Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

[Samba] AD multiple domain logon and problems with Kerbero..

 
   Soft32 Home -> Linux -> Samba RSS
Next:  [Samba] HPUX 10.20  
Author Message
Harvey

External


Since: Jan 09, 2004
Posts: 1



(Msg. 1) Posted: Fri Jan 09, 2004 1:10 pm
Post subject: [Samba] AD multiple domain logon and problems with Kerberos File Server authorization using SMB
Archived from groups: linux>samba (more info?)

Hi all,

I have configured the AD plug-in with the corresponding Forest, Domain
to accept multiple domain authentication. The authentication option in
Directory Access does have the root domain added as a custom path (the
edu.Mit.Kerberos file has all domains configured, and each domain has 2
entries that are “kdc” and “admin_server”).

A user belonging to the same configured Domain can login successfully,
however when a user from another domain tries to login, the login
window shakes and as result the user cannot enter his session. Has
anyone got this multiple domain authentication to work?

When a user belongs to the configured domain and logs-in, he
automatically gets a Kerberos ticket. Depending on the file server the
user connects to, two different scenarios take place. In the first
scenario, the user connects the FS and is authenticated by the Kerberos
protocol as it should normally. In the second scenario, the user
connects to another file server in the same domain as the user, and a
SMB/CIFS authentication window appears asking user, password and
domain. If, in this window user, password and domain are left blank,
and the OK button is clicked, then surprisingly the user is also
authenticated by the Kerberos protocol. By doing some network sniffing,
apparently the Kerberos protocol gets the correct name of file server
and in consequence obtains a ticket for it only after SAMBA has figured
out the correct file server name. Is it possible to resolve this issue
so that the SMB/CIFS authentication window does not appear?

Additionally, It is not possible for any Mac to authenticate correctly
using Kerberos to any file server in any other domains. No error
entries in the console.log or System.log have been found.

How should Windows Clusters of two physical PCs and N logical servers
be configured to accept Kerberos authentication from the Mac? The
problem is that the virtual server name is not in the Kerberos
database, but the machine account is. However nobody enters a web page
by typing the machine account, they all are aliases.

These test were performed with 5 different Macs, some having Mac OS X
v10.3.1 and other having 10.3.2, but the same results have been seen in
either one.

Thanks in advanced
Harvey--
To unsubscribe from this list go to the following URL and read the
instructions: http://lists.samba.org/mailman/listinfo/samba
Back to top
Login to vote
Display posts from previous:   
Related Topics:
[Samba] Samba 3.0.0 & LDAP: multiple domains logon - Hello, If you use samba 3.0.0 with LDAP authentication, samba uses an ldap attribute "sambaSID" in which th...

[Samba] Can domain logon requests handled by Samba Configu.. - Hi Windows NT as Backup domain controller can participate in the logon process. When a user logs on to a domain, the....

[Samba] domain-membership problem (joinging/logon) - Hello, for a long period of time we experienced a serious problem concerning the domain memberships of some of our..

[Samba] Problem logon WinXP SP2 to samba domain - After installation Windows XP SP2, have come in domain Samba 2.2.8. After rebooting, at an logon to domain have receive...

[Samba] PDC + LDAP + W2K-SP4 Domain logon - Dear all, ___Setup: - several wINDOWS 2000 workstations on SP4 (reg-patches applied, they worked on 2.x-stable) -..

[Samba] RE: PDC + LDAP + W2K-SP4 Domain logon - This is strange that it worked for you, because testparm tells me that if you use "wins support = yes" &&...
       Soft32 Home -> Linux -> Samba All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
  Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]