Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2020-02-12 Thread Alexander Bokovoy
On ke, 12 helmi 2020, Dario Lesca wrote: Il giorno mar, 11/02/2020 alle 21.35 +0200, Alexander Bokovoy ha scritto: There are few more missing parts here and there that need to beimplemented. They might affect some use cases and not others. At thispoint, I'd suggest to open bugs as you see them,

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2020-02-12 Thread Dario Lesca
Il giorno mar, 11/02/2020 alle 21.35 +0200, Alexander Bokovoy ha scritto: > There are few more missing parts here and there that need to > beimplemented. They might affect some use cases and not others. At > thispoint, I'd suggest to open bugs as you see them, this will help > us toclarify more

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2020-02-11 Thread Alexander Bokovoy
On ti, 11 helmi 2020, Dario Lesca wrote: Il giorno lun, 04/11/2019 alle 08.38 -0500, Neal Gompa ha scritto: The problem with the Samba team's advice is that it essentiallyprevents the MIT Kerberos AD-DC implementation from getting anybetter. Without people using it, we can't know what needs to

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2020-02-11 Thread Dario Lesca
Il giorno lun, 04/11/2019 alle 08.38 -0500, Neal Gompa ha scritto: > The problem with the Samba team's advice is that it > essentiallyprevents the MIT Kerberos AD-DC implementation from > getting anybetter. Without people using it, we can't know what needs > to be fixed.The Red Hat FreeIPA team

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-09 Thread Dario Lesca
Il giorno gio, 07/11/2019 alle 10.27 +, Sérgio Basto ha scritto: > I can help you here as I'm a Fedora packager maintainer . > > Have you Pull request and BugZilla reports with that information Nico, have you filled the BugZilla Request suggested by Sérgio? For rebuild last samba package

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-07 Thread Simo Sorce
On Mon, 2019-11-04 at 20:45 -0500, Nico Kadel-Garcia wrote: > On Mon, Nov 4, 2019 at 8:39 AM Neal Gompa wrote: > > > The problem with the Samba team's advice is that it essentially > > prevents the MIT Kerberos AD-DC implementation from getting any > > better. Without people using it, we can't

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-07 Thread Sérgio Basto
On Wed, 2019-11-06 at 23:28 -0500, Nico Kadel-Garcia wrote: > On Wed, Nov 6, 2019 at 1:00 PM Dario Lesca > wrote: > > Il giorno mer, 06/11/2019 alle 09.03 -0500, Nico Kadel-Garcia ha > > scritto: > > > > Can the Fedora samba maintainers do that? > > > > > > > > Thank > > > > > > > > > > They

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-07 Thread Alexander Bokovoy
On ke, 06 marras 2019, Scott Schmit wrote: On Mon, Nov 04, 2019 at 03:14:34PM +0100, Dario Lesca wrote: Il giorno lun, 04/11/2019 alle 08.38 -0500, Neal Gompa ha scritto: > What defines it as experimental? https://wiki.samba.org/index.php/Running_a_Samba_AD_DC_with_MIT_Kerberos_KDC > Using MIT

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Alexander Bokovoy
On ke, 06 marras 2019, Nico Kadel-Garcia wrote: On Wed, Nov 6, 2019 at 1:00 PM Dario Lesca wrote: Il giorno mer, 06/11/2019 alle 09.03 -0500, Nico Kadel-Garcia ha scritto: > > Can the Fedora samba maintainers do that? > > > > Thank > > > > They are very welcome to my work. > Then why do not

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Scott Schmit
On Mon, Nov 04, 2019 at 03:14:34PM +0100, Dario Lesca wrote: > Il giorno lun, 04/11/2019 alle 08.38 -0500, Neal Gompa ha scritto: > > What defines it as experimental? > > https://wiki.samba.org/index.php/Running_a_Samba_AD_DC_with_MIT_Kerberos_KDC > > Using MIT Kerberos is still considered

