Building the mod_auth_kerb Apache Module
After downloading the mod_auth_kerb C source file, it can be built as a dynamic shared object (dso) that can be loaded into Apache during runtime. The distribution consists solely of a single C source file, mod_auth_kerb.c. There is no configure script, so the Apache apxs program must be run manually to compile the source file with the appropriate options to create a valid Apache module. In addition, the Kerberos libraries and include directories have to be specified.
Before beginning, ensure that your Apache has support for
loadable modules compiled in. Find the httpd binary, and use the -l option to list the modules compiled into
the Apache binary. As long as mod_so is listed, then your Apache has
support for dynamically loadable modules:
% ./httpd -l Compiled-in modules: http_core.c mod_so.c
Table 7-1 shows the compile-time options available when building mod_auth_kerb.
Option | Description |
KRB5 | Needs to be defined for Kerberos 5 support. |
KRB_DEF_REALM | Defines the default realm that is used when authenticating users. This realm is appended to usernames sent by browsers to form a complete principal name. Note that the realm must be contained in quotes, and double-escaped as it is passed through several scripts. |
APXS2 | Define this if you intend to run mod_auth_kerb with an Apache 2.x web server. Otherwise, a module for Apache 1.3.x is built. |
KRB5_SAVE_CREDENTIALS | Forces mod_auth_kerb to keep the user’s TGT after ... |
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access