[Samba] Re: newbie question reguarding kerberos tickets

simo idra at samba.org
Thu May 11 22:13:27 GMT 2006


Samba stores the machine password and obtains tickets from the KDC when
needed.

Simo.

On Thu, 2006-05-11 at 16:53 -0500, Doug Tucker wrote:
> Thanks.  But again, is the ticket even needed?  I deleted the darn
> thing, rebooted to make sure it wasn't cached in memory somewhere, and
> everything seems to be working perfectly.  If it is indeed needed, and I
> need to extend the period, is there any directions on how to do that on
> the windows side?
> 
> 
> On Thu, 2006-05-11 at 23:07 +0200, Blaž Primc wrote:
> > Hi,
> > 
> > the period for which the ticket is valid can be set in Windows Server.
> > 
> > Best regards, Blaž.
> > 
> > Doug Tucker wrote:
> > > I recently joined a samba 3.0.22 server to AD.  When I did the kinit,
> > > the AD gave me a 24 hour ticket with a 1 week renewal.  Setting -r and
> > > -l to 365d did not change anything, the ticket still came back the same.
> > > However, my question is in reguard to whether this is really even
> > > needed?  First, I deleted the ticket, and everything seemed to continue
> > > to work perfectly.  Now, I let the ticket expire for a couple of weeks
> > > now, and yet, the samba server is working fine and users still
> > > authenticate against AD just fine.  Am I missing something, or is the
> > > creation of that ticket not even needed?  Thank you for your assistance.
> > > 
> > > doug...
> > > 
> > 
> 
-- 
Simo Sorce
Samba Team GPL Compliance Officer
email: idra at samba.org
http://samba.org



More information about the samba mailing list