Now that the principal has been created, keys can be extracted for the workstation by running
kadmin
on the workstation itself, and using the
ktadd
command within
kadmin
:
ktadd -k /etc/krb5.keytab host/blah.example.com
4. To use other kerberized network services, they must first be started. Below is a list of some
common kerberized services and instructions about enabling them:
•
rsh
and
rlogin
— To use the kerberized versions of
rsh
and
rlogin
, enable
klogin
,
eklogin
, and
kshell
.
• Telnet — To use kerberized Telnet,
krb5-telnet
must be enabled.
• FTP — To provide FTP access, create and extract a key for the principal with a root of
ftp
.
Be certain to set the instance to the fully qualified hostname of the FTP server, then enable
gssftp
.
• IMAP — To use a kerberized IMAP server, the
cyrus-imap
package uses Kerberos 5 if it
also has the
cyrus-sasl-gssapi
package installed. The
cyrus-sasl-gssapi
package
contains the Cyrus SASL plugins which support GSS-API authentication. Cyrus IMAP
should function properly with Kerberos as long as the
cyrus
user is able to find the proper
key in
/etc/krb5.keytab
, and the root for the principal is set to
imap
(created with
kadmin
).
The
dovecot
package also contains an IMAP server alternative to
cyrus-imap
, which is
also included with Red Hat Enterprise Linux, but does not support GSS-API and Kerberos
to date.
• CVS — To use a kerberized CVS server,
gserver
uses a principal with a root of
cvs
and is
otherwise identical to the CVS
pserver
.
For details about how to enable services, refer to the chapter titled Controlling Access to
Services in the Red Hat Enterprise Linux System Administration Guide.
7. Additional Resources
For more information about Kerberos, refer to the following resources.
7.1. Installed Documentation
• The
/usr/share/doc/krb5-server-<version-number>/
directory — The Kerberos V5
Installation Guide and the Kerberos V5 System Administrator's Guide in PostScript and HTML
formats. The
krb5-server
package must be installed.
• The
/usr/share/doc/krb5-workstation-<version-number>/
directory — The Kerberos
V5 UNIX User's Guide in PostScript and HTML formats. The
krb5-workstation
package
Additional Resources
351
Summary of Contents for ENTERPRISE LINUX 4.5.0 -
Page 1: ...Red Hat Enterprise Linux 4 5 0 4 5 0 Reference Guide ISBN N A Publication date ...
Page 2: ...Red Hat Enterprise Linux 4 5 0 ...
Page 4: ...Red Hat Enterprise Linux 4 5 0 ...
Page 24: ...xxiv ...
Page 26: ......
Page 36: ...12 ...
Page 72: ...48 ...
Page 112: ...88 ...
Page 122: ...98 ...
Page 140: ...116 ...
Page 142: ......
Page 300: ...276 ...
Page 318: ...294 ...
Page 320: ......
Page 332: ...308 ...
Page 350: ...326 ...
Page 378: ...354 ...
Page 388: ...364 ...
Page 394: ...370 ...
Page 395: ...Part IV Appendixes ...
Page 396: ......