SSSD/Kerberos/LDAP Authentication: Difference between revisions

From UNIX Systems Administration
Jump to navigation Jump to search
No edit summary
No edit summary
Line 12: Line 12:
Address:        <ip address>#53
Address:        <ip address>#53
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc1.<domain in lowercase></span>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc1.<domain in lowercase>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc2.<domain in lowercase></span>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc2.<domain in lowercase>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc3.<domain in lowercase></span>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc3.<domain in lowercase>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc4.<domain in lowercase></span>.
_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc4.<domain in lowercase>.
</pre>
</pre>
#Create a backup of the /etc/krb5.conf file.
#Create a backup of the /etc/krb5.conf file.
##<tt>'''# cp -p /etc/krb5.conf{,.bak}'''</tt>
##<tt>'''# cp -p /etc/krb5.conf{,.bak}'''</tt>
##Modify the /etc/krb5.conf file as follows, changes are highlighted in yellow.
##Modify the /etc/krb5.conf file as follows, changes are highlighted in yellow.

Revision as of 16:16, 21 July 2016

Install Required Packages

  1. RHEL6: Install the following packages.
    1. # yum install sssd krb5-workstation samba-common authconfig oddjob oddjob-mkhomedir openldap-clients ipa-client sssd-common krb5-devel
  2. RHEL7: Install the following packages
    1. # yum install sssd krb5-workstation samba-common authconfig oddjob oddjob-mkhomedir openldap-clients sssd-libwbclient sssd-tools ipa-client sssd-common krb5-devel

Configure Kerberos

  1. Gather the list of KDCs for the realm.
    1. # nslookup -type=SRV _kerberos._tcp.<domain in lowercase>

Output of previous command:

	Server:         <ip address>
	Address:        <ip address>#53
		
	_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc1.<domain in lowercase>.
	_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc2.<domain in lowercase>.
	_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc3.<domain in lowercase>.
	_kerberos._tcp.<domain in lowercase>        service = 0 100 88 <span style="background:yellow">dc4.<domain in lowercase>.	
  1. Create a backup of the /etc/krb5.conf file.
    1. # cp -p /etc/krb5.conf{,.bak}
    2. Modify the /etc/krb5.conf file as follows, changes are highlighted in yellow.