Continuing on my thread of posting about Kerberos - has anyone out there had their authentication fall back to NTLM when they attempt to connect to a DFS share?
Answer
DFS and Kerberos
Best answer by frozenarse
I'm seeing this on a Lion 10.7.2 client. It is joined to an Active Directory Domain which has domain based DFS.
Connecting to SMB://domain.school.edu/share$ results in kerberos failure because there is no Service Principal Name for "domain.school.edu". The authentication falls to NTLM. If I use SMB://DCname.domain.school.edu/share$ everything works fine.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
