Displaying 20 results from an estimated 20000 matches similar to: "Where are Heimdal Kerberos library and headers located?"
2004 Apr 14
3
OpenLDAP,heimdal kerberos,sasl, wich order?
Hi!
I have been reading for about two weeks (maybe I'm reading on the wrong 
places).  I have found as many documents as one could expect describind 
how to build a LDAPv3 server, or how to build samba with ldap.  This 
far, I have failed, and have a BIG confution in the order in wich the 
things should go:
In one document, they recommend this:
samba -> ldap -> sasl -> kerberos
2016 Jan 08
5
Samba AD/DC, Single-Sign-On, domain users cannot change password
I have successfully joined my Linux/Ubuntu workstation to the Samaba AD/DC domain thanks to
help from Rowland Penny.
Now I face an interesting problem ... Domain users cannot change their password.
Domain users can successfully login to the Linux workstation using their domain credentials,
but when the user tries to change the password using "Passwords and Keys" from the desktop
2016 Jul 21
3
sendmail getting domain\user as email userId [formerly: How to GSSAPI/Kerberos authenticate with Dovecot]
Hi Mark,
I've had the same trouble with the DOMAIN\user on my DCs, and as Rowland
has already pointed out, the "winbind use default domain = yes" configure
option is not honored on a DC.  My guess is that is because a Samba DC can
only be a DC for one domain, so that is why it isn't honored.  If I do
"getent passwd username" on my DCs, they all return
2006 Nov 29
2
Samba and Heimdal Kerberos V Authentication
Hello,
I maintain a network of numerous Linux workstations, several Apples,
and a few Windows machines. The Apples and Windows XP machines already
grab shared data via Samba and the remaining data is exported to the
Linux machines via NFS.
I am in the process of migrating the existing authentication system
from XYZ123 to Kerberos and going to place user data---with the
exception of passwords
2006 Mar 17
1
samba3 and heimdal: both using ldap as backends
samba-3.0.21c, heimdal-0.7.2
The heimdal documentation[1] talks about a samba integration when both
samba and heimdal are using ldap as their backends. I quote:
"Now you can proceed as in See Using LDAP to store the database. Heimdal
will pick up the Samba LDAP entries if they are in the same search space
as the Kerberos entries."
There is absolutely no further documentation.
I tried
2016 Jan 14
2
Samba AD/DC, Single-Sign-On, domain users cannot change password
On 14/01/16 05:54, Mark Foley wrote:
> Hmmm, this message is a week old and nothing?
>
> I know many of you have domain member hosts in your domain and surely are logging in as domain
> users authenticating with the Samba4 AD/DC, right?
>
> How do you change your password without having the domain Administrator do it for you?
>
> --Mark
>
> -----Original Message-----
2016 Jul 21
2
How to GSSAPI/Kerberos authenticate with Dovecot [formerly Where is krb5.keytab or equivalent?]
On 21/07/16 06:08, Mark Foley wrote:
> OK! I deleted the /etc/passwd entry for user mark and I modified my /etc/nsswitch.conf to:
>
> passwd: compat winbind
> group: compat winbind
>
> I couldn't get sendmail working with this at first -- I didn't know what to [re]start to get
> the new nsswitch config to take, so I rebooted. Probably I just had to restart sendmail,
2025 May 18
2
Users unable to reset passwords
On Sun May 18 03:22:40 2025 Penny via samba <samba at lists.samba.org> wrote:
>
> On Sat, 17 May 2025 00:46:20 -0400
> Mark Foley via samba <samba at lists.samba.org> wrote:
>
> > I'm trying to solve a couple of problems with Samba 4.18.19 and
> > Windows 11. I've described these in detail in previous messages in
> > this thread, so I'll be
2019 Jan 19
2
NT_STATUS_ACCOUNT_LOCKED_OUT
On Sat, 2019-01-19 at 13:37 -0500, Mark Foley via samba wrote:
> I sure could use some help on this.  Perhaps this problem is due to a
> recent Windows update?
> 
> Furthermore, when I do actually log into this computer as 'mark' and
> enter the correct PW, it
> works fine, no Auth errors. 
> 
> Could someone point me in the right direction for research? 
Turn up
2018 Dec 05
3
Samba4 Kerberos Authentication Error
On 12/5/2018 1:27 PM, Rowland Penny via samba wrote:
> On Wed, 5 Dec 2018 13:00:38 -0500
> Marco Shmerykowsky PE via samba <samba at lists.samba.org> wrote:
> 
>>> Are you using the OS's Samba packages ?
>>> If so, you should be aware that they are deemed experimental and do
>>> not fully work, they have problems and this could be another one of
2016 Jul 22
2
Heimdal Kerberos in Samba4
Hi List,
I do my best to ask my question in english. ;-)
Samba4 integrated heimdal kerberos to do the kerberos work for Active 
Directory. Some Linux Distributions like fedora/RedHat and openSUSE/SUSE 
don't accept heimdal even if it is shipped inside samba.
Their argument is that heimdal isn't maintained since 2012. Compiling 
samba against MIT krb5 results in Samba-Packages without
2005 Jun 20
2
MIT Kerberso or Heimdal Kerberos what is the question?
I have some problem whit Kerberos.
OS: FreeBSD 5.3
Domain: W2k3 native mode.
1)I am Installing Heimdal 0.6.1 over port. Config /etc/krb5.conf
%/usr/local/bin/kinit ivan 
ivan@NKMK.RU's Password: 
kinit: krb5_get_init_creds: Response too big for UDP, retry with TCP 
2)Compile and install  Heimdal 0.6.4 over source
%/usr/local/bin/kinit ivan 
ivan@NKMK.RU's Password: 
kinit:
2013 Dec 08
1
Question about Kerberos and what is the different if compile with internal heimdal or mit-krb5
Dear All,
Would like some know the answer on the above question.
What is the different between compiling using internal heimdal library vs
mit-krb5.
I'm on gentoo and thus like other distro having issue on the system-wide
mit-krb and removing it is not that convenient (But still possible)
I've try to compile samba 4.1.2 with internal heimdal library to work as a
Domain controller
But
2006 Dec 22
3
Heimdal or MIT kerberos comparison
What is the difference between Heimdal and MIT as far usability goes?
MIT seems to be the default on major linux distrobutions, but I here a
lot about people preferring Heimdal, but I can't find any reasons why.
Is one generally more stable/faster/reliable than the other?
 
There is already a blank wiki page at
http://wiki.samba.org/index.php/Samba_%26_Kerberos so if anyone has any
good
2007 Aug 03
2
Missing Heimdal, Kerberos, Samba and OpenLdap how-to
Hi,
i'm looking for this how-to, often referenced but no more available:
https://sec.miljovern.no/bin/view/Info/HeimdalKerberosSambaAndOpenLdap
Is there anywhere an how-to about integrating Heimdal, Kerberos, Samba 
and OpenLdap?
Thank you in advance
Marcello
2016 Jan 15
4
Samba AD/DC, Single-Sign-On, domain users cannot change password
On January 14, 2016 at 12:16 Rowland Penny wrote:
> Using 'passwd' does work, but pam has to be setup correctly and you 
> cannot change the password on the first day unless you change the 
> minimum password age to '0'
You answer piles of questions on this list, so you may not remember, but you helped me set this
whole domain-member/single logon thing last October. The
2018 Dec 05
2
Samba4 Kerberos Authentication Error
On 12/5/2018 12:28 PM, Rowland Penny via samba wrote:
> On Wed, 5 Dec 2018 12:19:39 -0500
> Marco Shmerykowsky PE <marco at sce-engineers.com> wrote:
> 
>>
>>
>> --
>>
>> Marco J. Shmerykowsky, PE, F.ASCE
>> marco at sce-engineers.com
>>
>> -----------------------------------------
>>      Shmerykowsky Consulting Engineers
2016 Jul 25
3
Heimdal Kerberos in Samba4
On Fri, Jul 22, 2016 at 12:25 PM, Jeremy Allison <jra at samba.org> wrote:
> On Fri, Jul 22, 2016 at 02:54:05PM +0200, Stefan Schäfer wrote:
>> Hi List,
>>
>> I do my best to ask my question in english. ;-)
>>
>> Samba4 integrated heimdal kerberos to do the kerberos work for
>> Active Directory. Some Linux Distributions like fedora/RedHat and
>>
2016 Jul 20
2
How to GSSAPI/Kerberos authenticate with Dovecot [formerly Where is krb5.keytab or equivalent?]
Mike, excellent suggestion!  I will definitely experiment with that nsswitch change.  Rowland
also mentioned adding RFC2307 to the AD settings for the user(s). 
If, as you say, my MTA will find the home directory with the nss windbind setting, that would
be fantastic! I would definitely removed the AD users from /etc/passwd.
I don't know if nsswitch.conf settings are now mentioned in the
2015 Sep 16
1
How to "Windows Authenticate"
> On 16 Sep 2015, at 19:10, Mark Foley <mfoley at ohprs.org> wrote:
> 
> Does the Dovecot NTLM mechanism work with MS Outlook?
> 
> [ ] YES
> [ ] NO
> 
> Please check one ... anybody.
> 
> ?Mark
The URL on the wiki, which had probably been shared before with you;
http://wiki2.dovecot.org/HowTo/ActiveDirectoryNtlm
suggests it does.
The URL quotes:
Step 5.