-
Bug
-
Resolution: Unresolved
-
Undefined
-
rhel-10.0.beta
-
samba-4.20.2-103.el10
-
Yes
-
Low
-
Regression
-
sst_idm_sssd
-
ssg_idm
-
0
-
False
-
-
None
-
Red Hat Enterprise Linux
-
None
-
Pass
-
RegressionOnly
-
None
idmap_ad creates an incorrect local krb5.conf in case of trusted domain lookups.
In case we have idmap_ad and trusted domain and connect to a trusted domain we create a krb5.conf for our realm but with the IP of the trusted domain KDC. Thus we try to get a krbtgt from the trusted domain for our machine account and fail. The trusted domain KDC doesn't know about our machine account.
We need to look up the KDC IP in this case instead of providing one.
- links to
-
RHBA-2024:136143 samba update