The s3 SMB client bindings seem slightly different to s4, in that they
default to setting the CLI_FULL_CONNECTION_FALLBACK_AFTER_KERBEROS flag.
This seems to fallback to finding a valid KRB TGT (from a previous
successful test), which results in the connection succeeding rather than
failing.
Setting MUST_USE_KERBEROS explicitly avoids this behaviour.
Signed-off-by: Tim Beale <timbeale@catalyst.net.nz>
Reviewed-by: Jeremy Allison <jra@samba.org>
"ENC-TS Pre-authentication"))
creds = self.insta_creds(template=self.get_credentials())
+ creds.set_kerberos_state(MUST_USE_KERBEROS)
creds.set_password("badPassword")
thrown = False
EVT_LOGON_NETWORK))
creds = self.insta_creds(template=self.get_credentials())
+ creds.set_kerberos_state(MUST_USE_KERBEROS)
creds.set_username("badUser")
thrown = False