If you use Kerberos and NTLM do not use the same AD account. Samba will update the AD account (e.g. change account password after x days) and msktutil does the same. So you will always have a problem if you do not use seperate AD accounts and there is nor reason to use the same.

Markus


"JC Putter" <[email protected]> wrote in message news:CAKKrXOnzPA0F20WfM05OiJPV=hs3azen0u+k56mht4eifwe...@mail.gmail.com...
If I rejoin the account using net ads join the RPC trust is
established as soon as you do a msktutil update the trust fails...

Anyone know of a workaround ?



On Fri, Feb 22, 2013 at 1:25 PM, JC Putter <[email protected]> wrote:
I followed the guide below as a starting point for my squid proxy,
however authentication fails after a day or so (i think due to account
reset)

I am using squid 3.2.6 with msktutil

ERROR: Negotiate Authentication validating user. Error returned 'BH
NT_STATUS_ACCESS_DENIED'

I am running a cronjob daily with msktutil --auto-update, but from the
message above this seems more like samba related issue.

anyone seen this or have suggestions ?


http://wiki.squid-cache.org/ConfigExamples/Authenticate/WindowsActiveDirectory



Reply via email to