[Samba] samba 3, ADS, kerberos, keytab problem - Additional pre-authentication required

Jim McDonough jmcd at us.ibm.com
Tue Mar 23 14:12:53 GMT 2004





>It works if I restart winbind regularly.
>Then new data from the ADS is integrated at once, if I set the winbind
>cache parameter in smb.conf. There's no need for another ticket, it
>seems to be created at joining the domain.
>But: If I do not restart winbind, the shared secret is gone after a
>certain time!?
Yes, I'm looking into this right now....as we cache the "connection" inside
winbind, so we don't have to continually re-authenticate, it seems we don't
ever time-out and renew the tickets.


----------------------------
Jim McDonough
IBM Linux Technology Center
Samba Team
6 Minuteman Drive
Scarborough, ME 04074
USA

jmcd at us.ibm.com
jmcd at samba.org

Phone: (207) 885-5565
IBM tie-line: 776-9984


More information about the samba mailing list