Anonymous
Not logged in
Log in
Request account
Search
Changes
From Pumping Station One
Namespaces
Page
Discussion
More
More
Languages
Page actions
Read
View source
History
← Older edit
Newer edit →
Systems/Services/Kerberos
(view source)
Revision as of 19:25, 20 September 2014
755 bytes added
,
19:25, 20 September 2014
→Kerberos
Line 36:
Line 36:
ad.pumpingstationone.org = AD.PUMPINGSTATIONONE.ORG
ad.pumpingstationone.org = AD.PUMPINGSTATIONONE.ORG
.ad.pumpingstationone.org = AD.PUMPINGSTATIONONE.ORG
.ad.pumpingstationone.org = AD.PUMPINGSTATIONONE.ORG
+
</pre>
+
+
== Apache SSO ==
+
+
Setting up the keytab:
+
<pre>
+
msktutil -u -s HTTP --server bob
+
cp /etc/krb5.keytab /usr/local/etc/apache24/krb5.keytab
+
ktutil -k /usr/local/etc/apache24/krb5.keytab remove -p rack\$
+
ktutil -k /usr/local/etc/apache24/krb5.keytab remove -p host/rack.ad.pumpingstationone.org
+
chown www /usr/local/etc/apache24/krb5.keytab
+
<pre>
+
+
Configure Auth:
+
<pre>
+
Authtype Kerberos
+
AuthName "AD.PUMPINGSTATIONONE.ORG"
+
KrbAuthoritative on
+
KrbServiceName HTTP/rack.ad.pumpingstationone.org
+
Krb5Keytab /usr/local/etc/apache24/krb5.keytab
+
KrbAuthRealms AD.PUMPINGSTATIONONE.ORG
+
KrbMethodk5Passwd on
+
KrbMethodNegotiate on
+
Require valid-user
</pre>
</pre>
Amishhammer
483
edits
Cookies help us deliver our services. By using our services, you agree to our use of cookies.
More information
OK
Navigation
Navigation
Main page
Recent changes
Random page
Help about MediaWiki
Wiki tools
Wiki tools
Special pages
Page tools
Page tools
Userpage tools
More
Printable version