[37160] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kinit: Mapping a local username to a Kerberos principal?

daemon@ATHENA.MIT.EDU (Lars Kellogg-Stedman)
Fri Jul 17 16:26:07 2015

To: kerberos@mit.edu
From: Lars Kellogg-Stedman <lars@oddbit.com>
Date: Fri, 17 Jul 2015 20:02:51 +0000 (UTC)
Message-ID: <loom.20150717T220108-339@post.gmane.org>
Mime-Version: 1.0
X-Complaints-To: usenet@ger.gmane.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Greg Hudson <ghudson <at> mit.edu> writes:


> At least some versions of pam_krb5 have some mapping options.  See the
> alt_auth_map and search_k5login options here:

In fact, it turns out that SSSD has exactly the behavior for which I was
looking.  I wrote up my solution here:

 
http://blog.oddbit.com/2015/07/16/mapping-local-users-to-kerberos-principals-with-sssd/

Cheers,

-- Lars


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post