Sponsored Content
Top Forums UNIX for Advanced & Expert Users Authenticating with SSSD / Kerberos against Windows Server 2012 R2 Post 302953790 by Devyn on Tuesday 1st of September 2015 12:25:26 PM
Old 09-01-2015
Authenticating with SSSD / Kerberos against Windows Server 2012 R2

I'm authenticating with SSSD / Kerberos against Windows Server 2012 R2. I've setup credentails delegation using these options:

Code:
Host *
  GSSAPIAuthentication yes
  GSSAPIDelegateCredentials yes
  GSSAPITrustDns yes

For both client/server but no luck. I've read online that I need to run ADSIEdit.msi to edit the user flags in Windows Server 2012 R2 to enable a delegation tab, which I've done, but no luck setting the delegation parameters. Thinking my issue is on the Windows Server 2012 with the setting I put for SPN (servicePrincipalName) but not 100%. 3

My question is does Linux SSSD / Kerberos care about the Windows Server 2012 R2 delegation settings and what should I set the servicePrincipalName too in Windows so my SSSD / Kerberos implementation will work?

What should I look for in the log files to determine if the credentials deletation is working or not working? I searched for *deleg* but nothing comes up.

What do I need to look for in the log files to determine where the delegation is breaking and hence not working?

Thanks,
Dev

Last edited by Don Cragun; 09-01-2015 at 05:17 PM.. Reason: Add CODE and ICODE tags. Delete extraneous BOLD tags.
 

10 More Discussions You Might Find Interesting

1. AIX

Users not authenticating via Kerberos on MS AD

I have AD (active directory) user, "asdf", created and a matching local AIX user name. Using "kinit", I can successfully authenticate it against the MS AD but when they I try to login via SSH with the same user name, it doesn't work. How can I get AIX to allow kerberos authentication as a valid... (1 Reply)
Discussion started by: kah00na
1 Replies

2. Shell Programming and Scripting

Unix shell script to Copy files from one Windows server to another Windows server.

Can anybody please help me on how to code for the below requirement: I need to write a shell script (on different unix server) to copy files from multiple folders (ex. BRN-000001) from one windows server (\\boldls-mwe-dev4)to a different windows server(\\rrwin-ewhd04.ecomad.int). This shell... (4 Replies)
Discussion started by: SravsJaya
4 Replies

3. Shell Programming and Scripting

gawk convert 2012-Jun-13 to 2012-06-13

I have a value in a file i am processing that has a date like "2012-Jun-13" how can I convert a date like that 2012-06-13? Am I stuck building an array of three digit months and corresponding numbers and running through the logic of figuring out the number?? or can I convert this with... (1 Reply)
Discussion started by: trey85stang
1 Replies

4. Shell Programming and Scripting

Date conversion help from dd/mm/yyyy to dd/Mon/yyyy i.e. 28/10/2012 to 28/Oct/2012

Hi I have a problem with Date format in my code. 1st I am trying to convert today's date to yesterday's using YESTERDAY3=`perl -e '@y=localtime(time()-86400); printf "%04d/%02d/%02d",$y+1900,$y+1,$y;$y;'` And once it is done I am trying to using the yesterday date in a grep command to... (3 Replies)
Discussion started by: nithinankam
3 Replies

5. What is on Your Mind?

Place your bits - 2012 FIFA Ballon d'Or and 2012 FIFA World Coach of the Year

I have added two new sports events. The FIFA Ballon d'Or is an association football award given annually to the player who is considered to have performed the best in the previous season. It is awarded based on votes by coaches and captains of international teams, as well as journalists from... (0 Replies)
Discussion started by: ni2
0 Replies

6. Red Hat

Not authenticating in apache server site for a folder

hi , Im configuring web site with authencation to a folder but the authentication is not happening. below is the conf file of /etc/httpd/conf/httpd.conf <VirtualHost 192.168.1.4:80> DocumentRoot /var/www/html/ ServerName redhatclient.example.com <directory... (0 Replies)
Discussion started by: redhatlbug
0 Replies

7. AIX

How can we share a AIX drive on to Windows 2012 server?

Hi, How can we share a AIX drive on to Windows 2012 server. or vise versa. Note: Not using NFS/CIFS/samba. (*we are not able to use samba/NFS/CIFS for some reason) Requirement: How to have real time file sharing over the network between Windows and UNIX Do you guys have any ... (4 Replies)
Discussion started by: System Admin 77
4 Replies

8. AIX

Samba 3.6.22 on AIX 7.1 with Windows AD (Kerberos and winbind)

Hi all, I have installed samba 3.6.22 on AIX 7.1 and join a windows AD with success. All seem to work fine, I have configured smb.conf, methods.cfg, kerberos, user .... the following command work fine wbinfo -u, wbinfo -g, wbinfo -i, wbinfo -s, wbinfo -S, lsuser, id... The unique... (20 Replies)
Discussion started by: PhilippeA
20 Replies

9. Shell Programming and Scripting

List line count of multiple files in windows server 2012

how to find out line count ( wc -l ) for multiple fines in windows cmd the command which i a using to find line count for single file is type sec0001.txt | find /c /v "" but how to use it for multiple files to get output filewise as if this command is run like type sec*.txt |... (2 Replies)
Discussion started by: sagar_1986
2 Replies

10. Solaris

Authenticating UNIX (Solaris 11) to Windows 2012R2 / Active Directory

Gentleman, i am trying to setup Authentication for my Solaris 11 Server through Active Directory (Server 2012 R2). At least some things are already working, for example a getent passwd mydomainuser and ldapsearch command comes back with a correct result. So not everything i did was wrong. ... (1 Reply)
Discussion started by: bahnhasser83
1 Replies
NFSTEST_DELEGATION(1)					     nfstest_delegation 1.0.1					     NFSTEST_DELEGATION(1)

