Unix Technical Forum

Using Active Directory Kerberos for Apache access

This is a discussion on Using Active Directory Kerberos for Apache access within the Linux Operating System forums, part of the Unix Operating Systems category; --> Hi, folks. There are lots of references to using Kerberos for Active Directory based authentication, and setting up the ...


Go Back   Unix Technical Forum > Unix Operating Systems > Linux Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-04-2008, 07:47 AM
Nico Kadel-Garcia
 
Posts: n/a
Default Using Active Directory Kerberos for Apache access

Hi, folks. There are lots of references to using Kerberos for Active
Directory based authentication, and setting up the Apache server to
authenticate itself as a registered Kerberos authentication client.
But this takes getting hostkeys installed, and I have access issues to
the Active Directory server to get the Linux server's keys installed.

I *KNOW* there's a way with HTTPD 2.x to have the webserver
authenticate against the Kerberos server, *without* registering it. I
saw it done with RHEL 4 last year. I've seen it done, but don't have
an example. I just want to have the web clients logging in
consistently with their Windows usernames and passwords, so we don't
have to maintain another inconsistent and awkward username and pasword
list to manage.

Does anyone have such a .conf file?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 07-04-2008, 07:47 AM
Allen Kistler
 
Posts: n/a
Default Re: Using Active Directory Kerberos for Apache access

Nico Kadel-Garcia wrote:
> Hi, folks. There are lots of references to using Kerberos for Active
> Directory based authentication, and setting up the Apache server to
> authenticate itself as a registered Kerberos authentication client.
> But this takes getting hostkeys installed, and I have access issues to
> the Active Directory server to get the Linux server's keys installed.
>
> I *KNOW* there's a way with HTTPD 2.x to have the webserver
> authenticate against the Kerberos server, *without* registering it. I
> saw it done with RHEL 4 last year. I've seen it done, but don't have
> an example. I just want to have the web clients logging in
> consistently with their Windows usernames and passwords, so we don't
> have to maintain another inconsistent and awkward username and pasword
> list to manage.
>
> Does anyone have such a .conf file?


The integration with AD was probably LDAP, not Kerberos.
AD=LDAP+Kerberos
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 07-05-2008, 02:15 AM
Nico Kadel-Garcia
 
Posts: n/a
Default Re: Using Active Directory Kerberos for Apache access

Allen Kistler wrote:
> Nico Kadel-Garcia wrote:
>> Hi, folks. There are lots of references to using Kerberos for Active
>> Directory based authentication, and setting up the Apache server to
>> authenticate itself as a registered Kerberos authentication client.
>> But this takes getting hostkeys installed, and I have access issues to
>> the Active Directory server to get the Linux server's keys installed.
>>
>> I *KNOW* there's a way with HTTPD 2.x to have the webserver
>> authenticate against the Kerberos server, *without* registering it. I
>> saw it done with RHEL 4 last year. I've seen it done, but don't have
>> an example. I just want to have the web clients logging in
>> consistently with their Windows usernames and passwords, so we don't
>> have to maintain another inconsistent and awkward username and pasword
>> list to manage.
>>
>> Does anyone have such a .conf file?

>
> The integration with AD was probably LDAP, not Kerberos.
> AD=LDAP+Kerberos


While the LDAP in Active Directory is defintely accessible, it's awkward and
painful to use. No, I've seen it done with bare Kerberos. It presents a
security concern to do without registering Kerberos host keys on the Linux
Apache server, but I've seen it done with LDAP nowhere near the mix.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 06:10 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com