[Samba] mod_ntlm_winbind / Apache2

Kevin Shanahan kmshanah at ucwb.org.au
Sun Sep 3 23:55:26 GMT 2006


On Sat, 2006-09-02 at 09:49 +1000, Andrew Bartlett wrote:
> Because it needs to access either the secrets.tdb or a keytab,
> gss-spnego is much more fragile than the NTLMSSP helper.  We could make
> it less fragile by handling the kerberos verification in winbindd,
> rather than in the ntlm_auth binary.

I'm not 100% sure of what you just said (my knowledge of kerberos stuff
is very limited). My samba setup on this host is running as a member
server in a Win2000 AD environment. Are you saying that I need to do
some more kerberos setup outside of samba/winbind to get the gss-spnego
helper to work?

Thanks,
Kevin.




More information about the samba mailing list