Talk by Alexander Bokovoy & Andreas Schneider (Red Hat / Samba Team)
Abstract:
In November 2023 Microsoft announced a path forward to remove NTLM from Windows. Their choice is easy: use Kerberos everywhere. How can Samba be made compatible with this approach?
At the same time, a lot of Samba users ask for making it possible to authenticate and interoperate with Entra ID and other OAuth2-based services. It might not be a surprise that Entra ID also has support for Kerberos. Can we build a solution that solves both problems?
In this talk Bokovoy and Schneider cover an experiment to reuse Kerberos infrastructure they built over years in FreeIPA to make Samba NTLM-less while improving overall security of the SMB authentication process.
Slides: https://sambaxp.org/fileadmin/user_up...
Visit the conference website at: https://sambaxp.org