On ke, 11 loka 2017, Kees Bakker via FreeIPA-users wrote:
On 11-10-17 01:05, Gordon Messmer via FreeIPA-users wrote:
On 10/04/2017 05:43 AM, Patrick No via FreeIPA-users wrote:
~~~~~~~~~~~~~~~~~~~~~~/etc/samba/smb.conf~~~~~~~~~~~~~~~~~~~~~~
security = ads



I'm working on Samba integration, as well.  I think you might need to use "security 
= USER".

Hmm, would you care to elaborate on this? All examples seem to suggest 
security=ads.
If you have a working IPA/SAMBA combination would you care to show your 
smb.conf global
section?

BTW. I am working (struggling is more appropriate) on a Samba server setup in 
our FreeIPA
environment. We're using Ubuntu 16.04, which has samba 4.3.11 and freeipa 4.3.1.
Trust setup will not work on Ubuntu where Samba compiled with Heimdal
Kerberos. Even if you are not establishing trust to AD itself,
ipa-adtrust-install sets up the plugins and configuration to properly
generate NT hashes and responders on IPA side. It implies and is only
working with Samba-on-IPA master when it is compiled with MIT Kerberos.

There is known bug on Launchpad.

Now that Samba 4.7.0 out and can be compiled with MIT Kerberos for AD DC
case too, Ubuntu may start recompiling their version to support MIT
Kerberos too but this is all in hands of the vendor, not IPA.
--
/ Alexander Bokovoy
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

Reply via email to