[PATCHSET] Samba AD with MIT Kerberos

Andreas Schneider asn at samba.org
Mon Mar 13 07:29:37 UTC 2017


Hello,

after more than 3 years of work I finally got this:


	ALL OK (14658 tests in 2030 testsuites)


The testsuite completed for the first time!


The journey started with the cwrap [1] project to make it possible to test 
Samba with the MIT KDC. We already pushed some code upstream especially code 
which not only handles MIT Kerberos but also fixed bugs with Heimdal. We 
discovered a lot of issues while working on this code.

Attached is the patchset to implement the missing parts and get everything 
working.


 46 files changed, 3113 insertions(+), 507 deletions(-)


What isn't working yet
----------------------

* KDC canon tests are not implemented yet
* PKINIT
* S4U2SELF/S4U2PROXY
* RODC


The patches are also available at [2].


It requires MIT Kerberos 1.15.1! Packages for Fedora 25 can be found at [3].


Review is much appreciated!


Thanks,



	Andreas



[1] https://cwrap.org
[2] https://git.samba.org/?p=asn/samba.git;a=shortlog;h=refs/heads/master-mit-kdc-ok
[3] https://copr.fedorainfracloud.org/coprs/asn/samba_ad_dc/

-- 
Andreas Schneider                   GPG-ID: CC014E3D
Samba Team                             asn at samba.org
www.samba.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: samba_ad_mit_kdc.patch
Type: text/x-patch
Size: 205221 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20170313/eb87a193/samba_ad_mit_kdc-0001.bin>


More information about the samba-technical mailing list