[Samba] Samba + Kerberos - ADS: possible?

Andrew Bartlett abartlet at samba.org
Wed Jun 16 02:44:12 GMT 2004


On Wed, 2004-06-16 at 02:35, Rodolfo Broco Manin wrote:
> Hi, All!!
> 
> I have a Windows XP client configured to use Kerberos authentication (with
> a MIT KDC).  I configured it with ksetup.exe from Windows 2000 and it
> works well.
> 
> Question is: can I use the kerberos tickets I got at logon time to access
> the shares from our samba server, without configuring a entire AD struct
> and soon?
> 
> Actually, I can access the shares, but only if my kerberos password and my
> smbpasswd password are equals (that is, my Windows client is using NTLM
> authentication method to access it).
> 
> Btw, I'm currently using "security = user" at samba server, and we don't
> have any Windows server (and this is the issue: is possible to use
> kerberos between Windows clients and Samba servers without any windows
> machines at the scenario?).

Currently not, but I do hope to correct this silly situation. (Which
will be helped by the kerberos keytab patch currently under
consideration for inclusion).

Andrew Bartlett

-- 
Andrew Bartlett                                 abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba/attachments/20040616/fa4e16c3/attachment.bin


More information about the samba mailing list