On Tue, 2013-07-30 at 21:25 -0400, Ryan Bair wrote: > Understood. The machine I'm trying to connect is just a member, not a > DC. This is something which was well supported in earlier versions of > Windows with AD (NT4 didn't die overnight), and reportedly still works > in 2012. I'm not expecting any Kerberos to come out of NT4, nor do I > see any. > > The issue is that the Samba DC is fulfilling a TGS request when it > really should not. I spelled this out in a bit more detail a few > messages back.
What I need you to do is show how this is different with Windows 2008, rather than Samba 4.0 as an AD DC. Then I might be able to assist, otherwise, the only 'buggy' part of this would seem to be the new security behavior of Windows 7, which you may be able to disable. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Catalyst IT http://catalyst.net.nz -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
