kerberos - KDC probléma
Sziasztok!
LDAP + Samba paroshoz, mint hitelesito rendszert a kerberost hasznalnam. A gondom az hogy nem tud konnektalni a KDC vel. Valoszinua config hibas, de mint lehetseges ok az is lehetseges hogy mivel kulso tuzfal fogja a 88 es 749 es portokat illetve ha jol tudom a 636 port is szukseges az LDAP hoz illetve a kerberos hitelesiteshez, talan ez is okozhatja a problemat. (Lehet e csak a belso halozatra beallitani a hitelesitest?)
mmcntr:/# kinit -t 5
kinit(v5): Cannot contact any KDC for requested realm while getting initial credentials
mmcntr:/#
mmcntr:/# kinit -v
kinit(v5): No credentials cache found while validating credentials
mmcntr:/#
Itt van meg a conf:
mmcntr:/# cat /etc/krb5.conf
[libdefaults]
default_realm = XXXX.XXXX.XX
default_tkt_enctypes = des-cbc-md5
default_tgs_enctypes = des-cbc-md5
dns_lookup_realm = true
dns_lookup_kdc = true
# The following krb5.conf variables are only for MIT Kerberos.
krb4_config = /etc/krb.conf
krb4_realms = /etc/krb.realms
kdc_timesync = 1
ccache_type = 4
forwardable = true
proxiable = true
# The following encryption type specification will be used by MIT Kerberos
# if uncommented. In general, the defaults in the MIT Kerberos code are
# correct and overriding these specifications only serves to disable new
# encryption types as they are added, creating interoperability problems.
# default_tgs_enctypes = aes256-cts arcfour-hmac-md5 des3-hmac-sha1 des-cbc-crc des-cbc-md5
# default_tkt_enctypes = aes256-cts arcfour-hmac-md5 des3-hmac-sha1 des-cbc-crc des-cbc-md5
# permitted_enctypes = aes256-cts arcfour-hmac-md5 des3-hmac-sha1 des-cbc-crc des-cbc-md5
# The following libdefaults parameters are only for Heimdal Kerberos.
v4_instance_resolve = false
v4_name_convert = {
host = {
rcmd = host
ftp = ftp
}
plain = {
something = something-else
}
}
fcc-mit-ticketflags = true
[realms]
XXXX.XXXX.XX = {
kdc = mmcntr
admin_server = mmcntr
default_domain = xxxx.xxxx.xx
}
[domain_realm]
.xxxx.xx = xxxxx.xxxx.xx
xxxx.xx = xxxx.xxxx.xx
[kdc]
profile = /var/kerberos/krb5kdc/kdc.conf
[appdefaults]
pam = {
debug = true
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
[logging]
default = FILE:/var/log/krb5def.log
kinit = FILE:/var/log/krb5ini.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/krb5adm.log
[login]
krb4_convert = true
krb4_get_tickets = false
mmcntr:/#
Felraktam a krb5-user, krb5-admin-server, krb5-config csomagokat is. Meg mit kellene feltennem illetve mi lehet meg a gond?
A valaszokat elore is koszonom.
- Tovább (kerberos - KDC probléma)
- 3373 megtekintés