LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 08-21-2018, 03:18 PM   #31
bam80
Member
 
Registered: Nov 2015
Location: Russia
Distribution: Slackware
Posts: 56

Rep: Reputation: Disabled
Question


Quote:
Originally Posted by kjhambrick View Post
Will set up a pair of Slackware64 14.2+current VMWare Machines and I'll take spamware for a spin
Hi all, thanks for PAM efforts.
Has anyone tried this with Slackware64 14.2?
 
Old 09-02-2018, 07:17 PM   #32
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
Well, the stuff in /etc/pam.d has been cleaned and provides a consistent policy across all services. The project shifts to maintenance mode. Hopefully P.V. will decide on the inclusion of PAM&Kerberos before Plasma5 goes in. I wont have the time and especially the motivation to PAMify it.


Cheers
 
7 members found this post helpful.
Old 09-15-2018, 05:07 PM   #33
ivandi
Member
 
Registered: Jul 2009
Location: Québec, Canada
Distribution: CRUX, Debian
Posts: 528

Original Poster
Rep: Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866Reputation: 866
Heads-up for samba-4.9.0.

We no longer need an ugly hack in /etc/krb5.conf to canonicalize user names:
Quote:
Local authorization plugin for MIT Kerberos
-------------------------------------------

This plugin controls the relationship between Kerberos principals and AD
accounts through winbind. The module receives the Kerberos principal and the
local account name as inputs and can then check if they match. This can resolve
issues with canonicalized names returned by Kerberos within AD. If the user
tries to log in as 'alice', but the samAccountName is set to ALICE (uppercase),
Kerberos would return ALICE as the username. Kerberos would not be able to map
'alice' to 'ALICE' in this case and auth would fail. With this plugin, account
names can be correctly mapped. This only applies to GSSAPI authentication,
not for getting the initial ticket granting ticket.
An /etc/krb5.conf like this works fine:
Code:
[libdefaults]
    default_realm    = EXAMPLE.NET
    dns_lookup_realm = false
    dns_lookup_kdc   = true

[logging]
    default          = SYSLOG:NOTICE

[plugins]
    localauth = {
	module = winbind:winbind/winbind_krb5_localauth.so
	enable_only = winbind
    }
And a change in "net ads keytab add":
Quote:
'net ads keytab' changes
------------------------

net ads keytab add no longer attempts to convert the passed serviceclass
(e.g. nfs, html etc.) into a Windows SPN which is added to the Windows AD
computer object. By default just the keytab file is modified.

A new keytab subcommand 'add_update_ads' has been added to preserve the
legacy behaviour. However the new 'net ads setspn add' subcommand should
really be used instead.

net ads keytab create no longer tries to generate SPN(s) from existing
entries in a keytab file. If it is required to add Windows SPN(s) then
'net ads setspn add' should be used instead.
So for nfs now we use "net ads add_update_ads nfs".


Cheers
 
3 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[ANN] Soma 2.13.0 dive Slackware 12 12-17-2017 07:06 PM
[ANN] mkslack 4.8 dive Slackware 0 05-05-2015 06:45 AM
[ANN] Soma 2.10.0 dive Slackware 2 04-16-2015 04:32 AM
[ANN] mkslack 4.7 dive Slackware 1 04-12-2015 12:34 PM
[ANN] Soma 2.7.1 dive Slackware 8 08-27-2011 03:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 10:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration