SMB: Use gssproxy for unattended accounts and/or constrained delegation

Solution Verified - Updated -

Issue

  • Configuring unattended application account access for Kerberized SMB shares does not work like for NFS shares using keytabs or some version of constrained delegation including RBCD
  • There is no current facility to leverage constrained delegation where an unattended account can use the system's principal to acquire a ticket.

Environment

  • Red Hat Enterprise Linux
    • 8
    • 9
  • Kerberos
  • SMB
  • gssproxy

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content