Re: [Samba] Winbind with krb5auth for trust users


hier are the file. I replaced the real domain/realm name by "search&replace", so there should not be a typping error in my file concernig the realm or domain names.


client:~ # more /etc/hostname
client:~ # more /etc/hosts
passwd: compat winbind
group:  compat winbind

hosts:          files mdns_minimal [NOTFOUND=return] dns
networks:       files dns

services:       files
protocols:      files
rpc:            files
ethers:         files
netmasks:       files
netgroup:       files nis
publickey:      files

bootparams:     files
automount:      files nis
aliases:        files

client:~ # more /etc/krb5.conf
        default_realm = LOC.EXAMPLE.COM
        dns_lookup_realm = false
        dns_lookup_kdc = true
client:~ # more /etc/samba/smb.conf
       security = ADS
       workgroup = LOC
       realm = LOC.EXAMPLE.COM

       log file = /var/log/samba/%m.log
       log level = 1

       template homedir = /home/%D/%U
       template shell = /bin/bash

       # Default ID mapping configuration for local BUILTIN accounts
       # and groups on a domain member. The default (*) domain:
       # - must not overlap with any domain ID mapping configuration!
       # - must use a read-write-enabled back end, such as tdb.
       # - Adding just this is not enough
       # - You must set a DOMAIN backend configuration, see below
       idmap config * : backend = tdb
       idmap config * : range = 1000000-2000000

thanks for the fast answer.

All DCs (local and trusted domain) running on Windows Server
2012. The client is running on OpenSUSE Leap 42.3. The samba
version is 4.6.5.

Right now I'm a step before nfs. At first I just want to
authorize users with krb5auth.

The error is:

mlrlinux:~ # wbinfo -K GLOBALDOM\\globdomuser Enter
GLOBALDOM\globdomuser's password:
plaintext kerberos password authentication for
[GLOBALDOM\globdomuser] failed (requesting cctype: FILE)
wbcLogonUser(GLOBALDOM\globdomuser): error code was
NT_STATUS_NO_LOGON_SERVERS (0xc000005e) error message was: No
logon servers Could not authenticate user
[GLOBALDOM\globdomuser] with Kerberos
(ccache: FILE)

DNS resolution is working. I'm able to get the credentials
for a GLOBDOM-User with kinit, which should not work if DNS
resultion has errors, right?
Depends on the member server setting.
For example, do you have : kerberos method = secrets and keytab in smb.conf?

Can you post the following files, sorry, we need to verify files. ( anonimize here needed )

Your krb5.conf

And smb.conf



