[23077] in Kerberos
Re: Samba 3 as domain member of w2k realm
daemon@ATHENA.MIT.EDU (Tobias Schenk)
Fri Dec 17 21:14:49 2004
From: Tobias Schenk <schenk_remove_this_@physik.tu-berlin.de>
Date: Sat, 18 Dec 2004 00:51:08 +0100
Message-ID: <cnr6s099egihoa5v39eh92khj3hs0noaji@4ax.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
On Thu, 18 Nov 2004 13:50:50 +0000 (UTC), riccardo.baldanzi@libero.it
("R.B.") wrote:
>Hi all,
>i've a problem joining a samba 3.0.7-1.3E.1 in a w2k domain:
>
>[root@proxynode2 squid]# net ads join -U myuser
>myuser's password:
>[2004/11/18 13:29:32, 0] utils/net_ads.c:ads_startup(183)
> ads_connect: Program lacks support for encryption type
> ticket_lifetime = 24000
> default_realm = MYDOMAIN.NET
> dns_lookup_realm = true
> dns_lookup_kdc = true
> default_etypes = des-cbc-crc des-cbc-md5
> default_etypes_des = des-cbc-crc des-cbc-md5
> forwardable = true
> proxiable = true
We struggle with a similar problem. I found an Microsoft knowledge
base article that MS always tries do encrypt answers with a certain
encryption. That is perhaps not supported on unix side. There is a
registry entry available like 'UseClientTicketSomeWhat' that could
help in your case. Sorry, that I cannot provide a link but I am out of
office.
HTH
Also a question to the experts. It seems to me getting tickets using
'kinit' is different from requesting a service regarding the ciphers?!
This would explain why I can connect to my samba server from linux and
not from windows. If a client can set the desired cipher then this
would explain why I can also connect to windows from linux.
Concluding: Can I set the cipher type of windows client requests? And
which do I have to use to make my samba work?
Thanks for comments,
Tobias
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos