[Samba] Samba 4.2.14 Group Policy (GPO) sync error

Rowland Penny rpenny at samba.org
Thu Aug 4 20:33:51 UTC 2016

On Thu, 4 Aug 2016 21:14:39 +0200
rme at bluemail.ch wrote:

> Hello Rowland,
> > No its not, its fairly easy, once you get your head around it. I
> > have been using something based on that webpage for nearly 4 years
> > now and only had self inflicted problems.
> Thanks for the heads-up. Perhaps my wording wasn't very good on it. I 
> would actually just prefer something built-in into BIND rather than 
> using an external script. That's why I was hoping for something like
> the krb5 grant. So as I understood you're using the script method
> instead. Is it because at the time you put your solution in place
> there was no support for Kerberos in BIND or is it because you
> investigated and found BIND not to support authorization via Kerberos
> and Samba?

No, the kerberos support was built into Bind, but it isn't Bind that
runs the script, it is DHCP.

> Perhaps somebody knows more about the Kerberos support in BIND and
> can point me to a guide. Else I will likely go for the external
> script solution as well for production.

Windows can update the forward zone, but, if I understand it correctly,
it doesn't update the reverse zone, Unix clients does neither


More information about the samba mailing list