LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-03-2011, 10:56 PM   #1
author_unknown
Member
 
Registered: Aug 2007
Location: Buffalo, NY
Distribution: Fedora 7, RHEL5, CentOS 5 and Backtrack 2.0
Posts: 73

Rep: Reputation: 15
Problem with Kerberos authenticcation


We are trying to implement a centralized Kerberos authentication mechanism for our Linux machines.

The REALM NAME is EXAMPLE.COM

Right now I have two machines:
1. server.example.com -> it runs the krb5kdc (KDC) and kadmind daemons.
2. client1.example.com -> configured to accept logins from Kerberos server.

The Kerberos server is working fine.

I created a principal “bryan” using kadmin.local script with password abc123
I tried logging in to client1.example.com using the same. the login failed citing incorrect username and password.

I created a user named “bryan” on client1.example.com with password Infy123+.
I tried logging in to client1.example.com using the password abc123 setup in Kerberos, this time the login succeeded
executing klist showed that there is a valid token issued.
I destroyed the token by using kdestroy

Now I tried logging in again with user “bryan” but this time with password Infy123+ and the login succeeded this time too.
executing klist showed that there is NO token issued

So , as per the requirement, I want to facilitate:
1. dynamic account creation for a principal i.e. the user account to be created automatically when the user logs in.
2. Disable login through the local Linux/Unix account


Any help would really be appreciated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh and kerberos error: Server not found in Kerberos database Felipe Linux - Server 1 01-17-2011 03:12 AM
Problem with Kerberos Authentication wxiluo Linux - Server 1 09-24-2009 05:57 AM
Problem for get ticket from kerberos aspenbr Linux - Networking 1 08-11-2009 10:44 AM
problem in configuring kerberos kban Linux - Networking 1 06-13-2006 08:02 AM
Kerberos Install Problem! mesh2005 Linux - Networking 2 11-10-2005 05:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration