CTDB 46.update-keytabs.script query

Martin Schwenke martin at meltin.net
Tue Aug 25 12:08:47 UTC 2026


On Tue, 25 Aug 2026 11:07:15 +0200, Stefan Metzmacher <metze at samba.org>
wrote:

> Am 25.08.26 um 09:57 schrieb Martin Schwenke:
> > On Tue, 25 Aug 2026 09:54:50 +0200, Stefan Metzmacher <metze at samba.org>
> > wrote:
> >   
> >> Am 25.08.26 um 04:31 schrieb Martin Schwenke via samba-technical:  
> >   
> >>> It all looks quite simple.  However, I don't understand the need for
> >>> the --configfile option in:
> >>>
> >>>     net ads keytab \
> >>>       create --option='sync machine password script=' \
> >>>       --configfile="$CTDB_BASE/lib/server.conf"
> >>>
> >>> I'm wondering about disadvantages of using the default (of, say,
> >>> /etc/samba/smb.conf).  
> >>
> >> --option='sync machine password script=' is needed,
> >> as otherwise it would recurse itself, calling the script again.  
> > 
> > Thanks.  That one makes sense.
> > 
> > I'm wondering more about --configfile="$CTDB_BASE/lib/server.conf"
> > pointing to a file that doesn't usually exist...  
> 
> Isn't that just for make test?

I think that this is left over from trying to integrate into make test.

In local_daemons.sh mode (so in the clusteredmember testenv), there is
only a toy event script installed.  In
particular, 46.update-keytabs.script isn't installed. So, I think
source3/script/updatekeytab_test.sh is used during make test and it has
a similar thing with --configfile.

> I think instead it should just use the default
> and it should get the correct location via SMB_CONF_PATH,
> as lpcfg_load_internal() already exports that, and the selftest
> code should also export that.

I think the test could be extended to update the machine password while
one node is stopped.  To support this I can (mostly notes to self):

* Install the event script in this test - it is simple, so shouldn't be
  a problem.

* Add a script option, mostly for testing, to be able specify the
  server configuration (which would be set to $SMB_CONF_PATH when
  specified during test).

* Update onnode to handle "active" nodes as well as "connected" and
  "healthy".  This is fairly trivial.

* Update source3/script/updatekeytab_test.sh and
  source3/script/winbind_ctdb_updatekeytab.sh to only generate keytabs
  on active nodes.  "connected" is too weak, since a stopped node is
  connected but in recovery, so the net command won't be able to attach
  to the registry.

* Add a test case that stops a test node, updates the machine password,
  continues the test node, and then confirms that the test node has a
  valid keytab.  That way the event script is actually tested.

It is now on my todo list...  :-)

peace & happiness,
martin



More information about the samba-technical mailing list