Bug 737810

Summary: net ads join requires undocumented option to use kerberos
Product: Red Hat Enterprise Linux 6 Reporter: Marko Myllynen <myllynen>
Component: sambaAssignee: Guenther Deschner <gdeschner>
Status: CLOSED ERRATA QA Contact: Martin Cermak <mcermak>
Severity: medium Docs Contact:
Priority: medium    
Version: 6.1CC: azelinka, dpal, gdeschner, mcermak, prc, sbose
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: samba-3.5.10-102.el6 Doc Type: Bug Fix
Doc Text:
Cause: The net manpage did not contain documentation for using kerberos authentication. Consequence: Users were not aware how to use kerberos authentication from the net binary. Fix: Manpage update. Result:
Story Points: ---
Clone Of:
: 771375 (view as bug list) Environment:
Last Closed: 2011-12-06 16:26:20 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 743047, 771375    

Description Marko Myllynen 2011-09-13 07:28:07 UTC
Description of problem:
net ads join doesn't use the existing krb5 ticket unless the undocumented -k option is provided. Lack of this documentation is causing great confusion for users (just see how many guide instruct to do "kinit username ; net ads join -U username%password").

# export KRB5CCNAME=/tmp/ticket
# kinit
Password for admin.COM: 
# net ads join
Enter root's password: 
Interrupted by signal.
# net ads join -U admin
Enter admin's password: 
Interrupted by signal.
# net ads join -k
Using short domain name -- DOMAIN
Joined 'SMBTEST1' to realm 'DOMAIN.EXAMPLE.COM
# 

Version-Release number of selected component (if applicable):
samba-common-3.5.6-86.el6_1.4.x86_64

Comment 1 Marko Myllynen 2011-09-13 07:28:46 UTC
See also https://bugzilla.redhat.com/show_bug.cgi?id=737808.

Comment 6 Guenther Deschner 2011-11-25 14:03:55 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Cause: The net manpage did not contain documentation for using kerberos authentication.

Consequence: Users were not aware how to use kerberos authentication from the net binary.

Fix: Manpage update.

Result:

Comment 7 errata-xmlrpc 2011-12-06 16:26:20 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1519.html