ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is It Possible to Mount SMB Share Using Kerberos Token of Current User on MacOS

    IT Discussion
    apple unix smb macos kerberos active directory
    6
    48
    6.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • coliverC
      coliver @DustinB3403
      last edited by

      @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

      @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

      If you do that mapping on the Mac, and then log in as another user, hopefully they can't see the files from the first user. If they can, that's even worse.

      This I'm not following, the goal is to create a central point that I can simply drag to an individual users desktop on any given mac, and have them connect to my Windows file server.

      Since this is a shared resource (organizationally) they would presumably be able to see the files saved on this SMB server.

      That should work. Once they login to the Mac and it's domain joined it should use the Kerberos token to authenticate.

      DustinB3403D 1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403 @dbeato
        last edited by DustinB3403

        @dbeato this won't work as it would require us (IT dept) knowing people's passwords.

        1 Reply Last reply Reply Quote 1
        • DustinB3403D
          DustinB3403 @coliver
          last edited by

          @coliver said in Is it possible to mount smb share using login credentials of current user.:

          @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

          @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

          If you do that mapping on the Mac, and then log in as another user, hopefully they can't see the files from the first user. If they can, that's even worse.

          This I'm not following, the goal is to create a central point that I can simply drag to an individual users desktop on any given mac, and have them connect to my Windows file server.

          Since this is a shared resource (organizationally) they would presumably be able to see the files saved on this SMB server.

          That should work. Once they login to the Mac and it's domain joined it should use the Kerberos token to authenticate.

          How would I pass the kerberos credentials into the mapping? Nothing I'm seeing appears to address it.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403
            last edited by

            The goal here, is to use the domain user credentials, regardless who it is, and what system they logon.

            I want to be able to simply add this as a part of our image and just hand it out. Once the user logs into the system for the first time (and afterwards) IT would simply drag a "shortcut" to the task tray.

            Rather than requiring the user to run "Command+K" and browsing the share as shown in the above example.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @DustinB3403
              last edited by

              @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

              @coliver said in Is it possible to mount smb share using login credentials of current user.:

              @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

              @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

              If you do that mapping on the Mac, and then log in as another user, hopefully they can't see the files from the first user. If they can, that's even worse.

              This I'm not following, the goal is to create a central point that I can simply drag to an individual users desktop on any given mac, and have them connect to my Windows file server.

              Since this is a shared resource (organizationally) they would presumably be able to see the files saved on this SMB server.

              That should work. Once they login to the Mac and it's domain joined it should use the Kerberos token to authenticate.

              How would I pass the kerberos credentials into the mapping? Nothing I'm seeing appears to address it.

              Are you domain joined?

              DustinB3403D 1 Reply Last reply Reply Quote 1
              • DustinB3403D
                DustinB3403 @scottalanmiller
                last edited by

                @scottalanmiller yup.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @DustinB3403
                  last edited by

                  @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                  @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                  If you do that mapping on the Mac, and then log in as another user, hopefully they can't see the files from the first user. If they can, that's even worse.

                  This I'm not following, the goal is to create a central point that I can simply drag to an individual users desktop on any given mac, and have them connect to my Windows file server.

                  Since this is a shared resource (organizationally) they would presumably be able to see the files saved on this SMB server.

                  Are they on Kerberos and have access to that share? Does the same thing work on Windows?

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @DustinB3403
                    last edited by

                    @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                    @scottalanmiller yup.

                    Okay, so this is a Mac? This isn't a question that can be asked generically. This depends on the SMB protocol server being used. Is this Mac, Samba, Windows, etc. That makes a difference. What is needed or will work for UNIX that isn't Mac doesn't apply to Mac because Mac doesn't use Samba and all other UNIX does.

                    DustinB3403D 2 Replies Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      The thing that you are trying to do, I think, is something that even Windows can't do. Or else I'm not understanding the goal. Can you explain it in a Windows context then we can translate to Mac or Samba?

                      DustinB3403D 1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403 @scottalanmiller
                        last edited by

                        @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                        @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                        @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                        If you do that mapping on the Mac, and then log in as another user, hopefully they can't see the files from the first user. If they can, that's even worse.

                        This I'm not following, the goal is to create a central point that I can simply drag to an individual users desktop on any given mac, and have them connect to my Windows file server.

                        Since this is a shared resource (organizationally) they would presumably be able to see the files saved on this SMB server.

                        Are they on Kerberos and have access to that share? Does the same thing work on Windows?

                        On Windows I haven't investigated, but we simply create a shortcut for the user, and their domain credentials allow them access to the share.

                        We support Kerberos yes. I could open the share using Apple's "Connect to server" without having to type in additional credentials.

                        1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403 @scottalanmiller
                          last edited by

                          @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                          @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                          @scottalanmiller yup.

                          Okay, so this is a Mac? This isn't a question that can be asked generically. This depends on the SMB protocol server being used. Is this Mac, Samba, Windows, etc. That makes a difference. What is needed or will work for UNIX that isn't Mac doesn't apply to Mac because Mac doesn't use Samba and all other UNIX does.

