Re: [Samba] kerberos configuration in samba

2009-12-16 Thread Ralf Hornik Mailings
Rajesh Ghanekar wrote: - I guess I don't need to do kinit manually if I am using "net ads join" command, right? kinit is a good tool for tesing a kerberos workskation, or when doing local GSSAPI authentication. Not needed for samba. In your smb.conf you have to set the realm unless your

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Rob Townley
On Tue, Dec 15, 2009 at 4:48 AM, Rajesh Ghanekar wrote: > Hi All, >  I am using samba-3.2.11-0.1.145 in my setup. I have multiple domain > controllers > for a domain. I am confused on do I need to edit /etc/krb5.conf or not. I am > using > MIT kerberos (krb5-1.4.3-19.34) on SLES10. > > Here is wha

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Rajesh Ghanekar
Hi Ralf, Ralf Hornik Mailings wrote: Rajesh Ghanekar wrote: Hi Ralf, Thanks for the help. But I was asking if all 4 points mentioned in my mail are correct or not, like what if SRV records are not present, etc, then what should go in krb5.conf and smb.conf? Im not clear, what you are as

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Ralf Hornik Mailings
Rajesh Ghanekar wrote: Hi Ralf, Thanks for the help. But I was asking if all 4 points mentioned in my mail are correct or not, like what if SRV records are not present, etc, then what should go in krb5.conf and smb.conf? Im not clear, what you are asking for. All points 1 - 3 are true. Poin

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Rajesh Ghanekar
Hi Ralf, Thanks for the help. But I was asking if all 4 points mentioned in my mail are correct or not, like what if SRV records are not present, etc, then what should go in krb5.conf and smb.conf? Thanks, Rajesh Ralf Hornik Mailings wrote: Rajesh Ghanekar wrote: One idea to make an admi

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Ralf Hornik Mailings
Rajesh Ghanekar wrote: One idea to make an admin server HA in krb5.conf could be DNS round robin, as far as multiple admin server are really supported. Does other points (#1 - #3) mentioned in my mail holds true or there is still some confusion from my side? Regarding http://www.infor

[Samba] kerberos configuration in samba

2009-12-15 Thread Rajesh Ghanekar
Hi All, I am using samba-3.2.11-0.1.145 in my setup. I have multiple domain controllers for a domain. I am confused on do I need to edit /etc/krb5.conf or not. I am using MIT kerberos (krb5-1.4.3-19.34) on SLES10. Here is what I got from Samba HOWTO: 1. Adding entries in /etc/krb5.conf for

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Rajesh Ghanekar
Ralf Hornik Mailings wrote: Rajesh Ghanekar wrote: 4. I can have multiple "kdc = " entries in /etc/krb5.conf, if I need to manually configure /etc/krb5.conf, but only single "admin server =" and "password server =" line. How does this /etc/krb5.conf entry for admin server and password server

Re: [Samba] kerberos configuration in samba

2009-12-15 Thread Ralf Hornik Mailings
Rajesh Ghanekar wrote: 4. I can have multiple "kdc = " entries in /etc/krb5.conf, if I need to manually configure /etc/krb5.conf, but only single "admin server =" and "password server =" line. How does this /etc/krb5.conf entry for admin server and password server becomes HA if the machin

[Samba] kerberos configuration in samba

2009-12-15 Thread Rajesh Ghanekar
Hi All, I am using samba-3.2.11-0.1.145 in my setup. I have multiple domain controllers for a domain. I am confused on do I need to edit /etc/krb5.conf or not. I am using MIT kerberos (krb5-1.4.3-19.34) on SLES10. Here is what I got from Samba HOWTO: 1. Adding entries in /etc/krb5.conf for "