[583] in athena10

home help back first fref pref prev next nref lref last post

punt Samba configuration package?

daemon@ATHENA.MIT.EDU (Robert A Basch)
Mon Oct 27 18:27:40 2008

Message-Id: <200810272226.m9RMQmW7007160@abulia.mit.edu>
To: athena10@MIT.EDU
Date: Mon, 27 Oct 2008 18:26:48 -0400
From: Robert A Basch <rbasch@MIT.EDU>

Recently I checked in a samba-config package, which would install an
smb.conf file pointing at the WIN.MIT.EDU domain.  After further
investigation, I now think we should punt this package, and not bother
trying to configure Samba for Athena 10.

The technical plan mentions configuration of a Kerberos-enabled
smbclient only.  Yet smbclient needs no configuration file settings
in order to support Kerberos authentication to a WIN.MIT.EDU server,
as the client uses the principal/realm supplied by the server.

Specifying the realm and security settings in smb.conf is only useful
for Samba servers, as far as I can tell (if the machine is joined
to the WIN.MIT.EDU domain).  At first I thought that it was useful
to apply this configuration anyway, even though the plan is to install
only the Samba client.  But I did not realize that the samba-common
package's postinst script can break the divert/symlink mechanism used
by our configuration package system, so that configuring smb.conf in
our own package would mean more effort than it is probably worth.

So, unless there is something I am missing here, I think we should
just punt the Samba configuration package.  It might be useful,
instead, to have a document for server admins, describing how to join
a machine to the domain, and configure Samba accordingly.

home help back first fref pref prev next nref lref last post