[Samba] Cache auth credentials on Samba domain member

Jeremy Allison jra at samba.org
Thu Jun 1 17:42:42 UTC 2017


On Thu, Jun 01, 2017 at 03:11:53PM +0200, Gionatan Danti wrote:
> Il 01-06-2017 14:45 Data Control Systems - Mike Elkevizth ha scritto:
> >I've had issues with cached credentials with the Ubuntu packages that
> >are currently at version 4.3.11.  They are a little old, but I haven't
> >seen any change logs for the newer versions specifically regarding
> >this issue.  Maybe I've missed it, but it's the main reason I continue
> >using sssd.
> >
> >Mike E.
> >
> >On Thu, Jun 1, 2017, 2:08 AM Gionatan Danti via samba
> ><samba at lists.samba.org> wrote:
> >
> 
> I tried with sssd also, but with the same result: if connection to
> the main (remote) AD server is down, samba does not authenticate
> users. To recap my setup:
> 
> DOMAIN CONTROLLER (Win2003) <-> VPN TUNNEL <-> REMOTE SAMBA SERVER
> <-> REMOTE CLIENTS
> 
> If the VPN tunnel goes down, the remote samba server stop
> authenticating users. It does not seem a winbind or sssd problem,
> after all: severing the VPN connection, user authentication *outside
> samba shares* work correctly (I confirmed it by logging in via SSH
> using domain credential).
> 
> However, *no* user authentication is possible on samba shares when
> the VPN tunnel is down?
> 
> Do you have any suggestions?

I think Uri and Volker did the work on this. Uri, can you
give an update on where we stand with offline auth and
winbindd ?

Thanks,

Jeremy.



More information about the samba mailing list