try to open Share from Windows
box:
gss_accept_sec_context failed with [ Miscellaneous failure (see text):
Failed to find cifs/mymember.my.domain.tld at MY.DOMAIN.TLD(kvno 58) in keytab
MEMORY:cifs_srv_keytab (aes256-cts-hmac-sha1-96)]
SPNEGO(gse_krb5) NEG_TOKEN_INIT failed: NT_STATUS_LOGON_FAILURE
I have made a research here in google and here in mail
2013 Jun 05
3
Samba4 and NVSv4
Short story: cannot get Kerberized NFSv4 to work. I've googled a great
deal and cannot find where I have goofed (and there sure is a lot of
misleading and just plain incorrect information out there), so would
appreciate another pair of eyes. NFSv4 without Kerberos does work fine, as
does ID mapping. We're using NFSv4 in production with sec=sys, but I'm not
happy with that. My
2013 Jun 05
3
Samba4 and NVSv4
Short story: cannot get Kerberized NFSv4 to work. I've googled a great
deal and cannot find where I have goofed (and there sure is a lot of
misleading and just plain incorrect information out there), so would
appreciate another pair of eyes. NFSv4 without Kerberos does work fine, as
does ID mapping. We're using NFSv4 in production with sec=sys, but I'm not
happy with that. My
2019 Nov 05
5
Failed to find cifs/fs-share@dom.corp (kvno 109) in keytab
Ok, you did to much as far i can tell.
You want to see this: i'll show my output, then i is better to see what i mean.
this is where you start with.
klist -ke |sort ( default member )
---- --------------------------------------------------------------------------
3 host/HOSTNAME1 at REALM.DOMAIN.TLD (aes128-cts-hmac-sha1-96)
3 host/HOSTNAME1 at REALM.DOMAIN.TLD
2016 Sep 15
3
Exporting keytab for SPN failure
Am 15.09.2016 um 09:35 schrieb Rowland Penny via samba:
> On Wed, 14 Sep 2016 16:23:27 -0500
> Michael A Weber via samba <samba at lists.samba.org> wrote:
>
>>> On Sep 14, 2016, at 2:00 PM, Achim Gottinger <achim at ag-web.biz>
>>> wrote:
>>>
>>>
>>>
>>> Am 14.09.2016 um 20:33 schrieb Michael A Weber:
>>>>>
2019 Feb 26
2
gpo not applied a boot computer
THANK YOU FOR YOUR REPLY
THE RESULT :
KVNO Principal
----
--------------------------------------------------------------------------
1 HOST/samba4 at FSS.LAN (des-cbc-crc)
1 HOST/samba4.fss.lan at FSS.LAN (des-cbc-crc)
1 SAMBA4$@FSS.LAN (des-cbc-crc)
1 HOST/samba4 at FSS.LAN (des-cbc-md5)
1 HOST/samba4.fss.lan at FSS.LAN (des-cbc-md5)
1 SAMBA4$@FSS.LAN (des-cbc-md5)
1
2016 Sep 17
2
Exporting keytab for SPN failure
Am 17.09.2016 um 04:53 schrieb Achim Gottinger via samba:
>
>
> Am 17.09.2016 um 03:24 schrieb r moulton via samba:
>> On Fri, Sep 16, 2016 at 6:08 PM, Achim Gottinger via samba
>> <samba at lists.samba.org> wrote:
>>>
>>> Am 17.09.2016 um 02:36 schrieb Achim Gottinger via samba:
>>>>
>>>>
>>>> Am 17.09.2016 um 02:19
2016 Dec 19
5
Problem with keytab: "Client not found in Kerberos database"
I am trying to use a keytab for a client machine to authenticate to
Samba's own LDAP server.
The samba servers (replicated) are ubuntu 16.04 with samba 4.5.2
compiled from source.
The client machine is ubuntu 16.04 with stock samba 4.3.11. It has been
joined directly to the Samba domain ("net ads join"). I have also
extracted a keytab ("net ads keytab create -P")
2016 Sep 17
2
Exporting keytab for SPN failure
Am 17.09.2016 um 17:07 schrieb Achim Gottinger via samba:
>
>
> Am 17.09.2016 um 06:14 schrieb Achim Gottinger via samba:
>>
>>
>> Am 17.09.2016 um 04:53 schrieb Achim Gottinger via samba:
>>>
>>>
>>> Am 17.09.2016 um 03:24 schrieb r moulton via samba:
>>>> On Fri, Sep 16, 2016 at 6:08 PM, Achim Gottinger via samba
>>>>
2016 Sep 16
2
Exporting keytab for SPN failure
Am 16.09.2016 um 22:49 schrieb Rowland Penny via samba:
> On Fri, 16 Sep 2016 22:43:42 +0200
> Achim Gottinger via samba <samba at lists.samba.org> wrote:
>
>>
>> Am 16.09.2016 um 22:00 schrieb Robert Moulton via samba:
>>> Achim Gottinger via samba wrote on 9/15/16 1:20 AM:
>>>>
>>>> Am 15.09.2016 um 09:35 schrieb Rowland Penny via