[22252] in Kerberos

home help back first fref pref prev next nref lref last post

UI for Kerberos accounts administration

daemon@ATHENA.MIT.EDU (Lukas Kubin)
Fri Aug 20 09:06:05 2004

Message-ID: <4125F684.7050807@opf.slu.cz>
Date: Fri, 20 Aug 2004 15:03:00 +0200
From: Lukas Kubin <kubin@opf.slu.cz>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

I'm planning to build an web interface for administering our 
Kerberos/OpenAFS/LDAP accounts.
How should I pass credentials to the web service? I can use the 
mod_auth_kerb module for Apache. Then some wrapper script will call 
kadmin command. When I want kadmin not to ask for password everytime it 
is called, I'll have to create an administrator's keytab stored on the 
webserver. That way appear not to be secure.
What solution do people use for authorizing various UI clients for 
access to Kerberos database?
Is there some freely available tool for administering K5 (possibly with 
LDAP and OpenAFS support) accounts?
Thank you.

lukas

-- 
Lukas Kubin

phone: +420596398275
email: kubin@opf.slu.cz

Information centre
The School of Business Administration in Karvina
Silesian University in Opava
Czech Republic
http://www.opf.slu.cz
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post