SMB: Use gssproxy for unattended accounts and/or constrained delegation
Issue
- Configuring unattended application account access for Kerberized SMB shares does not work like for NFS shares using keytabs or some version of constrained delegation including RBCD
- There is no current facility to leverage constrained delegation where an unattended account can use the system's principal to acquire a ticket.
Environment
- Red Hat Enterprise Linux
- 8
- 9
- Kerberos
- SMB
- gssproxy
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.