[Samba] How to use kerberos as the default auth in AD config?

Rowland Penny rpenny at samba.org
Fri Aug 17 12:32:59 UTC 2018


On Fri, 17 Aug 2018 17:54:49 +0530
Shyam Kaushik <shyam at zadarastorage.com> wrote:

> Hi Rowland,
> 
> I tried both pam winbind & also samba with fix for CVE-2018-1139. But
> still cannot get windows 2016 "protected users" to work with samba.
> 
> Note that "wbinfo --krb5auth" manages to authenticate. This I see it
> uses WINBIND_PAM_AUTH & not WINBIND_PAM_AUTH_CRAP. I dont see how to
> switch to WINBIND_PAM_AUTH instead of AUTH_CRAP. Any further
> insights? Thanks!
> 

Do you have libpam-krb5 installed ?

Rowland



More information about the samba mailing list