Gémes Géza geza at kzsdabas.sulinet.hu
Sun Mar 21 12:33:12 GMT 2004

| The heimdal patches were a different thing - in that case Samba is not
| actually using Kerberos at all (but it is part of my plan to allow it).
| As to looking like AD, there is much more to AD than LDAP+kerberos.  But
| that does not stop us making a good stab at making LDAP+Kerberos viable
| for unix clients, which we have some control over...

OK, sorry for my quite confusing reply, what I was really interested in
is if Samba as an AD client would use the information contained in MS
PAC, or after getting the ticket would do an LDAP lookup, to get the
authorization(SIDS)/account(HomeDrive,etc) informations?
In the later case a correctly configured Heimdal/LDAP could simulate an
AD (except MSRPC calls) for Samba (but not Windows :-( )



My question could be reformulated: what is needed to have a UNIX AD (!)
signs where work has to be done?
- -LDAP with multimaster(!) replication
- -Kerberos with LDAP backend, with NTLM hashes (Loriket) and MSPAC(!)
- -DNS with LDAP backend, and Kerberos authenticated updates(!)
- -DHCP server
- -NTP server
- -New MSRPC calls in Samba(!)
- -Anything else?
