Sorry Andrew, that message was intended towards Gaiseric's comment. I will try to get you a trace against Windows 2008, but it may take me a while to get a test environment set up for that. I've also noticed that this happens as far back as Windows 2000 clients, so not isolated to Win7.
On Tue, Jul 30, 2013 at 9:31 PM, Andrew Bartlett <[email protected]> wrote: > On Tue, 2013-07-30 at 21:25 -0400, Ryan Bair wrote: > > Understood. The machine I'm trying to connect is just a member, not a > > DC. This is something which was well supported in earlier versions of > > Windows with AD (NT4 didn't die overnight), and reportedly still works > > in 2012. I'm not expecting any Kerberos to come out of NT4, nor do I > > see any. > > > > The issue is that the Samba DC is fulfilling a TGS request when it > > really should not. I spelled this out in a bit more detail a few > > messages back. > > What I need you to do is show how this is different with Windows 2008, > rather than Samba 4.0 as an AD DC. Then I might be able to assist, > otherwise, the only 'buggy' part of this would seem to be the new > security behavior of Windows 7, which you may be able to disable. > > Andrew Bartlett > > -- > Andrew Bartlett > http://samba.org/~abartlet/ > Authentication Developer, Samba Team http://samba.org > Samba Developer, Catalyst IT http://catalyst.net.nz > > > -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
