Information on how to get kerberos ticket of the user in VFS/shell during conneciton

Volker Lendecke Volker.Lendecke at SerNet.DE
Thu Feb 22 09:34:36 UTC 2018

On Wed, Feb 21, 2018 at 07:50:57PM +0100, Manfred Furuholmen via samba-technical wrote:
> Hi Volker,
> thanks for the answer.
>  Yes AFS moved a bit forward,  today no one is using the kaserver anymore,
> all the installation are using a Kerberos 5 server (MIT, Heimdal or ADC),
> but at the end the akog convert the kerberos TGT in the AFS token, and from
> that point not much it is changed.
> For these reason if it is possible to have the TGT of the user during the
> connection we can convert in AFS  token and the pag will take care of the
> rest (thanks for the Samba model base on process), without insert the
> KeyFile to secrets.tdb

How is the conversion from tgt to afs token done exactly? Can you
point me at the code in the afs sources?

Thanks, Volker

Besuchen Sie die verinice.XP 2018 in Berlin,
Anwenderkonferenz für Informationssicherheit
vom 21.-23.03.2018 im Sofitel Kurfürstendamm
Info & Anmeldung hier:

SerNet GmbH, Bahnhofsallee 1b, 37081 Göttingen
phone: +49-551-370000-0, fax: +49-551-370000-9
AG Göttingen, HRB 2816, GF: Dr. Johannes Loxen, mailto:kontakt at

More information about the samba-technical mailing list