August 2003
Intermediate to advanced
270 pages
10h 9m
English
We must establish a cross-realm trust between the UNIX.SAMPLE.COM realm and the Active Directory domain SAMPLE.COM. This trust will be used so that users in the SAMPLE.COM Active Directory domain can transparently log into machines located in the UNIX.SAMPLE.COM Kerberos realm. We’ll be following the instructions outlined in Chapter 8 to establish a cross-realm trust between a Unix-based Kerberos realm and a Windows domain.
First, we’ll create the appropriate cross-realm principals on the Unix KDC:
unixkdc1# /krb5/sbin/kadmin Authenticating as principal jgarman/admin@UNIX.SAMPLE.COM with password. Enter password: kadmin: addprinc -e des:normal krbtgt/SAMPLE.COM@UNIX.SAMPLE.COM WARNING: no policy specified for krbtgt/SAMPLE.COM@UNIX.SAMPLE.COM; defaulting to no policy Enter password for principal "krbtgt/SAMPLE.COM@UNIX.SAMPLE.COM": Re-enter password for principal "krbtgt/SAMPLE.COM@UNIX.SAMPLE.COM": Principal "krbtgt/SAMPLE.COM@UNIX.SAMPLE.COM" created. kadmin: addprinc -e des:normal krbtgt/UNIX.SAMPLE.COM@SAMPLE.COM WARNING: no policy specified for krbtgt/UNIX.SAMPLE.COM@SAMPLE.COM; defaulting to no policy Enter password for principal "krbtgt/UNIX.SAMPLE.COM@SAMPLE.COM": Re-enter password for principal "krbtgt/UNIX.SAMPLE.COM@SAMPLE.COM": Principal "krbtgt/UNIX.SAMPLE.COM@SAMPLE.COM" created.
Remember the passwords given here; we’ll be entering them in on the Windows side next. After logging in under a Domain Administrator account ...
Read now
Unlock full access