[Samba] Winbind with krb5auth for trust users

Andreas Hauffe andreas.hauffe at tu-dresden.de
Tue Aug 22 07:36:15 UTC 2017


Hi,

I'm having trouble realizing a krb5auth with pam_winbind with trusted 
domain users (external trust) on our clients. The client is joined to a 
local domain, which has a "external trust" to a global domain.

The following things are working for all users (local and trusted domain):

"wbinfo -i"
"wbinfo --pam-logon"
"wbinfo -a"
"kinit"


Just "wbinfo -K" works only for local domain users. And that is the 
problem. I need the Kerberos ticket for NFS.

smb.conf, krb5.conf and the other configs are taken from 
https://wiki.samba.org/index.php/Setting_up_Samba_as_a_Domain_Member. 
Just changed the domain/realm name to the local domain name.

Regards
Andreas




More information about the samba mailing list