1
0
mirror of https://github.com/samba-team/samba.git synced 2025-01-12 09:18:10 +03:00

s3:winbindd: rely on the kerberos_state from pdb_get_trust_credentials()

The implementation of pdb_get_trust_credentials() should have all
the details to set the kerberos_state to a useful value.

This should enable the fallback to NTLMSSP again, when using our
machine account against trusted domains.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=12598

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Ralph Boehme <slow@samba.org>
This commit is contained in:
Stefan Metzmacher 2017-02-22 20:07:25 +01:00
parent ba9d139ec3
commit 51caeb7c53

View File

@ -936,17 +936,6 @@ static NTSTATUS get_trust_credentials(struct winbindd_domain *domain,
goto ipc_fallback;
}
if (domain->primary && lp_security() == SEC_ADS) {
cli_credentials_set_kerberos_state(creds,
CRED_AUTO_USE_KERBEROS);
} else if (domain->active_directory) {
cli_credentials_set_kerberos_state(creds,
CRED_MUST_USE_KERBEROS);
} else {
cli_credentials_set_kerberos_state(creds,
CRED_DONT_USE_KERBEROS);
}
if (creds_domain != domain) {
/*
* We can only use schannel against a direct trust