[EMAIL PROTECTED] wrote:
> I had something similar, I had to include all relevant kdcs in the realms
> section of krb5.conf to Authenticate from trusted domains to the domain the
> member server is in
>   
Bless you my son! That appears to have done the trick. Now to
thrash-test it :-)

I must say it surprises me. I know I can easily deduce the same values
that I just put into krb5.conf via some DNS lookups - I thought Samba
would have done the same... (actually you don't even need DNS for that:
Under ADS, realm == fqdn)


Thanks!

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Reply via email to