[Samba] pam_winbind

Gerald (Jerry) Carter jerry at samba.org
Wed Aug 29 12:08:52 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ken Moberg wrote:

> Is there a flavor of the pam_winbind module 
> that uses Challenge/Response (CRAP) for authentication?

Nope.  Because Every PAM enabled app I'm aware of likes to use the
username/password.

> I have samba-3.0.25 and the pam_winbind module only does cleartext. 
> This fails when trying to authenticate against AD.

I"m curious why it fails for you.  Internally winbindd still
does with the Kerb5 AS_REQ or NTLM auth on behavior of the user
to AD.


> I'd like to switch our app from using ntlm_auth to pam. I
> did a quick hack an added winbind_auth_request_crap() and 
> it works, but I'm wondering if anyone else has already
> done this.

Nope.  Is this a custom app?





cheers, jerry
=====================================================================
Samba                                    ------- http://www.samba.org
Centeris                         -----------  http://www.centeris.com
"What man is a man who does not make the world better?"      --Balian
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG1WHUIR7qMdg1EfYRAquiAKCXgmmdL5th8ZTIDhK9gIf6JLBlyQCg8o7m
uzujQrq4ZEetPpGfjxdu7Uk=
=fTGN
-----END PGP SIGNATURE-----


More information about the samba mailing list