Re: [Samba] Samba 3.0.0 Beta 3: krb5_cc_get_principal failed butJoin to realm successful?

2003-08-20 Thread Andrew Bartlett
On Wed, Aug 20, 2003 at 06:01:03PM +0200, Axel Suppantschitsch wrote:
 Hiya,
 
   as I was not capable of getting only close to join the RC1 of
 Samba 3.0 to my ADS realm, I downgraded to the Redhat 9.0 rpm version of
 Samba 3.0 Beta 3 from download.samba.org.
 
 With this package I get a lot closer to a working solution. Anyway,
 Kerberos is not working as supposed during the net ads join process
 which should leave a bunch of Kerberos credentials in the ticket cache.
 Not in my case, where the join of the ADS realm seems to be successful
 (Samba server is visible in Active Directory Users and Computers), but
 _NO_ Kerberos credetials are available at all due to an error...
 YES, I have changed the Administrator password after I raised the Win
 2003 Server to a Domain Controller! And YES, I already tried RC1 (I
 compiled the rpms exactly as instructed with the delivered spec file and
 the affiliated shell script (see post [Samba] Samba 3.0.0 RC1: Unable
 to find a suitable server)!
 
 Once again the process of the successful join to my ADS realm with the
 missing Kerberos credentials:

I think we do it all on a 'in memory' keytab now, so we don't store it about
after the join.

If you manually kinit I think it just uses that cache.

Andrew Bartlett
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba


RE: [Samba] Samba 3.0.0 Beta 3: krb5_cc_get_principal failed butJoin to realm successful?

2003-08-20 Thread Axel Suppantschitsch
Hi Andrew,

well, then smbclient //sambaserver/share -k should work if the
credentials are in the memory, but it doesn't as it can't find any
credentials...

The other way round I can't access the samba share from a windows client
without being asked for username and password. So both
after-ads-join-tests from the Samba documentation have failed in my
scenario...

Wbr,

Axel.


I think we do it all on a 'in memory' keytab now, so we don't store it
about after the join.

If you manually kinit I think it just uses that cache.

Andrew Bartlett

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba