Configuring saslauthd
At this point, SASL-enabled applications will be able to use the SASL GSSAPI support to perform native Kerberos 5 authentication. However, there is still a dearth of client applications that are able to perform GSSAPI authentication. Therefore, for backward compatibility with these clients, the saslauthd daemon can be configured to provide password verification services to services that use SASL for authentication services.
The saslauthd program is a daemon that runs continuously in the background, listening on a local domain socket for connections from services. When a service receives a connection that wishes to authenticate with a plain text login and password, it sends a message to saslauthd over the local socket, containing the username and password that the user presented for verification. Upon receipt of this information, saslauthd verifies the credentials against the configured authentication source. Through this mechanism, the security-sensitive process of verifying user passwords can be separated out into a small process that can run as root, and free the service itself from requiring superuser privileges just to verify passwords.
One of saslauthd’s supported authentication mechanisms is Kerberos 5. When verifying Kerberos passwords, saslauthd takes the username and password passed to it from the requesting service, appends the local realm to the username to form the client principal, and attempts to acquire a TGT for the principal from the local realm’s ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access