Information on how to get kerberos ticket of the user in VFS/shell during conneciton
jra at samba.org
Wed Feb 21 17:44:36 UTC 2018
On Wed, Feb 21, 2018 at 12:23:38PM +0100, Manfred Furuholmen via samba-technical wrote:
> We are actually trying to build a bridge between Windows and AFS,
> because we need to replace the native AFS client(that is no longer
> supported). We want to exporting with Samba the /afs/cell_name path
> mounted on a Linux node.
> One of the major problem is the token for the AFS cell, we want to
> avoid to forge the token inside of the samba machine, and also we
> don't have Kaserver anymore (If I understood is also removed from
> Samba), for this reason i have a couple of questions:
> Is it possible to have the user kerberos ticket during the execution
> of the prexec during the connection to the share? (to have as a file)?
> or is it possible to have in the VFS layer for the same operation (I
> didn't see any call for that in the vfs) ?
Sounds like you need a proxiable krb5 ticket to pass to AFS.
More information about the samba-technical