Hello,

Is it possible to create a Samba network share on an FreeIPA domain controller that would allow domain users to authenticate via their Kerberos tickets without running ipa-adtrust-install?

Since I don't plan to establish any trust relationship with Windows domains:

  1. Can winbind properly map user SIDs to UIDs without the AD trust components installed?

  2. Or is there an alternative way to configure smb.conf to make this work with pure FreeIPA/Kerberos authentication?

My understanding is that ipa-adtrust-install generates the necessary ID mapping structures for Samba, but I'm wondering if there's a lighter-weight solution when Windows trusts aren't required.

Thank you for any insights!

-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue
  • [Freeipa-users] Config... Данила Скачедубов via FreeIPA-users

Reply via email to