NAME
nfstest_delegation - Delegation tests SYNOPSIS
nfstest_delegation --server <server> [--client <client>] [options] DESCRIPTION
Basic delegation tests verify that a correct delegation is granted when opening a file for reading or writing. Also, another OPEN should not be sent for the same file when the client is holding a delegation. Verify that the stateid of all I/O operations should be the delega- tion stateid. Reads from a different process on the same file should not cause the client to send additional READ packets when the client is holding a read delegation. Furthermore, a LOCK packet should not be sent to the server when the client is holding a delegation. Recall delegation tests verify the delegation is recalled when a conflicting operation is sent to the server from a different client. Con- flicting operations are reading, writing and changing the permissions on the same file. Note, that reading a file from a different client can only recall a read delegation. Also, verify that a delegation is not recalled when a different client is granted a read delegation. After a delegation is recalled, the client should send an OPEN with CLAIM_DELEGATE_CUR before returning the delegation and the stateid should be the same as the original OPEN stateid. Also, a delegation should not be granted when re-opening the file right before returning the delegation. Verify client flushes all written data before returning the WRITE delegation. The LOCK should be sent as well right before returning a delegation which has been recalled. A delegation should not be granted on the second client who cause the delegation recall on the first client. OPTIONS
--version show program's version number and exit -h, --help show this help message and exit -f FILE, --file=FILE Options file -s SERVER, --server=SERVER Server name or IP address -p PORT, --port=PORT NFS server port [default: 2049] --nfsversion=NFSVERSION NFS version [default: 4] --minorversion=MINORVERSION Minor version [default: 1] -e EXPORT, --export=EXPORT Exported file system to mount [default: '/'] -m MTPOINT, --mtpoint=MTPOINT Mount point [default: '/mnt/t'] --datadir=DATADIR Data directory where files are created [default: ''] -o MTOPTS, --mtopts=MTOPTS Mount options [default: 'hard,rsize=4096,wsize=4096'] -i INTERFACE, --interface=INTERFACE Device interface [default: 'eth0'] -v VERBOSE, --verbose=VERBOSE Verbose level [default: 'none'] --nocleanup Do not cleanup --rmtraces Remove trace files [default: remove trace files if no errors] --keeptraces Do not remove any trace files [default: remove trace files if no errors] --createlog Create log file --bugmsgs=BUGMSGS File containing test messages to mark as bugs if they failed --ignore Ignore all bugs given by bugmsgs --nomount Do not mount server --basename=BASENAME Base name for all files and logs [default: automatically generated] --tverbose=TVERBOSE Verbose level for test messages [default: '1'] --filesize=FILESIZE File size to use for test files [default: 65536] --nfiles=NFILES Number of files to create [default: 2] --rsize=RSIZE Read size to use when reading files [default: 4096] --wsize=WSIZE Write size to use when writing files [default: 4096] --iodelay=IODELAY Seconds to delay I/O operations [default: 0.1] --offset-delta=OFFSET_DELTA Read/Write offset delta [default: 4096] --warnings Display warnings --nfsdebug=NFSDEBUG Set NFS kernel debug flags and save log messages [default: ''] --rpcdebug=RPCDEBUG Set RPC kernel debug flags and save log messages [default: ''] --sudo=SUDO Full path of binary for sudo [default: '/usr/bin/sudo'] --tcpdump=TCPDUMP Full path of binary for tcpdump [default: '/usr/sbin/tcpdump'] --iptables=IPTABLES Full path of binary for iptables [default: '/sbin/iptables'] --messages=MESSAGES Full path of log messages file [default: '/var/log/messages'] --tmpdir=TMPDIR Temporary directory [default: '/tmp'] --runtest=RUNTEST Comma separated list of tests to run [default: 'all'] --client=CLIENT Remote NFS client that mounts server used for multiple client tests --lock-offset=LOCK_OFFSET Starting offset for lock [default: 0] --lock-len=LOCK_LEN Number of bytes to lock [default: 0] TESTS
read Basic read delegation test write Basic write delegation test read_lock Basic read delegation test with file lock write_lock Basic write delegation test with file lock read_recall_write Recall read delegation by writing from a second client write_recall_write Recall write delegation by writing from a second client read_recall_write_lock Recall read delegation by writing from a second client with file lock write_recall_write_lock Recall write delegation by writing from a second client with file lock write_recall_read Recall write delegation by reading from a second client write_recall_read_lock Recall write delegation by reading from a second client with file lock read_recall_setattr Recall read delegation by changing the permissions to the file write_recall_setattr Recall write delegation by changing the permissions to the file read_recall_setattr_lock Recall read delegation by changing the permissions to the file with file lock write_recall_setattr_lock Recall write delegation by changing the permissions to the file with file lock EXAMPLES
The only required option is --server but only the basic delegation tests will be run. Use the --client option to run the recall tests as well $ nfstest_delegation --server 192.168.0.11 --client 192.168.0.20 NOTES
The user id in the local host and the host specified by --client must have access to run commands as root using the 'sudo' command without the need for a password. The user id must be able to 'ssh' to remote host without the need for a password. SEE ALSO
nfstest.test_util(1), nfstest_cache(1), nfstest_dio(1), nfstest_pnfs(1), nfstest_posix(1) BUGS
No known bugs. AUTHOR
Jorge Mora (mora@netapp.com) NFStest 1.0.2 10 April 2013 NFSTEST_DELEGATION(1)
All times are GMT -4. The time now is 08:37 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy