[Samba] Trouble in ssh into Windows machines in the Windows/Samba Domain

Rowland penny rpenny at samba.org
Wed Apr 14 10:38:29 UTC 2021

On 14/04/2021 11:02, Nicola Mingotti via samba wrote:
> Hi Louis,
> from further experimentsI can tell you that in my system (Debian 
> Stable, Samba by .deb package)

I run Devuan against Raspbian and it works for myself without that file

> the only way to make the thing working is setting " 
> k5login_authoritative = false  " in [libdefaults].

No, the only way for you is by setting that line

> Not working if put in [realms].

I do not have it anywhere in /etc/krb5.conf

> I have taken the parameter name from here:
> https://web.mit.edu/kerberos/krb5-1.12/doc/admin/conf_files/krb5_conf.html 

Yes, but a Samba AD DC uses Heimdal, not MIT, unless you use a Fedora 
Samba AD DC and you shouldn't use one of those, they are experimental.

> It is a useful feature to have in some servers !

AD has a similar feature for all users, whatever way they attempt to login.


More information about the samba mailing list