Re: SPNEGO questions

From: Andrew Bartlett <abartlet@dont-contact.us>
Date: Wed, 02 Nov 2005 09:06:25 +1100

On Tue, 2005-11-01 at 18:37 +0100, Serassio Guido wrote:
> Hi Andrews,
>
> At 03.18 28/10/2005, Andrew Bartlett wrote:
>
> >This was a regression. I've fixed this now.
>
> Some news:
>
> I can confirm to you that the SPN problem is fixed, the Samba 4
> machine was joined fine to the domain, and now I am able to see the
> list of the shares from a Windows 2000 machine, but I cannot connect
> to any share. There is something like Samba 3 'username map' in Samba 4 ?

A known problem. We are working on winbindd, and that will start to get
things going again.

> Another question, the SPNs created from net join are:
>
> C:\>setspn -L vm-sarge
> Registered ServicePrincipalNames for
> CN=VM-SARGE,CN=Computers,DC=acmeconsulting,DC=loc:
> host/vm-sarge/ACMECONSULTING
> host/vm-sarge.acmeconsulting.loc/ACMECONSULTING
> host/vm-sarge/acmeconsulting.loc
> host/vm-sarge.acmeconsulting.loc/acmeconsulting.loc
> host/vm-sarge
> host/vm-sarge.acmeconsulting.loc
>
> The first four are correct ?
>
> I have tried to use Squid with ntlm_auth and Negotiate (gss-spnego), but ....
>
> Unable to open tdb '/usr/local/samba/private/secrets.ldb'
> Failed to connect to '/usr/local/samba/private/secrets.ldb'
> Could not open secrets.ldb

This sounds stupid, but you will need to either run Squid as root, or
give world access to secrets.ldb.

This will change before release...

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net

Received on Tue Nov 01 2005 - 15:06:29 MST

This archive was generated by hypermail pre-2.1.9 : Thu Dec 01 2005 - 12:00:15 MST