Changes between Version 8 and Version 9 of howto/SquidKerberosAuthentication


Ignore:
Timestamp:
12/22/10 20:16:29 (13 years ago)
Author:
Edwin Eefting
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • howto/SquidKerberosAuthentication

    v8 v9  
    5050Eerst moeten we zorgen dat kerberos goed werkt. De config staat nog in /etc, maar deze komt later misschien in /home/system:
    5151{{{
     52[Syn-3] root@proxy.adtest.psy.datux.nl ~# cat /etc/krb5.conf
     53[logging]
     54 default = FILE:/var/log/krb5libs.log
     55 kdc = FILE:/var/log/krb5kdc.log
     56 admin_server = FILE:/var/log/kadmind.log
     57
     58[libdefaults]
     59 default_realm = ADTEST.PSY.DATUX.NL
     60 dns_lookup_realm = false
     61 dns_lookup_kdc = false
     62 ticket_lifetime = 24h
     63
     64# For Windows XP:
     65 default_tgs_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
     66 default_tkt_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
     67 permitted_enctypes = rc4-hmac des-cbc-crc des-cbc-md5
     68
     69# For Windows 2007:
     70# default_tgs_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
     71# default_tkt_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
     72# permitted_enctypes = aes256-cts-hmac-sha1-96 rc4-hmac des-cbc-crc des-cbc-md5
     73 forwardable = yes
     74
     75[realms]
     76 ADTEST.PSY.DATUX.NL = {
     77  kdc = 192.168.13.13:88
     78  admin_server = 192.168.13.13:7491
     79  default_domain = adtest.psy.datux.nl
     80 }
     81
     82[domain_realm]
     83 .adtest.psy.datux.nl = ADTEST.PSY.DATUX.NL
     84 adtest.psy.datux.nl = ADTEST.PSY.DATUX.NL
     85
     86[appdefaults]
     87 pam = {
     88   debug = false
     89   ticket_lifetime = 36000
     90   renew_lifetime = 36000
     91   forwardable = true
     92   krb4_convert = false
     93}
     94
    5295}}}
    5396