Configuring mod_auth_kerb
Once the module has been built and placed in the Apache
module directory, then it can be added to the server’s
httpd.conf file. Add the following LoadModule line:
LoadModule kerb_auth_module libexec/apache/mod_auth_kerb.so
Also add the following AddModule line to your
httpd.conf file:
AddModule mod_auth_kerb.c
Once these lines are in place in the httpd.conf configuration file, then the Kerberos authentication module can be configured for use through htaccess files or directly inside of the Apache configuration file, like any other Apache authentication module. An htaccess file looks like the following:
AuthType KerberosV5 AuthName "Kerberos password" KrbAuthRealm WEDGIE.ORG require valid-user
This example prompts users to enter in credentials, asking for
their “Kerberos password” as defined in the AuthName clause. Note that this will accept
any valid credentials for any principal in the WEDGIE.ORG Kerberos
realm. If further access control is desired, the standard Apache user
list and group functionality can be used to limit authorization to a
subset of principal names. An up-to-date list of the configuration
directives that can be placed in the htaccess
file can be found at the mod_auth_kerb site.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access