You are not logged in.
Good morning.
I have an Active Directory (AD) on Windows Server 2012. This machine also shares printers and only permits printout from authenticated users. I have an ArchLinux machine added to the AD via samba and sssd. I log in the ArchLinux machine with AD credentials and can access Windows shares.
I set up a printer queue in CUPS with URI smb://server/printer. If I send jobs via the command 'lpr -P printer file.pdf', the printer responds with 'Tree connect failed (NT_STATUS_ACCESS_DENIED)'. However, if I send them via the command 'smbclient -k //server/printer -c "print file.pdf"', AD credentials are taken from the kerberos ticket and the jobs are printed appropriately. I have tried the URI smb://user:password@server/printer and it works. Although the user and password do not appear in the URI after installing the printer, they appear in /etc/cups/printers.conf without encryption. I do not want this approach because it is not secure.
I have tried 'DefaultAuthType Negotiate' in /etc/cups/cupsd.conf and all values for 'OpPolicy' in /etc/cups/printers.conf. No combination works for me.
The file /usr/lib/cups/backend/smb looks like this:
lrwxrwxrwx 1 root root 17 dic 27 11:54 /usr/lib/cups/backend/smb -> /usr/bin/smbspool
Package versions:
cups 2.2.6-4
samba 4.7.4-1
sssd 1.16.0-4
krb5 1.16.1
¿Someone can help me?
Thanks in advance.
Offline