[Samba] Samba + Kerberos - ADS: possible?

Andrew Bartlett abartlet at samba.org
Wed Jun 16 02:44:12 GMT 2004

On Wed, 2004-06-16 at 02:35, Rodolfo Broco Manin wrote:
> Hi, All!!
> I have a Windows XP client configured to use Kerberos authentication (with
> a MIT KDC).  I configured it with ksetup.exe from Windows 2000 and it
> works well.
> Question is: can I use the kerberos tickets I got at logon time to access
> the shares from our samba server, without configuring a entire AD struct
> and soon?
> Actually, I can access the shares, but only if my kerberos password and my
> smbpasswd password are equals (that is, my Windows client is using NTLM
> authentication method to access it).
> Btw, I'm currently using "security = user" at samba server, and we don't
> have any Windows server (and this is the issue: is possible to use
> kerberos between Windows clients and Samba servers without any windows
> machines at the scenario?).

Currently not, but I do hope to correct this silly situation. (Which
will be helped by the kerberos keytab patch currently under
consideration for inclusion).

Andrew Bartlett

Andrew Bartlett                                 abartlet at pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba/attachments/20040616/fa4e16c3/attachment.bin

More information about the samba mailing list