[cifs-protocol] RE: How is a krb5 request to cifs/my.realm handled?

Richard Guthrie rguthrie at microsoft.com
Mon Dec 15 02:52:25 GMT 2008


Andrew,

Thanks for the question. I will create a case for this shortly and an engineer will get in touch with you to begin working this issue.

Richard Guthrie
Escalation Engineer

________________________________________
From: Andrew Bartlett [abartlet at samba.org]
Sent: Sunday, December 14, 2008 7:10 PM
To: Interoperability Documentation Help
Cc: pfif at tridgell.net; cifs-protocol at samba.org
Subject: How is a krb5 request to cifs/my.realm handled?

A number of our users are having trouble with group policy in Samba4,
and it seems that their clients (WinXP, Vista) look for their group
policy information in //my.realm/sysvol

This name resolves in DNS, but we don't currently have a mapping for it
in our KDC, because I don't know, if I were to create a mixed
Microsoft/Samba4 domain what key this would resolve to.

Given that it must be shared between all domain controllers, is this
somehow mapped to krbtgt/my.realm?  Is DNS/my.realm also handled this
way?

(In the meantime it would of course be trivial to add such a mapping,
but I want to solve this properly)

Thanks,

Andrew Bartlett
--
Andrew Bartlett
http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.


More information about the cifs-protocol mailing list