I have a simple Apache setup that works fine when I create a keytab on a domain level authentication works fine. When I create a keytab at the forest level authentication does not work. I get the following error message. Does anyone know what I am doing wrong here? I validated there is the SPN is unique on the AD side.
Our Network Security folks have mandated that we "Kerberize" our systems to allow them to perform an authenticated scan. This consists of instructions to change /etc/pam.d/sshd from:
# sshd: auth account password session
auth optional pam_krb5.so use_kcminit
auth optional ... (0 Replies)
I'm fairly new to UNIX-land, and one of my first assigned tasks was to try to set up Kerberos authentication on an unused partition. Hopefully everything makes sense, but please let me know if any clarification is needed with any of it.
AIX 7.1, and while I found various docs on the subject, a... (11 Replies)
Dear Expert,
i have linux box that is running in the windows domain, BUT did not being a member of the domain. as I am not the System Administrator so I have no control on the server in the network, such as modify dns entry , add the linux box in AD and domain record and so on that relevant.
... (2 Replies)
I am in the process of developing a application that needs to be able to authenticate users details with a kerberos server, which is proving to be rather difficult. There seems to be a lack of good information on how to do this using the MIT kerberos api.
Can anyone point me in the right... (0 Replies)
I have 2 servers (lft1 and lft3) running AIX 5.3 ML 5. Both are installed with krb5.client.rte 1.4.0.4 and openssh.base.server 4.3.0.5300.
I have configured some of the users on both servers to authenticate against our Windows 2003 Active Directory. From my PC, I can use telnet to login... (1 Reply)
I have installed Kerberos security in my UNIX system but I need to disable because of an application conflict with Kerberos.
So Anybody ca tell me how can I disable it?
Thank you (1 Reply)
ktutil(1) User Commands ktutil(1)NAME
ktutil - Kerberos keytab maintenance utility
SYNOPSIS
/usr/bin/ktutil
DESCRIPTION
The ktutil command is an interactive command-line interface utility for managing the keylist in keytab files. You must read in a keytab's
keylist before you can manage it. Also, the user running the ktutil command must have read/write permissions on the keytab. For example,
if a keytab is owned by root, which it typically is, ktutil must be run as root to have the appropriate permissions.
COMMANDS
clear_list Clears the current keylist.
clear
read_kt file Reads a keytab into the current keylist. You must specify a keytab file to read.
rkt file
write_kt file Writes the current keylist to a keytab file. You must specify a keytab file to write. If the keytab file already
wkt file exists, the current keylist is appended to the existing keytab file.
add_entry number Adds an entry to the current keylist. Specify the entry by the keylist slot number.
addent number
delete_entry number Deletes an entry from the current keylist. Specify the entry by the keylist slot number.
delent number
list Lists the current keylist.
l
list_request Lists available requests (commands).
lr
quit Exits utility.
exit
q
EXAMPLES
Example 1 Deleting a principal from a file
The following example deletes the host/denver@ACME.com principal from the /etc/krb5/krb5.keytab file. Notice that if you want to delete an
entry from an existing keytab, you must first write the keylist to a temporary keytab and then overwrite the existing keytab with the tem-
porary keytab. This is because the wkt command actually appends the current keylist to an existing keytab, so you can't use it to overwrite
a keytab.
example# /usr/krb5/bin/ktutil
ktutil: rkt /etc/krb5/krb5.keytab
ktutil: list
slot KVNO Principal
---- ---- ---------------------------------------
1 8 host/vail@ACME.COM
2 5 host/denver@ACME.COM
ktutil:delent 2
ktutil:l
slot KVNO Principal
---- ---- --------------------------------------
1 8 host/vail@ACME.COM
ktutil:wkt /tmp/krb5.keytab
ktutil:q
example# mv /tmp/krb5.keytab /etc/krb5/krb5.keytab
FILES
/etc/krb5/krb5.keytab keytab file for Kerberos clients
ATTRIBUTES
See attributes(5) for descriptions of the following attributes:
+-----------------------------+-----------------------------+
| ATTRIBUTE TYPE | ATTRIBUTE VALUE |
+-----------------------------+-----------------------------+
|Availability |SUNWkrbu |
+-----------------------------+-----------------------------+
|Interface Stability |See below. |
+-----------------------------+-----------------------------+
The command arguments are Evolving. The command output is Unstable.
SEE ALSO kadmin(1M), k5srvutil(1M), attributes(5), kerberos(5)SunOS 5.11 16 Nov 2006 ktutil(1)