[Samba] Winbind with krb5auth for trust users

Andreas Hauffe andreas.hauffe at tu-dresden.de
Tue Aug 22 07:36:15 UTC 2017


I'm having trouble realizing a krb5auth with pam_winbind with trusted 
domain users (external trust) on our clients. The client is joined to a 
local domain, which has a "external trust" to a global domain.

The following things are working for all users (local and trusted domain):

"wbinfo -i"
"wbinfo --pam-logon"
"wbinfo -a"

Just "wbinfo -K" works only for local domain users. And that is the 
problem. I need the Kerberos ticket for NFS.

smb.conf, krb5.conf and the other configs are taken from 
Just changed the domain/realm name to the local domain name.


More information about the samba mailing list