Koozali.org: home of the SME Server

Hyper-v Replication and Kerberos - am I barking up the wrong tree here?

Offline jptechnical

  • ***
  • 68
  • +0/-0
Hi all... it has been a long time since I was able to use SME server, and I am excited to see 2 full generations have come, excellent work everyone!

So... here is what I am trying to accomplish, and I am not sure where to start looking. Replication for 2 hyper-v 2012 r2 servers. I can join them to the 9.1 domain (9.1 bone-stock), and all the authentication goodness seems to be working. However, when I try to setup replication using kerberos as the authentication method it fails.

Is this a limitation of sme, or samba 3x, or is this just something not within the realm of possibility and I should just 'move along, nothing to see here'?


It feels great to be back!


Here is the error I get, in case any care to see the details.

[Main Instruction]
Enabling replication failed.

[Content]
Hyper-V failed to enable replication.

Hyper-V failed to authenticate using Kerberos authentication.

[Expanded Information]
Hyper-V failed to enable replication for virtual machine 'FreeNAS-Test': No authority could be contacted for authentication. (0x80090311). (Virtual machine ID 4DE5FBF0-AB90-4FC3-8C1B-15274F95DA56)

Hyper-V failed to authenticate the Replica server VMHOST1.corp using Kerberos authentication. Error: No authority could be contacted for authentication. (0x80090311)


Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Hyper-v Replication and Kerberos - am I barking up the wrong tree here?
« Reply #1 on: January 16, 2016, 11:06:07 AM »
I guess you're talking about AD replication, which is unsupported in SME9 (and in most linux distros, since AD is something available only with samba4)

Offline jptechnical

  • ***
  • 68
  • +0/-0
Re: Hyper-v Replication and Kerberos - am I barking up the wrong tree here?
« Reply #2 on: January 16, 2016, 08:20:11 PM »
Thanks for replying.

Actually, no. This is hyper-v replication specifically, which doesn't really have anything to do with Active Directory replication. The devices talk directly to each other to replicate data, they can do the authentication mechanism in a couple of ways, one is certificate-based the other is Kerberos based. The Kerberos authentication method is by far the simplest from the host machines.

I can make certificate based authentication work, but it is far more complicated, and lots of moving parts with generating and installing certificates.

 I suppose my understanding of Kerberos and Active Directory is pretty weak, so there may be far more reliance on Active Directory that I'm aware of. So I may indeed be barking up the wrong tree. But thanks for looking and commenting none the less.

Offline Daniel B.

  • *
  • 1,700
  • +0/-0
    • Firewall Services, la sécurité des réseaux
Re: Hyper-v Replication and Kerberos - am I barking up the wrong tree here?
« Reply #3 on: January 17, 2016, 01:36:26 PM »
Most likely kerberos auth between the 2 hyper-V will only work if both are part of an AD domain. As they are in a NT domain, without kerb support, you'll have to switch to another auth mecanism
C'est la fin du monde !!! :lol: