Bug 1244 - ADS with trust to MIT Kerberos Realm wont work
Summary: ADS with trust to MIT Kerberos Realm wont work
Status: CLOSED FIXED
Alias: None
Product: Samba 3.0
Classification: Unclassified
Component: libsmbclient (show other bugs)
Version: 3.0.2a
Hardware: Other other
: P3 normal
Target Milestone: none
Assignee: Samba Bugzilla Account
QA Contact:
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-04-05 08:31 UTC by Wolfram Klaus
Modified: 2005-08-24 10:22 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfram Klaus 2004-04-05 08:31:59 UTC
We have an Active Directory with a cross realm trust to a MIT Kerberos realm.
All normal users are mapped to an equivalent principal in the Kerberos realm.
Thus we have a common single autentication system for Windows an Unix(TM)-like
sytems (Linux and Tru64). 
Problem is, that samba seems not to be able to autenticate users. 
I could easily add the machine to the AD via net ads join, but 
smbclient -L samba_machine -k 
always gives NT_STATUS_LOGON_FAILURE.
Comment 1 Gerald (Jerry) Carter (dead mail address) 2005-02-08 20:48:58 UTC
This should work if you have a ticket for a user in the 
MIT realm and try to connect to the Samba joined to the 
AD domain.  Can you retest against 3.0.11 and reopen if 
the bug still exists.   
Comment 2 Gerald (Jerry) Carter (dead mail address) 2005-08-24 10:22:05 UTC
sorry for the same, cleaning up the database to prevent unecessary reopens of bugs.