[22935] in Kerberos
Re: samba keytab support for AD and kinit -k
daemon@ATHENA.MIT.EDU (Luke Howard)
Mon Nov 29 21:53:21 2004
From: Luke Howard <lukeh@padl.com>
Message-Id: <200411300252.iAU2q9cd037261@au.padl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
To: rapatel@optonline.net
Date: Tue, 30 Nov 2004 13:52:09 +1100
cc: hartmans@mit.edu
cc: samba-technical@lists.samba.org
cc: rapatel@rapatel.homeip.net
cc: kerberos@mit.edu
Reply-To: lukeh@padl.com
Errors-To: kerberos-bounces@mit.edu
>Unfortunately it looks like 3.0.9, while providing the host services
>that use the keytab with all combinations of
>keytab entries to match the Windows 2003/AD SPN and UPN combinations,
>does not address this issue. The UPN
>is still registered as HOST/{short-host-name}@REALM, and a normal kinit
>-k will not succeed because the KDC
>does not accept the use of the SPN for an initial authentication. I
>understand there is a way under Windows to
>map SPNs to user accounts (UPNs), but I'm not sure how to accomplish
>that. Maybe we can accomplish this when
>we create the LDAP entry in AD? That might be a better alternative
>than changing the UPN to HOST/{fqdn}@REALM
>if it may cause any problems.
I don't think there is a way around setting the UPN to contain the
FQDN.
-- Luke
--
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos