From 4f5791ebd03eaec1c7da0865a383175b05102712 Mon Sep 17 00:00:00 2001 From: Daniel Baumann Date: Sun, 5 May 2024 19:47:29 +0200 Subject: Adding upstream version 2:4.17.12+dfsg. Signed-off-by: Daniel Baumann --- docs-xml/smbdotconf/security/kerberosmethod.xml | 41 +++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 docs-xml/smbdotconf/security/kerberosmethod.xml (limited to 'docs-xml/smbdotconf/security/kerberosmethod.xml') diff --git a/docs-xml/smbdotconf/security/kerberosmethod.xml b/docs-xml/smbdotconf/security/kerberosmethod.xml new file mode 100644 index 0000000..b7cd988 --- /dev/null +++ b/docs-xml/smbdotconf/security/kerberosmethod.xml @@ -0,0 +1,41 @@ + + + + Controls how kerberos tickets are verified. + + + Valid options are: + + secrets only - use only the secrets.tdb for + ticket verification (default) + + system keytab - use only the system keytab + for ticket verification + + dedicated keytab - use a dedicated keytab + for ticket verification + + secrets and keytab - use the secrets.tdb + first, then the system keytab + + + + The major difference between "system keytab" and "dedicated + keytab" is that the latter method relies on kerberos to find the + correct keytab entry instead of filtering based on expected + principals. + + + + When the kerberos method is in "dedicated keytab" mode, + must be set to + specify the location of the keytab file. + + +dedicated keytab file +default + -- cgit v1.2.3