[cifs-protocol] How is a krb5 request to cifs/my.realm handled?

Andrew Bartlett abartlet at samba.org
Mon Dec 15 01:10:13 GMT 2008


A number of our users are having trouble with group policy in Samba4,
and it seems that their clients (WinXP, Vista) look for their group
policy information in //my.realm/sysvol 

This name resolves in DNS, but we don't currently have a mapping for it
in our KDC, because I don't know, if I were to create a mixed
Microsoft/Samba4 domain what key this would resolve to.

Given that it must be shared between all domain controllers, is this
somehow mapped to krbtgt/my.realm?  Is DNS/my.realm also handled this
way?

(In the meantime it would of course be trivial to add such a mapping,
but I want to solve this properly)

Thanks,

Andrew Bartlett
-- 
Andrew Bartlett
http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/cifs-protocol/attachments/20081215/362e1b6f/attachment.bin


More information about the cifs-protocol mailing list