<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIFS client &amp;amp; Kerberos in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060012#M540211</link>
    <description>Thanks Eric for your help.&lt;BR /&gt;&lt;BR /&gt;I do not have a windows KDC. Are you sure is absolutely necessary? I've been reading quite a lot of kerberos documentation (my head is spinning around) and is never mentioned Windows...&lt;BR /&gt;&lt;BR /&gt;But if that is the case I will go back to NFS, last thing I want is to get into Windows.</description>
    <pubDate>Tue, 28 Aug 2007 04:01:23 GMT</pubDate>
    <dc:creator>Oscar Garcia</dc:creator>
    <dc:date>2007-08-28T04:01:23Z</dc:date>
    <item>
      <title>CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060010#M540209</link>
      <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;I might be over complicating things with this configuration but I have reached an stuck point.&lt;BR /&gt;I am trying to share a directory in HPUX 11i v1 (A) with CIFS. My goal is to be able to mount it to another HPUX 11i v1 (B).&lt;BR /&gt;To achive this, I have installed Kerberos Server T1417AA in other server 11i v1 (C).&lt;BR /&gt;To begin with, the autoconfiguration of kerberos server behaved different from what was in the documentation. To simplify things I cannot find a /etc/krb5.conf file...&lt;BR /&gt;Any help, advice or suggestion would be gratefully appreciated.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 24 Aug 2007 10:29:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060010#M540209</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-24T10:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060011#M540210</link>
      <description>Hi Oscar,&lt;BR /&gt;&lt;BR /&gt;You need a Windows KDC to use Kerberos with both the CIFS Server and Client.  You need to install the HP-UX 11v1 Kerberos Client for either the CIFS Server/Client to work with krb5 authentication.  Don't use the Kerberos Client that originally came with 11iv1 - go here and get the latest client:&lt;BR /&gt;&lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=KRB5CLIENT" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=KRB5CLIENT&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;All of this may be moot if you do not have a Windows 2000/2003 KDC to use.</description>
      <pubDate>Fri, 24 Aug 2007 15:11:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060011#M540210</guid>
      <dc:creator>eric roseme</dc:creator>
      <dc:date>2007-08-24T15:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060012#M540211</link>
      <description>Thanks Eric for your help.&lt;BR /&gt;&lt;BR /&gt;I do not have a windows KDC. Are you sure is absolutely necessary? I've been reading quite a lot of kerberos documentation (my head is spinning around) and is never mentioned Windows...&lt;BR /&gt;&lt;BR /&gt;But if that is the case I will go back to NFS, last thing I want is to get into Windows.</description>
      <pubDate>Tue, 28 Aug 2007 04:01:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060012#M540211</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-28T04:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060013#M540212</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;I actually have a case open on this with the HP response center in Israel.&lt;BR /&gt;&lt;BR /&gt;So far, I have been advised to make sure the latest version of CIFS client and server are installed on the HP-UX system.&lt;BR /&gt;&lt;BR /&gt;I will provide further update as I run a checklist and diagnose.&lt;BR /&gt;&lt;BR /&gt;cifs client requires a reboot to install, so plan that one out.&lt;BR /&gt;&lt;BR /&gt;Hopefully I can get back to you with good news soon.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 28 Aug 2007 04:08:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060013#M540212</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-08-28T04:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060014#M540213</link>
      <description>&lt;!--!*#--&gt;Hi Steven,&lt;BR /&gt;&lt;BR /&gt;I have installed the most recent versions in the servers. But I have to tell I am lost following the documentation. I am wandering if is a case of updating the document...&lt;BR /&gt;&lt;BR /&gt;This is the dialog that I've got for the server configuration:&lt;BR /&gt;&lt;BR /&gt; 1) Configure as a Primary Security Server&lt;BR /&gt; 2) Configure as a Secondary Security Server&lt;BR /&gt;&lt;BR /&gt;-I chose option 1.