Configuring GSSAPI with eDirectory
E
no
vd
ocx
(e
n)
6 Ap
ril 20
07
611
E
Configuring GSSAPI with
eDirectory
The SASL-GSSAPI mechanism for Novell
®
eDirectory
TM
enables you to authenticate to eDirectory
through LDAP using a Kerberos ticket. You are not required to enter the eDirectory user password.
The Kerberos ticket should be obtained by authenticating to a Kerberos server.
For SASL-GSSAPI conceptual information, refer to the
Novell eDirectory 8.8 What's New Guide
(http://www.novell.com/documentation/edir88/index.html)
.
NOTE:
The SASL-GSSAPI mechanism works with eDirectory 8.7.1 or later. This mechanism is
currently supported on Linux.
The following sections explain how to configure GSSAPI and describe the various tasks you can
perform with Kerberos in eDirectory and give some useful additional information:
Section E.1, “Prerequisites,” on page 611
Section E.2, “Configuring the SASL-GSSAPI Method,” on page 615
Section E.3, “Managing the SASL-GSSAPI Method,” on page 616
Section E.4, “Creating a Login Sequence,” on page 622
Section E.5, “How Does LDAP Use SASL-GSSAPI?,” on page 622
Section E.6, “Error Messages,” on page 622
E.1 Prerequisites
To configure GSSAPI, you must first do the following:
SASL-GSSAPI method:
Install the SASL-GSSAPI method. Refer to the Installing a Login
Method section in the
NMAS 3.0 Administration Guide
(http://www.novell.com/
documentation/nmas30/admin/data/a49tuwk.html#a49tuwk)
.
NOTE:
To install the SASL-GSSAPI login method on NetWare, follow the same procedure as
in Windows.
To verify whether SASL-GSSAPI is installed on your machine, enter the following:
ldapsearch -x -h osg-dt-srv9 -b " " -s base | grep -i sasl
If SASL-GSSAPI is installed, the output of the command is similar to the following:
supportedSASLMechanisms: NMAS_LOGIN
supportedSASLMechanisms: GSSAPI
Kerberos plug-in for iManager:
Install the Kerberos plug-in for iManager. Refer to
Section E.1.2, “Installing the Kerberos Plug-in for iManager,” on page 612
for more
information.
KDC:
Install Kerberos KDC (MIT, Microsoft (Active Directory), or Heimdal) on the network.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...