[37160] in Kerberos
Re: kinit: Mapping a local username to a Kerberos principal?
daemon@ATHENA.MIT.EDU (Lars Kellogg-Stedman)
Fri Jul 17 16:26:07 2015
To: kerberos@mit.edu
From: Lars Kellogg-Stedman <lars@oddbit.com>
Date: Fri, 17 Jul 2015 20:02:51 +0000 (UTC)
Message-ID: <loom.20150717T220108-339@post.gmane.org>
Mime-Version: 1.0
X-Complaints-To: usenet@ger.gmane.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Greg Hudson <ghudson <at> mit.edu> writes:
> At least some versions of pam_krb5 have some mapping options. See the
> alt_auth_map and search_k5login options here:
In fact, it turns out that SSSD has exactly the behavior for which I was
looking. I wrote up my solution here:
http://blog.oddbit.com/2015/07/16/mapping-local-users-to-kerberos-principals-with-sssd/
Cheers,
-- Lars
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos