[Samba] Linux client of the domain - SSSD : authenticating via Kerberos
steve
steve at steve-ss.com
Fri Dec 20 07:00:19 MST 2013
On Fri, 2013-12-20 at 14:40 +0100, Cyril wrote:
> Le 20/12/2013 14:19, steve a écrit :
> > On Fri, 2013-12-20 at 10:37 +0100, Cyril wrote:
> >
> >> kinit myserver$@SUBDOMAIN.DOMAIN.FR
> >> It also ask me a password but the admin's one doesn't work.
> >>
> >
> > Eh? You don't need a password. You already have the key!
> > kinit -k -t /etc/krb5.sssd.keytab myserver$
> >
> > Could you post the output of that command?
> >
>
> That give me nothing. No error, no warning.
> It didn't ask me anypassword
>
OK. So it worked.
>
> >> Am-I suppose to create this principal myserver$@SUBDOMAIN.DOMAIN.FR
> >> first before generating the keytab on the DC ?
> >>
> > You already have the principal. It was created when you joined the
> > machine to the domain.
>
> Ho, you mean joining the myserver machine !
>
No, I'm sorry. The post crossed. I now know that the machine is not
joined to the domain using samba. You do somehow however, have a key for
the machine.
And, from your other posts, your domain users can now authenticate on
the Linux client.
Cheers,
Steve
More information about the samba
mailing list