On Sat, 2004-09-25 at 03:45, Bruce Marriner wrote:
>      I have a Samba 3 server running as my domain controller and want to 
> configure it to authenticate user passwords off a MIT KDC server that
> is already up and running. 

What are the clients?  How do they get their kerberos tickets?

Such a setup is possible, and I've attached my proposed patch.  

To use the patch export kerberos keys into the local keytab for
cifs/hostname@, and (I think) [EMAIL PROTECTED]  Then set 'kerberos use keytab
= yes' in your smb.conf.

What will not work however is clients that expect to do an NTLM login,
and have us somehow pass that to a KDC.

Another option is my patch and the Heimdal snapshots with Samba support,
which can allow Samba to use it's password DB for NTLM logins, and for
Heimdal to use the same password database for kerberos tickets.

Andrew Bartlett

-- 
Andrew Bartlett                                 [EMAIL PROTECTED]
Authentication Developer, Samba Team            http://samba.org
Student Network Administrator, Hawker College   [EMAIL PROTECTED]

Attachment: signature.asc
Description: This is a digitally signed message part

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

Reply via email to