hello, linuxcaffe alum needs help with samba windows ad authentication
Lennart Sorensen
lsorense-1wCw9BSqJbv44Nm34jS7GywD8/FfD2ys at public.gmane.org
Fri May 28 21:50:57 UTC 2010
On Fri, May 28, 2010 at 05:42:07PM -0400, Timothy Hildred wrote:
> I am a long time employee of the linuxcaffe at harbord and grace where I
> might have met some of you before. A mutual friend Jamon suggested i try
> here for advice when configuring samba to authenticate with kerberos on
> active directory. so here is my problem;
> kinit Administrator gives me a ticket
> net ads join -U Administrator gives me:
> libsmb/smb_signing.c:(253) signing_good: BAD SIG: seq 1 Failed to join
> domain: Access denied #
>
> however, when i do a kinit timadshare (which is a user i made in active
> directory) i get a ticket and can join the realm.
> Using short domain name -- RIGHT
> Joined 'TIMADSHARE' to realm 'RIGHT.AD.SP.COM'
>
> wbinfo -u and -g both do what they ought, but neither getent group or passwd
> do.
>
> i have been hacking at this for about a week now, and i think i might
> explode. any suggestions?
I wonder if kerberos was named after the hound of Hades for a reason... :)
I haven't dealt with kerberos for 10 years. I remember it didn't make
sense then either.
--
Len Sorensen
--
The Toronto Linux Users Group. Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists
More information about the Legacy
mailing list