[Samba] Kerberos requirements for Samba and AD Membership

Gerald (Jerry) Carter jerry at samba.org
Wed Jun 8 18:45:00 GMT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Andy Pierce wrote:
|>But if you want kerberos, make sure you have
|>current MIT or heimdal libs and OpenLDAP 2.2.x
|>client libraries.  Samba will need to link
|>against these.
|
|
| Thanks Jerry. Is there a specific level of
| Kerberos from eith MIT or Heimdal? For example, do
| I need to have a least version 5-1.4.x or something?
| The reason this is important to me is that the sysadmin
| tells me that AIX comes with an implementation of
| Kerberos but I don't know which one and from what
| vendor. Seems I read somewhere that it is a subset of
| MIT. If I can't tell them a version, they'll hammer
| me and say they can't move forward until I can
| answer that question.

For MIT either the latest 1.3.x or 1.4.x release should
be ok.  the 1.2.x releases will work but only with DES
keys.

| Also, is OpenLDAP 2.2.x a requirement? I have not
| seen that mentioned elsewhere. Again, I am
| not wanting to BE the directory on AIX but only
| be a member of the directory. Does that make sense?

You need the OpenLDAP 2.x client libs only.  Not an
actually OpenLDAP slapd installation.




cheers, jerry
=====================================================================
Alleviating the pain of Windows(tm)      ------- http://www.samba.org
GnuPG Key                ----- http://www.plainjoe.org/gpg_public.asc
"I never saved anything for the swim back."     Ethan Hawk in Gattaca
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCpzysIR7qMdg1EfYRApY7AKCahT+Fmhb8pCv2nMkvwFjxiLYrMgCeIo29
9odRP2bmt+zhDN4Wnoi8zrg=
=iS7G
-----END PGP SIGNATURE-----


More information about the samba mailing list