If anyone knows what it is, just let me know and I will edit this to get it in there. You should now have a machine that will authenticate to the AD and show you the shares that you are allowed to access.

Service tickets are obtained whenever a user or computer accesses a server on the network.

For example, when a user maps a drive to a file server, the resulting service ticket request generates event ID 4769 on the DC.

Result codes: This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.

The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

[logging] default = FILE:/var/log/krb5kdc = FILE:/var/log/krb5admin_server = FILE:/var/log/[libdefaults] default_realm = EDMONSON. NET dns_lookup_realm = false dns_lookup_kdc = false ticket_lifetime = 24h forwardable = yes default_tgs_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC default_tkt_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC preferred_enctypes = DES-CBC-CRC DES-CBC-MD5 RC4-HMAC default_domain = edmonson.} [domain_realm] .= EDMONSON. Find the filesystem entry that you want to enable ACL for and edit the options field (the fourth field, usually says Now you need to unmount that filesystem and remount it.

This will give you access to extended security settings similar to Windows file permissions. You might not want to enable ACLs for all of your filesystems as it can induce some overhead that you might not need. NET [kdc] profile = /var/kerberos/krb5kdc/[appdefaults] pam = { debug = false ticket_lifetime = 36000 renew_lifetime = 36000 forwardable = true krb4_convert = false } Now it is a good idea to add your domain controller to your change: workgroup = EDMONSON add: realm = EDMONSON. NET change: server string = Linux Samba File Server change: security = ADS change: encrypt passwords = yes change: preferred master = no add: template shell = /bin/false add: template homedir = /home/%D/%U add: idmap uid = 10000-20000 add: idmap gid = 10000-20000 add: enhanced browsing = no add: winbind use default domain = yes Now you need to enable extended Access Control Lists (ACLs) on the filesystem that you will be using.The easiest way to do that is to just reboot the machine, since sometimes there might be users with files open and you can’t unmount while that is going on.Now if you are planning on give your users home folders you need to make their directories.I cheated a little and did the following to quickly create mine: That should give you a directory for every user with them having full control of that directory.I think there is an option to SAMBA to get it to do this when a user connects to the machine, but I couldn’t find it quickly today to set it.

