[22918] in Kerberos

home help back first fref pref prev next nref lref last post

Re: samba keytab support for AD and kinit -k

daemon@ATHENA.MIT.EDU (Luke Howard)
Mon Nov 29 00:52:20 2004

From: Luke Howard <lukeh@padl.com>
Message-Id: <200411290551.iAT5p8ru079865@au.padl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
To: hartmans@mit.edu
Date: Mon, 29 Nov 2004 16:51:08 +1100
cc: rapatel@optonline.net
cc: samba-technical@lists.samba.org
cc: kerberos@mit.edu
Reply-To: lukeh@padl.com
Errors-To: kerberos-bounces@mit.edu


>    Rakesh> The issue is that in the Windows KDC, an SPN can not be
>    Rakesh> used as a "user" for authentication and computers normally
>    Rakesh> do not contain a UPN entry.  
>
>That is not my understanding of the Microsoft KDC architecture.  This
>claim also goes against interoperability tests I have conducted with
>Microsoft.

If I remember correctly, Rakesh is right. To do an AS-REQ you must
use the UPN or the SAM account name (regardless of the account type).

>Samba's handling of short names and Kerberos principals seems
>different than the Microsoft tools and tends to work much less of the
>time.  IT would be great to see it more consistent with the Windows
>domain join procedure.

There are a bunch of fixes in 3.0.9, YMMV.

-- Luke

--
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post