[Samba] Samba 3.0.6 Problems w/AD and Kerberos

Tom Ryan tomryan at camlaw.rutgers.edu
Wed Sep 8 19:28:13 GMT 2004


I found that if you use the FQDN it works.. (which was not acceptable to
us).. we (unfortuantely) went to security = domain.

Tom

On Wed, 8 Sep 2004, Blindauer Emmanuel wrote:

> Le dimanche 05 Septembre 2004 13:38, Christian Merrill a écrit :
> > Running into a lot of people upgrading to the 3.0.6 package that all
> > of a sudden begin to experience the "Failed to verify incoming
> > ticket!" errors etc., that are generally associated with a kerberos
> > package incompatibility.
> >
> > However many of these people are running later versions of kerberos
> > *and* reverting to a previous version of Samba appears to fix the
> > issue.  Is there something new setting wise that has taken place, is
> > something really wrong with this new package, or is this all just a
> > strange coincidence?
> >
> > Christian
> I confirm the problem:
> I'm running win2k SP4, AD, mixed mode, no other special conf.
> the samba is 3.0.6, compiled from sources. I use winbind too.
> winbind has some "  krb5_cc_get_principal failed (No credentials cache found)"
> but nothing special.
> but the samba daemon get, for some users,
> "smbd/sesssetup.c:reply_spnego_kerberos(173)
> Failed to verify incoming ticket "
> and this prevent user from acceding their share.
> the used kerberos is 1.3.4
>
> The 2000 domain has been started from scratch, no NT4 migration.
>
> Emmanuel
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  http://lists.samba.org/mailman/listinfo/samba
>

_______________________________________________________________________
Tom Ryan                                            Voice: 856-225-6361
Consulting System Administrator                       Fax: 856-969-7900
Rutgers School of Law - Camden               IT Help Desk: 856-225-2343


More information about the samba mailing list