hello, linuxcaffe alum needs help with samba windows ad authentication

Lennart Sorensen lsorense-1wCw9BSqJbv44Nm34jS7GywD8/FfD2ys at public.gmane.org
Fri May 28 21:50:57 UTC 2010


On Fri, May 28, 2010 at 05:42:07PM -0400, Timothy Hildred wrote:
> I am a long time employee of the linuxcaffe at harbord and grace where I
> might have met some of you before. A mutual friend Jamon suggested i try
> here for advice when configuring samba to authenticate with kerberos on
> active directory. so here is my problem;
> kinit Administrator gives me a ticket
> net ads join -U Administrator gives me:
> libsmb/smb_signing.c:(253)   signing_good: BAD SIG: seq 1 Failed to join
> domain: Access denied #
> 
> however, when i do a kinit timadshare (which is a user i made in active
> directory) i get a ticket and can join the realm.
> Using short domain name -- RIGHT
> Joined 'TIMADSHARE' to realm 'RIGHT.AD.SP.COM'
> 
> wbinfo -u and -g both do what they ought, but neither getent group or passwd
> do.
> 
> i have been hacking at this for about a week now, and i think i might
> explode. any suggestions?

I wonder if kerberos was named after the hound of Hades for a reason... :)

I haven't dealt with kerberos for 10 years.  I remember it didn't make
sense then either.

-- 
Len Sorensen
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists





More information about the Legacy mailing list