[PATCH] Fix spnego with machine$@DOMAIN
asn at samba.org
Thu Dec 1 12:11:02 UTC 2016
if you join a domain with Kerberos (MIT) you get the following error:
samba-cli01:~ # net ads join -k
Kinit for SAMBA-CLI01$@EARTH to access WINSRV-DC02.earth.milkyway.site failed:
KDC reply did not match expectations
The reason is that after the latest changes to libsmb we use:
as the principal for kinit. Windows allows to use the domain name (netbios
name) in the principal but for that you need to turn on canonicalization
support. We do not do that if Samba is compiled with MIT Kerberos.
The attached patch is part of my MIT KDC working branch since last year, I
think it is time to push it to master :)
Please review and push!
Andreas Schneider GPG-ID: CC014E3D
Samba Team asn at samba.org
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 1623 bytes
Desc: not available
More information about the samba-technical