[Samba] Users cannot change their passwords
rpenny at samba.org
Tue Sep 25 15:00:54 UTC 2018
On 25 Sep 2018 10:45:46 -0400
Konstantin Boyandin via samba <samba at lists.samba.org> wrote:
> On 25.09.2018 15:44, Rowland Penny via samba wrote:
> > On Mon, 24 Sep 2018 21:22:06 GMT
> > "Torin Woltjer" <torin.woltjer at granddial.com> wrote:
> >> Thanks for the quick reply, I believe I am using MIT based on log
> >> file names; but is there a better way to tell? I'm not very
> >> knowledgeable about the distinction between MIT and Heimdal
> >> regarding KDC. Can you direct me to a resource that explains how
> >> to make the switch as I am just using the defaults in SUSE.
> >> Additionally, many of the domains experiencing this bug were
> >> working fine; before migrating them from Ubuntu 16.04. Is this
> >> because the bug was introduced in a newer version that I am now
> >> using? Is the bug fixed in a version newer than what I am using
> >> now?
> >> Thanks again, I appreciate the help.
> >> Torin Woltjer
> >> Grand Dial Communications - A ZK Tech Inc. Company
> >> 616.776.1066 ext. 2006
> >> www.granddial.com
> > Took some finding, but I am now very sure that the opensuse Samba
> > AD DC uses MIT instead of Heimdal, so this makes it inadvisable to
> > use in production. There are just too many problems to make it
> > usable, the password problem being one of them.
> > I am sorry, but, as far as I am aware, there is no RPM based distro
> > that has production ready Samba packages, I also have a feeling that
> > the Ubuntu packages now use MIT, so this really just leaves Debian
> > etc.
> I am using Ubuntu 18.04. Both MIT and Heimdal strains of Kerberos are
> available from standard repositories and can be installed
> simultaneously, FWIK.
Well possibly, but Samba would only use one and I don't think running
two kdc's on one server is a good idea.
More information about the samba