SSSD/Kerberos/LDAP Authentication: Difference between revisions

From UNIX Systems Administration
Jump to navigation Jump to search
No edit summary
Line 10: Line 10:
#Gather the list of KDCs for the realm, the KDCs are bold italic.
#Gather the list of KDCs for the realm, the KDCs are bold italic.
##<tt>'''# nslookup -type=SRV _kerberos._tcp.<domain in lowercase>'''</tt>
##<tt>'''# nslookup -type=SRV _kerberos._tcp.<domain in lowercase>'''</tt>
*#*;:::Output of previous command:
###:::Output of previous command:
###:::<tt>Server:        <ip address>
###:::<tt>Server:        <ip address>
###:::Address:        <ip address>#53<br /><br />
###:::Address:        <ip address>#53<br /><br />

Revision as of 16:24, 21 July 2016

Install Required Packages

  1. RHEL6: Install the following packages.
    1. # yum install sssd krb5-workstation samba-common authconfig oddjob oddjob-mkhomedir openldap-clients ipa-client sssd-common krb5-devel
  2. RHEL7: Install the following packages
    1. # yum install sssd krb5-workstation samba-common authconfig oddjob oddjob-mkhomedir openldap-clients sssd-libwbclient sssd-tools ipa-client sssd-common krb5-devel
  3. UBUNTU: Install the following packages
    1. $ sudo apt-get install krb5-user krb5-config samba sssd ntp nscd libpam-sss libnss-sss sssd-tools sssd-ad libpam-modules

Configure Kerberos

  1. Gather the list of KDCs for the realm, the KDCs are bold italic.
    1. # nslookup -type=SRV _kerberos._tcp.<domain in lowercase>
      1. Output of previous command:
        Server: <ip address>
        Address: <ip address>#53

        _kerberos._tcp.<domain in lowercase> service = 0 100 88 dc1.<domain in lowercase>.
        _kerberos._tcp.<domain in lowercase> service = 0 100 88 dc2.<domain in lowercase>.
        _kerberos._tcp.<domain in lowercase> service = 0 100 88 dc3.<domain in lowercase>.
        _kerberos._tcp.<domain in lowercase> service = 0 100 88 dc4.<domain in lowercase>.
  2. Create a backup of the /etc/krb5.conf file.
    1. # cp -p /etc/krb5.conf{,.bak}
    2. Modify the /etc/krb5.conf file as follows, changes are highlighted in yellow.