LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 08-20-2012, 03:26 AM   #1
frenchviking
LQ Newbie
 
Registered: May 2012
Posts: 11

Rep: Reputation: Disabled
Apache SSO in multi domain Windows environment


Hello,

I have a RedHat 5.7 server with Apache 2.2.3 configured to automatically authenticate users when they reach a website. The SSO is working for only one domain, but users can log in with others domains accounts without SSO.

Every domain has a trust with others. I thought this would be enough for authentication to work with multiple domains.

Is it possible to make SSO work in a multiple domains environment ?

Here is an extract of my /etc/krb5.conf

Quote:
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log

[libdefaults]
default_realm = DOMAIN1.COM
default_keytab_name = /var/sites/conf_apache/extranet.V1.keytab HTTP/extranet.com@DOMAIN1.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
default_tkt_enctypes = arcfour-hmac-md5
default_tgs_enctypes = arcfour-hmac-md5
allow_weak_crypto = true

[realms]
DOMAIN1.COM = {
kdc = DC1.DOMAIN1.COM:88
admin_server = DOMAIN1.COM:749
default_domain = DOMAIN1.COM
}
DOMAIN2.COM = {
kdc = DC1.DOMAIN2.COM:88
admin_server = DOMAIN2.COM:749
default_domain = DOMAIN2.COM
}
DOMAIN3.COM = {
kdc = DC1.DOMAIN3.COM:88
admin_server = DOMAIN3.COM:749
default_domain = DOMAIN3.COM
}


[domain_realm]
.DOMAIN1.COM = DOMAIN1.COM
DOMAIN1.COM = DOMAIN1.COM
.DOMAIN2.COM = DOMAIN2.COM
DOMAIN2.COM = DOMAIN2.COM
.DOMAIN3.COM = DOMAIN3.COM
DOMAIN3.COM = DOMAIN3.COM


[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false


The Kerberos part of my Virtualhost:

Quote:
<Location />
AuthName "Extranet"

KrbMethodNegotiate On
KrbAuthoritative On
KrbMethodK5Passwd On
KrbAuthRealms DOMAIN1.COM DOMAIN2.COM DOMAIN3.COM
AuthType Kerberos
require valid-user
KrbServiceName HTTP/extranet.org@DOMAIN1.COM
Krb5KeyTab /var/sites/conf_apache/extranet.V1.keytab
</Location>
Do I have to generate a per domain keytab and put it in the Vhost ? Actually it was generated from DOMAIN1.COM.

Thank you.
 
Old 08-20-2012, 07:17 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,758

Rep: Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643Reputation: 643
I believe what you need is transitive trust relationships which is not currently possible with AD - I've been waiting for IPA v3 which has just come out (beta), if you take a look at the new IPA architecture you'll see how many components it takes to make it possible.

Maybe you should run a POC in the lab, that's what I'll be doing.
 
Old 08-21-2012, 01:46 AM   #3
frenchviking
LQ Newbie
 
Registered: May 2012
Posts: 11

Original Poster
Rep: Reputation: Disabled
thank you for your answer. If this is the only solution, I will let it go. I was looking for an error in my configuration. The SSO on multi domains is more a best effort for our users than a real need.

Thank you again, I will keep an eye on IPA v3.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adding linux laptop into a windows domain environment. ocardona Linux - Newbie 4 12-30-2012 01:11 PM
Apache SSO using mod_auth_remote rosv Linux - Security 1 08-18-2010 08:05 AM
Authz_ldap? I need to have SSO with kerberos against a AD domain mujzeptu Linux - Server 6 02-07-2008 10:53 AM
How to access samba share in a Windows domain environment qdog007 Linux - Software 6 02-28-2007 11:56 PM
windows domain like environment...pl. help azamup Debian 1 02-19-2007 07:57 AM


All times are GMT -5. The time now is 05:23 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration