Yes the "net ads keytab create" created the keytab file now. But in the logs i can see that the encryption type used is not good:
Apr 2 12:37:18 rhel4wbtest1 sshd[4542]: pam_krb5: error reading keys for host/rhel4wbtest2.vegagroup.net from /etc/krb5/krb5.keytab: Bad encryption type Apr 2 12:37:18 rhel4wbtest1 sshd[4542]: pam_krb5: authentication fails for `tuser' does winbind by default use: rc4-hmac? -----Original Message----- From: Guenther Deschner [mailto:[EMAIL PROTECTED] Sent: 02 April 2008 11:39 To: Oliver Weinmann Cc: [email protected] Subject: Re: [Samba] Urgent... winbind and keytab file creation -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Oliver Weinmann wrote: > Hi, > > I'm running winbind (3.0.28a) on SLES9 with heimdal Kerberos. Everything > works fine so far. Now i need to have the host keytab generated by winbind to > be in the default /etc/krb5/krb5.keytab in order to use nfs with kerberos > security. The problem is i have set the parameter in smb.conf: > > use kerberos keytabe = true > > and as mentioned in man smb.conf i have set in krb5.conf > > default_keytab_name = FILE:/etc/krb5/krb5.keytab > > after a "net join ads" the krb5.keytab file is not created? do i have to > create it myself? Is this not really implemented? What am I doing wrong? Have you tried "net ads keytab create" ? Guenther - -- Günther Deschner GPG-ID: 8EE11688 Red Hat [EMAIL PROTECTED] Samba Team [EMAIL PROTECTED] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFH81Q/SOk3aI7hFogRAo9oAJ9olnYtnTFteNgF6jVpK/xdh9be8gCeNHVP WjEvra9U//Tj25Y8hFjnDwg= =peli -----END PGP SIGNATURE----- ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/listinfo/samba