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Nico Kadel-Garcia
On Wed, Nov 6, 2019 at 1:00 PM Dario Lesca wrote: > > Il giorno mer, 06/11/2019 alle 09.03 -0500, Nico Kadel-Garcia ha > scritto: > > > Can the Fedora samba maintainers do that? > > > > > > Thank > > > > > > > They are very welcome to my work. > > > > Then why do not use your samba.spec for build

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Dario Lesca
Il giorno mer, 06/11/2019 alle 09.03 -0500, Nico Kadel-Garcia ha scritto: > > Can the Fedora samba maintainers do that? > > > > Thank > > > > They are very welcome to my work. > Then why do not use your samba.spec for build official samba package at least on Fedora? It already contain the

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Nico Kadel-Garcia
> Waiting for MIT kerberos to become stable and supported from samba > team, a simple solution is insert into official samba.spec, a flag for > easily rebuild it with heimdal kerberos, without substitute or modify > the .spec file. > > Something like this: > > $ rpmbuild --rebuild --with heimdal

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-06 Thread Dario Lesca
Il giorno mer, 06/11/2019 alle 08.52 +0100, Franta Hanzlík ha scritto: > If I can speak for myself and for the Linux people I know, nobody > needs a FreeIPA, and many need a Samba AD DC. And of course they want > a stable solution if possible. > > The current situation leads to either choosing a

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-05 Thread Franta Hanzlík
On Mon, 4 Nov 2019 20:56:13 -0600 Chris Adams wrote: > Once upon a time, Nico Kadel-Garcia said: > > Without robust integration with AD, I have no use > > for FreeIPA. And I don't know *anyone* who uses a FreeIPA server. > > > > Perhaps it's time to drop FreeIPA? > > Nope. You are assuming

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Chris Adams
Once upon a time, Nico Kadel-Garcia said: > Without robust integration with AD, I have no use > for FreeIPA. And I don't know *anyone* who uses a FreeIPA server. > > Perhaps it's time to drop FreeIPA? Nope. You are assuming the everybody needs AD... lots of people have no use for AD and just

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Neal Gompa
On Mon, Nov 4, 2019 at 8:46 PM Nico Kadel-Garcia wrote: > > On Mon, Nov 4, 2019 at 8:39 AM Neal Gompa wrote: > > > The problem with the Samba team's advice is that it essentially > > prevents the MIT Kerberos AD-DC implementation from getting any > > better. Without people using it, we can't

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Adam Williamson
On Mon, 2019-11-04 at 20:45 -0500, Nico Kadel-Garcia wrote: > On Mon, Nov 4, 2019 at 8:39 AM Neal Gompa wrote: > > > The problem with the Samba team's advice is that it essentially > > prevents the MIT Kerberos AD-DC implementation from getting any > > better. Without people using it, we can't

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Nico Kadel-Garcia
On Mon, Nov 4, 2019 at 8:39 AM Neal Gompa wrote: > The problem with the Samba team's advice is that it essentially > prevents the MIT Kerberos AD-DC implementation from getting any > better. Without people using it, we can't know what needs to be fixed. > The Red Hat FreeIPA team has been

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Alexander Bokovoy
On ma, 04 marras 2019, Dario Lesca wrote: Too many people (like also me) try to use samba-dc on fedora for deploy a production AD DC controller, without know that MIT kerberos is experimental and some useful things cannot work (es. win to win access). An recent last example:

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Dario Lesca
Il giorno lun, 04/11/2019 alle 08.38 -0500, Neal Gompa ha scritto: > What defines it as experimental? https://wiki.samba.org/index.php/Running_a_Samba_AD_DC_with_MIT_Kerberos_KDC > Using MIT Kerberos is still considered experimental. -- Dario Lesca (inviato dal mio Linux Fedora 30 Workstation)

Re: Please, IMHO, resolve in some way the Samba MIT kerberos problem.

2019-11-04 Thread Neal Gompa
On Mon, Nov 4, 2019 at 8:33 AM Dario Lesca wrote: > > Too many people (like also me) try to use samba-dc on fedora for deploy > a production AD DC controller, without know that MIT kerberos is > experimental and some useful things cannot work (es. win to win > access). > > An recent last example: