[Samba] design question for small environment

Stefan G. Weichinger lists at xunil.at
Mon Sep 10 10:35:28 UTC 2018


Am 10.09.18 um 11:12 schrieb Rowland Penny via samba:

> Hi Stefan, I would set up a small AD domain, one DC, and turn the two
> original servers into Unix domain members and then use kerberos.
> 
> I cannot think of any other way of not using passwords.

I won't get a third server for doing so. It could be a VM or container, 
though.

For now we discussed simply editing the batchfile to not contain the 
passwords and the users have to enter their (strong) pw at connection time.

Maybe set "/persistent: no" as well.

This would improve things, no readable passwords on the client anymore.



More information about the samba mailing list