Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 3rd December 2009, 02:33 PM
tenmoi Offline
Registered User
 
Join Date: Feb 2007
Posts: 24
linuxfedorafirefox
Set up 389 DS server as Kerberos V principal database

Hi!

I have set up a 389 DS server and a kdc . However there is not a howto or any document concerning setting up the DS as a Kerberos database back-end. Nor is there a 389 DS forum, so I am asking here and hopefully some of you could possibly help or throw in some light as to this kind of setup.

I have read the 389 DS features page and the Redhat documents but there is no reference to this feature.

Thank you.
Reply With Quote
  #2  
Old 3rd December 2009, 09:35 PM
dburkland Offline
Registered User
 
Join Date: Aug 2009
Posts: 13
windows_xp_2003firefox
I am not really familiar with 389 DS but I just recently completed a similar probject using MIT-KRB5 and OpenLDAP. I don't know how different 389 DS is from OpenLDAP but this article may provide some help. Feel free to PM me if you like
Reply With Quote
  #3  
Old 4th December 2009, 01:55 PM
tenmoi Offline
Registered User
 
Join Date: Feb 2007
Posts: 24
linuxubuntufirefox
Thank you for your reply.

The link you provided is probably only applied to openldap (I guess so because I convert the kerberos.schema and then import it to DS to no avail.)

In fact I did set up the DS and Kdc and can authenticate both fedora and ubuntu karmic against the DS, using credentials set in the DS.

What I want to achieve is to configure Kerberos to use DS (not Openldap) as its principal database. Of course,there is FreeIPA, which integrates Krb and DS, but I want to learn how those separate pieces work.

BY the way, I'd like to ask this question:
I installed FreeIPA and pass all tests and follow all troubleshooting guides but I cannot log in to the server thru firefox with the error "kerberos login error".

Thank you.
Reply With Quote
  #4  
Old 7th April 2010, 05:42 PM
robert.forster's Avatar
robert.forster Offline
Registered User
 
Join Date: Feb 2008
Location: Newport News, VA
Posts: 128
windows_xp_2003firefox
Re: Set up 389 DS server as Kerberos V principal database

I have setup something along those lines

Currently running 389 to handle usernames and posix information along with remove directories and automount FS and KRB5 system

Unfortunately to integrate the two together wasn't worth it to me. I handle to two separately and use a perl script to create the accounts.

389 handles UID/GID homedir/autoFS w/secureNFS
Kerberos KRB5 authentication

I initially wanted it all done within FDS but found that there were to many hurdles and issues with FDS (now 389) calling on KRB
__________________
Intel Core2 QUADcore 2.4 Ghz
RAM = 3GIG
ATI Radeon HD 2400
Dual 19" monitors
Windows XP sp3
DVD+/- RW 16
HD=250G (OS) 500G + 300G (storage)

[Microsoft] Vista - Definition per http://dictionary.reference.com "a far-reaching mental view" :eek: (but not realistic?)

registered linux user #467749 :cool:
Reply With Quote
Reply

Tags
389, database, kerberos, principal, server, set

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
vsftpd server and kerberos problem ole123 Using Fedora 1 29th October 2008 01:47 AM
Kerberos v5 realm server at Fedora - Help needed Molot Servers & Networking 1 5th July 2005 11:02 PM


Current GMT-time: 11:15 (Tuesday, 21-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat