LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 04-14-2022, 07:18 AM   #1
xj25vm
Member
 
Registered: Jun 2008
Posts: 393

Rep: Reputation: 68
Slackware + Samba + AD - and move from Heimdal to MIT kerberos


This is to help anyone who might hit the same issue. It looks like some time in the past year or so Slackware has changed from compiling Samba with internal Heimdal kerberos support to compiling against external MIT kerberos libraries (at least it looks like that, please correct me if I am wrong). If doing a Slackware upgrade on an existing Samba box already configured with Active Directory mode, this breaks Samba and at least for me, it took a whole morning to figure out how or why. To fix this you need to migrate the Samba AD config from Heimdal to MIT kerberos using the instructions below:

https://wiki.samba.org/index.php/Run...he_Heimdal_KDC

Notes:

1. Follow the instructions carefully and amend the kdc.conf file correctly - not like I did the first time around :-\

2. The kerberos daemon (/etc/rc.d/rc.krb5dc) does not need and should not be started separately for Samba to work.

Searching the net for "slackware samba heimdal mit kerberos" or similar combinations didn't return anything specific or of much use for me - hence I thought I would post this info here.

Good luck! :-)

Last edited by xj25vm; 04-14-2022 at 07:20 AM. Reason: spelling
 
Old 04-14-2022, 10:07 PM   #2
rkelsen
Senior Member
 
Registered: Sep 2004
Distribution: slackware
Posts: 4,491
Blog Entries: 7

Rep: Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581Reputation: 2581
This extract from the Slackware Changelog explains it:

Code:
Fri Jul 14 22:11:58 UTC 2017
...
n/samba-4.6.6-x86_64-1.txz:  Upgraded.
  This update fixes an authentication validation bypass security issue:
  "Orpheus' Lyre mutual authentication validation bypass"
  All versions of Samba from 4.0.0 onwards using embedded Heimdal
  Kerberos are vulnerable to a man-in-the-middle attack impersonating
  a trusted server, who may gain elevated access to the domain by
  returning malicious replication or authorization data.
  Samba binaries built against MIT Kerberos are not vulnerable.
  For more information, see:
    https://www.samba.org/samba/security/CVE-2017-11103.html
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11103
  (* Security fix *)
...
This change was made between the 14.2 and 15.0 releases.

Good thing too, by the looks of it.
 
3 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Heimdal or MIT Kerberos Turbocapitalist Linux - Security 1 04-22-2018 01:31 AM
Invalid MIT-MAGIC-COOKIE-1 keyInvalid MIT-MAGIC-COOKIE-1 when trying x11 forwarding Sean1988 Linux - Newbie 2 05-12-2014 05:35 AM
passwordless OpenSSH with MIT-Kerberos and PAM dbalsige Linux - Software 1 11-12-2009 12:12 PM
Heimdal vs MIT krb5 which ones better? behmjoe Linux - Software 1 05-17-2009 08:10 AM
Trying to find walkthrough guides for Kerberos Heimdal V and OpenBSD 3.9 Gsee *BSD 0 05-15-2006 07:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 11:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration