[22917] in Kerberos

home help back first fref pref prev next nref lref last post

Re: samba keytab support for AD and kinit -k

daemon@ATHENA.MIT.EDU (Sam Hartman)
Mon Nov 29 00:23:43 2004

To: Rakesh Patel <rapatel@optonline.net>
From: Sam Hartman <hartmans@mit.edu>
Date: Mon, 29 Nov 2004 00:21:41 -0500
In-Reply-To: <41AA7EBF.6090502@optonline.net> (Rakesh Patel's message of
 "Sun, 28 Nov 2004 20:43:27 -0500")
Message-ID: <87653p5ixm.fsf@luminous.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: samba-technical@lists.samba.org
cc: bob.smart@csiro.au
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>>>>> "Rakesh" == Rakesh Patel <rapatel@optonline.net> writes:

    Rakesh> Just limiting below to the main issue [note that I had not
    Rakesh> encountered this before when we went through various
    Rakesh> stages of testing the keytab management changes].

    Rakesh> Sam Hartman wrote:

    Rakesh> The issue is that in the Windows KDC, an SPN can not be
    Rakesh> used as a "user" for authentication and computers normally
    Rakesh> do not contain a UPN entry.
    >>  That is not my understanding of the Microsoft KDC
    >> architecture.  This claim also goes against interoperability
    >> tests I have conducted with Microsoft.
    >> 
    >> 
    >> 

    Rakesh> I have a machine "rockylinux" (FC3 - samba-3.0.8-0.pre1.3
    Rakesh> package) joined to an AD/2003 domain running Windows2003
    Rakesh> as the DC.
To clarify, what I meant here is simply that my experience is that
Windows machine accounts created by Windows tend to be set up to allow
the principal to be used both for inbound and outbound authentication.
Samba may well do something different.

--Sam

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post