[Samba] logging lines in krb5.conf

Jason Keltz jas at eecs.yorku.ca
Mon Oct 5 15:30:04 UTC 2020


Using MIT5 backend with Samba..

I'm wondering if anyone can provide some insight into the "logging" 
lines in krb5.conf.  By default, they don't exist.

I've seen mention of adding these lines:

  default = FILE:/var/log/krb5libs.log
  kdc = FILE:/var/log/krb5kdc.log
  admin_server = FILE:/var/log/kadmind.log

As far as I can tell, the "admin_server" lines don't apply to Samba 
because the DC doesn't seem to be running anything on the admin port (I 

Should these lines be on all the Linux AD clients, or does it only make 
sense to put these on the server?

Am I modifying /etc/krb5.conf on the server, or in the samba dir 

I added to /etc/krb5.conf on the server but the log files aren't being 
created.  I tried to stop and start the server process and it didn't 
make a difference.

I assumed that after running kinit, or SSHing from one system to 
another, I'd see lines show up in those logs (at least the kdc one).

Thanks for any suggestions.