                          (tags buddy tags) although I should've put this bit into the OP.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • DustinB3403D
                            DustinB3403 @scottalanmiller
                            last edited by DustinB3403

                            @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                            The thing that you are trying to do, I think, is something that even Windows can't do. Or else I'm not understanding the goal. Can you explain it in a Windows context then we can translate to Mac or Samba?

                            Windows World:

                            Create shortcut on desktop: Server1

                            Shortcut details

                            Target: \server.domain.com

                            Immediately opens the available shares on the server without having to pass additional credentials.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @DustinB3403
                              last edited by

                              @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                              @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                              The thing that you are trying to do, I think, is something that even Windows can't do. Or else I'm not understanding the goal. Can you explain it in a Windows context then we can translate to Mac or Samba?

                              Windows World:

                              Create shortcut on desktop: Server1

                              Immediately opens the available shares on the server without having to pass additional credentials.

                              Okay, so in theory all we need is a link to the URI and we'd like that sitting on the Mac desktop so they just click on that?

                              DustinB3403D 1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @DustinB3403
                                last edited by

                                @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                @scottalanmiller yup.

                                Okay, so this is a Mac? This isn't a question that can be asked generically. This depends on the SMB protocol server being used. Is this Mac, Samba, Windows, etc. That makes a difference. What is needed or will work for UNIX that isn't Mac doesn't apply to Mac because Mac doesn't use Samba and all other UNIX does.

                                (tags buddy tags) although I should've put this bit into the OP.

                                The tags and OP say UNIX, and not MacOS, which while MacOS is UNIX for sure, it's also totally separate from all other UNIX in this case. So solving for the 99% would leave you without an answer here 😉

                                DustinB3403D 1 Reply Last reply Reply Quote 2
                                • DustinB3403D
                                  DustinB3403 @scottalanmiller
                                  last edited by DustinB3403

                                  @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                  @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                  @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                  The thing that you are trying to do, I think, is something that even Windows can't do. Or else I'm not understanding the goal. Can you explain it in a Windows context then we can translate to Mac or Samba?

                                  Windows World:

                                  Create shortcut on desktop: Server1

                                  Shortcut details

                                  Target: \server.domain.com

                                  Immediately opens the available shares on the server without having to pass additional credentials.

                                  Okay, so in theory all we need is a link to the URI and we'd like that sitting on the Mac desktop so they just click on that?

                                  Pretty much, or even somewhere that IT can tell the users (bulk email) to drag to their desktop.

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller
                                    last edited by

                                    https://discussions.apple.com/thread/3067279

                                    Do it manually once, right click and make an alias to put on the desktop. Does that work?

                                    DustinB3403D 1 Reply Last reply Reply Quote 0
                                    • DustinB3403D
                                      DustinB3403 @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                      @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                      @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                      @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                      @scottalanmiller yup.

                                      Okay, so this is a Mac? This isn't a question that can be asked generically. This depends on the SMB protocol server being used. Is this Mac, Samba, Windows, etc. That makes a difference. What is needed or will work for UNIX that isn't Mac doesn't apply to Mac because Mac doesn't use Samba and all other UNIX does.

                                      (tags buddy tags) although I should've put this bit into the OP.

                                      The tags and OP say UNIX, and not MacOS, which while MacOS is UNIX for sure, it's also totally separate from all other UNIX in this case. So solving for the 99% would leave you without an answer here 😉

                                      Yea... I know. Any pointers? stupid apple

                                      DustinB3403D 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Changed tags and title to reflect the topic.

                                        1 Reply Last reply Reply Quote 0
                                        • DustinB3403D
                                          DustinB3403 @DustinB3403
                                          last edited by

                                          @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                          @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                          @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                          @scottalanmiller said in Is it possible to mount smb share using login credentials of current user.:

                                          @dustinb3403 said in Is it possible to mount smb share using login credentials of current user.:

                                          @scottalanmiller yup.

                                          Okay, so this is a Mac? This isn't a question that can be asked generically. This depends on the SMB protocol server being used. Is this Mac, Samba, Windows, etc. That makes a difference. What is needed or will work for UNIX that isn't Mac doesn't apply to Mac because Mac doesn't use Samba and all other UNIX does.

                                          (tags buddy tags) although I should've put this bit into the OP.

                                          The tags and OP say UNIX, and not MacOS, which while MacOS is UNIX for sure, it's also totally separate from all other UNIX in this case. So solving for the 99% would leave you without an answer here 😉

                                          Yea... I know. Any pointers? stupid apple

                                          When I use the apple tool, it connects to the server and then ask what share I want to open. Which this is fine and what our users expect today.

                                          I also don't want to automatically mount and have mounted every individually shared folder from our server. More or less "connect when asked, not always"

                                          1 Reply Last reply Reply Quote 0
                                          • DustinB3403D
                                            DustinB3403
                                            last edited by

                                            In Windows world, connecting to my server, I connect, and then am offered all of the available shared folders.

                                            In Mac, I'm forced to select one of the shared folders to mount.

                                            Ideally, I'm looking to Mimic Windows world a bit here.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post