Kerberos PKINIT KeyTrust logon support
Sergio Longhi Neto via samba <[email protected]> Fri, 20 Mar 2026 19:39:14 +0000 (UTC)
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
Good afternoon, everyone. I would first like to congratulate the Samba team, a robust tool that I have been using for decades. If you could help me, I need to implement MFA for access by users with elevated privileges and I would like to use Hello for Business for this. From what I understand, version 4.24 has KeyTrust support, but in the test environments I set up I was unsuccessful and I did not find any support material to configure this functionality. In short: is it possible to configure Hello for Business in version 4.24 using KeyTrust natively without needing Windows Server? I have already configured the PKI, adjusted the smb.conf, checked the krb5.conf, but the key is not generated in the computer's tpm nor in the user's attributes... Thank you very much in advance. Sergio -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba