[Samba] How to use kerberos as the default auth in AD config?

Shyam Kaushik shyam at zadarastorage.com
Fri Aug 17 12:35:46 UTC 2018


Hi Rowland,

No I dont have libpam-krb5 installed. Will try this. Thanks!

--Shyam

-----Original Message-----
From: Rowland Penny [mailto:rpenny at samba.org]
Sent: 17 August 2018 18:03
To: Shyam Kaushik
Cc: samba at lists.samba.org
Subject: Re: How to use kerberos as the default auth in AD config?

On Fri, 17 Aug 2018 17:54:49 +0530
Shyam Kaushik <shyam at zadarastorage.com> wrote:

> Hi Rowland,
>
> I tried both pam winbind & also samba with fix for CVE-2018-1139. But
> still cannot get windows 2016 "protected users" to work with samba.
>
> Note that "wbinfo --krb5auth" manages to authenticate. This I see it
> uses WINBIND_PAM_AUTH & not WINBIND_PAM_AUTH_CRAP. I dont see how to
> switch to WINBIND_PAM_AUTH instead of AUTH_CRAP. Any further
> insights? Thanks!
>

Do you have libpam-krb5 installed ?

Rowland



More information about the samba mailing list