Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-06 Thread Alexander Bokovoy
On Mon, 06 Jun 2016, lejeczek wrote: Users mapping concept (which I do not grasp completely yet) - when an AD client (win10) now gets to samba shares okey it is done with AD user credentials, win client sees share like: u...@my.dom which user is not IPA's user (there are no trusts no syncing).

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-06 Thread lejeczek
On 06/06/16 12:42, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, lejeczek wrote: SMB services with Kerberos require use of cifs/ service principal. Your keytab only has host/ keys, and your AD machine account for the does not have 'cifs/' SPN defined. The latter is what causes smbclient -k

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-06 Thread Alexander Bokovoy
On Mon, 06 Jun 2016, lejeczek wrote: SMB services with Kerberos require use of cifs/ service principal. Your keytab only has host/ keys, and your AD machine account for the does not have 'cifs/' SPN defined. The latter is what causes smbclient -k to fail -- AD DC doesn't know about 'cifs/' and r

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-06 Thread lejeczek
On 03/06/16 17:00, Alexander Bokovoy wrote: On Fri, 03 Jun 2016, lejeczek wrote: On 03/06/16 15:22, Alexander Bokovoy wrote: On Fri, 03 Jun 2016, lejeczek wrote: hi users, I have a samba and sssd trying AD, it's 7.2 Linux. That linux box is via sssd and samba talking to AD DC and win10

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-03 Thread Alexander Bokovoy
On Fri, 03 Jun 2016, lejeczek wrote: On 03/06/16 15:22, Alexander Bokovoy wrote: On Fri, 03 Jun 2016, lejeczek wrote: hi users, I have a samba and sssd trying AD, it's 7.2 Linux. That linux box is via sssd and samba talking to AD DC and win10 clients get to samba shares, getent pass sees A

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-03 Thread lejeczek
On 03/06/16 15:22, Alexander Bokovoy wrote: On Fri, 03 Jun 2016, lejeczek wrote: hi users, I have a samba and sssd trying AD, it's 7.2 Linux. That linux box is via sssd and samba talking to AD DC and win10 clients get to samba shares, getent pass sees AD users, samba can get to DC's shares

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-03 Thread lejeczek
On 03/06/16 15:11, Sumit Bose wrote: On Fri, Jun 03, 2016 at 02:39:00PM +0100, lejeczek wrote: hi users, I have a samba and sssd trying AD, it's 7.2 Linux. That linux box is via sssd and samba talking to AD DC and win10 clients get to samba shares, getent pass sees AD users, samba can get to

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-03 Thread Alexander Bokovoy
On Fri, 03 Jun 2016, lejeczek wrote: hi users, I have a samba and sssd trying AD, it's 7.2 Linux. That linux box is via sssd and samba talking to AD DC and win10 clients get to samba shares, getent pass sees AD users, samba can get to DC's shares and win10's clients shares, all good except...

Re: [Freeipa-users] a bit off topic- samba + sssd => AD

2016-06-03 Thread Sumit Bose
On Fri, Jun 03, 2016 at 02:39:00PM +0100, lejeczek wrote: > hi users, > > I have a samba and sssd trying AD, it's 7.2 Linux. > > That linux box is via sssd and samba talking to AD DC and win10 clients get > to samba shares, getent pass sees AD users, samba can get to DC's shares and > win10's cli