&lt;BR /&gt;&lt;BR /&gt;Do you want to stash the principal database key on your local disk (y/n)&lt;BR /&gt;&lt;BR /&gt;- I replied y&lt;BR /&gt;&lt;BR /&gt;Please enter the fully qualified name of the Secondary Security Server1&lt;BR /&gt;press 'q' if you want to skip this and proceed further:&lt;BR /&gt;&lt;BR /&gt;-replied q&lt;BR /&gt;&lt;BR /&gt;Enter the realm name&lt;BR /&gt;&lt;BR /&gt;- I gave a name different from the default&lt;BR /&gt;&lt;BR /&gt;Then it shown all these lines:&lt;BR /&gt;&lt;BR /&gt;/opt/krb5/krb.conf moved to /opt/krb5/krb.conf.keep&lt;BR /&gt;&lt;BR /&gt;/opt/krb5/krb.realms moved to /opt/krb5/krb.realms.keep&lt;BR /&gt;&lt;BR /&gt;/opt/krb5/kpropd.ini moved to /opt/krb5/kpropd.ini.keep&lt;BR /&gt;&lt;BR /&gt;Creating krb.conf and krb.realms files&lt;BR /&gt;Copying admin_acl_file and password.policy file onto KRB5_ROOT dir&lt;BR /&gt;&lt;BR /&gt;You will be prompted for the database Master Password.&lt;BR /&gt;It is important that you DO NOT FORGET this password.&lt;BR /&gt;&lt;BR /&gt;Enter Password:&lt;BR /&gt;Kerberos server has been configured successfully.&lt;BR /&gt;&lt;BR /&gt;Then the next thing in the document (&lt;A href="http://docs.hp.com/en/T1417-90001/ch03s03.html)" target="_blank"&gt;http://docs.hp.com/en/T1417-90001/ch03s03.html)&lt;/A&gt; is a description of the files that suppose to be generated automatically and that I cannot find: krb5.conf and kdc.conf.&lt;BR /&gt;&lt;BR /&gt;So I hope the guys from HP come up with a nice explanation.&lt;BR /&gt;&lt;BR /&gt;Thanks and regards,</description>
      <pubDate>Tue, 28 Aug 2007 05:03:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060014#M540213</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-28T05:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060015#M540214</link>
      <description>I'm not sure that you need Kerberos if you're just connecting HP to HP. I would only expect to need Kerberos for Active Directory domain authentication. I haven't done much with the HP CIFS Client, but I've used Samba (which is what HP brands as their CIFS Server) for years with local smbpasswd authentication and no Kerberos involved.&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Aug 2007 10:44:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060015#M540214</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2007-08-28T10:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060016#M540215</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Still fighting with this. We are trying to avoid a Kerberos server on HP-UX for fear it will interfere with SSO, single sign on using the windows PDC.&lt;BR /&gt;&lt;BR /&gt;I will read your doc, run your configuration script and see what it gets me. I'm thinking I may need to install the server product to make this work.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 28 Aug 2007 10:51:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060016#M540215</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-08-28T10:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060017#M540216</link>
      <description>Well, I was looking for the list of prerequisites to show to Hieronimus, when I found this perl (&lt;A href="http://www.docs.hp.com/en/B8724-90044/B8724-90044.pdf):" target="_blank"&gt;http://www.docs.hp.com/en/B8724-90044/B8724-90044.pdf):&lt;/A&gt; &lt;BR /&gt;Kerberos Key Distribution Center and CIFS Servers&lt;BR /&gt;For this release, only Windows 2000 is supported for Kerberos authentication.&lt;BR /&gt;Specifically, Key Distribution Centers (KDCs) and CIFS file servers&lt;BR /&gt;that participate in Kerberos authentication with the HP CIFS Client&lt;BR /&gt;must be Windows 2000 systems. Any other supported server platform&lt;BR /&gt;can be used for traditional NTLM authentication.&lt;BR /&gt;&lt;BR /&gt;After all it seems that Eric was right...&lt;BR /&gt;&lt;BR /&gt;I think I did some work with Samba in Suse 8, but I was not happy with the results and as my favourites servers are HP, I was just dreaming with CIFS replacing the awful NFS.</description>
      <pubDate>Tue, 28 Aug 2007 11:22:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060017#M540216</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-28T11:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060018#M540217</link>
      <description>I may have missed something in your question, but is there a reason you can't use NTLM? It looks like the CIFS Client isn't quite so picky about NTLM servers.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I'm not sure that HP CIFS Client is up to the task of replacing NFS. My (brief) dealings with it did not give me confidence. It worked, but it seemed a little quirky and very poorly documented.&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Aug 2007 12:44:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060018#M540217</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2007-08-28T12:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060019#M540218</link>
      <description>Thanks Hieronimus, &lt;BR /&gt;&lt;BR /&gt;I am going to give it another shot without touching kerberos. I think I got so confused reading here and there, that I lost the plot completely.&lt;BR /&gt;&lt;BR /&gt;It may be a bit academic, but the question is still valid for that kerberos configuration script...</description>
      <pubDate>Wed, 29 Aug 2007 09:30:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060019#M540218</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-29T09:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060020#M540219</link>
      <description>When a vendor is really just providing a tested/supported version of an open source app I usually use the original documentation and just check the vendor docs to see where they made changes. You may be better off reading the documentation on &lt;A href="http://samba.org/" target="_blank"&gt;http://samba.org/&lt;/A&gt; instead of HP's CIFS Server manuals.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I don't know about the Kerberos configuration script, but most of the HP-supplied setup scripts I've looked at were outdated, had undocumented limitations, or had no documentation at all. It wouldn't surprise me if the documentation was wrong or the script was broken.</description>
      <pubDate>Wed, 29 Aug 2007 10:55:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060020#M540219</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2007-08-29T10:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060021#M540220</link>
      <description>Hi Oscar,&lt;BR /&gt;&lt;BR /&gt;yes - I am absolutely sure that to authenticate either HP CIFS Server or HP CIFS Client with Kerberos, you must use a Windows KDC.  &lt;BR /&gt;&lt;BR /&gt;The HP-UX Kerberos server can auth-n HP-UX applications, Inet-Services, or PAM-Kerberos, but not either CIFS product.  &lt;BR /&gt;&lt;BR /&gt;Sorry for the misunderstanding.  I can post the links in the docs that explain this, if you like.  You can look at the Samba list for postings where users try to hack in an MIT or Heimdal KDC, but that's not a "supported" Samba config.&lt;BR /&gt;&lt;BR /&gt;Eric Roseme&lt;BR /&gt;Hewlett-Packard</description>
      <pubDate>Wed, 29 Aug 2007 18:07:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060021#M540220</guid>
      <dc:creator>eric roseme</dc:creator>
      <dc:date>2007-08-29T18:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060022#M540221</link>
      <description>Thanks Eric for the reply.&lt;BR /&gt;&lt;BR /&gt;This then settles it down. I was wrong trying to use kerberos for what I intended to do.&lt;BR /&gt;I will wait for Steve to write his findings before closing the thread.</description>
      <pubDate>Thu, 30 Aug 2007 04:19:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060022#M540221</guid>
      <dc:creator>Oscar Garcia</dc:creator>
      <dc:date>2007-08-30T04:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060023#M540222</link>
      <description>Okay.  Given that we have ruled out krb5, if you want to config your CIFS server to just share out a directory for your CIFS client, you can just use a basic CIFS Server setup.  You can make it a stand-alone CIFS server, or  a PDC of it's own domain.  "security = user" will work fine, no need for an LDAP backend - you can just use the /var/opt/samba/private/smbpasswd file. After you do the basic config from the samba_setup script, just run /opt/samba/bin/samba_setup.  When you're done, run /opt/samba/bin/syncsmbpasswd and all of your /etc/passwd users will be copied to your smbpasswd file.  You can just edit out the ones that should not have CIFS access and you're ready to go.</description>
      <pubDate>Thu, 30 Aug 2007 11:49:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060023#M540222</guid>
      <dc:creator>eric roseme</dc:creator>
      <dc:date>2007-08-30T11:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS client &amp; Kerberos</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060024#M540223</link>
      <description>I was just looking into the Kerberos Server documentation. I guess you are using the wrong version of the document, here's the correct version:&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/T1417-90003/ch05s03.html" target="_blank"&gt;http://docs.hp.com/en/T1417-90003/ch05s03.html&lt;/A&gt;</description>
      <pubDate>Fri, 16 Nov 2007 05:48:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cifs-client-amp-kerberos/m-p/4060024#M540223</guid>
      <dc:creator>Kiran Kr</dc:creator>
      <dc:date>2007-11-16T05:48:20Z</dc:date>
    </item>
  </channel>
</rss>

