[22252] in Kerberos
UI for Kerberos accounts administration
daemon@ATHENA.MIT.EDU (Lukas Kubin)
Fri Aug 20 09:06:05 2004
Message-ID: <4125F684.7050807@opf.slu.cz>
Date: Fri, 20 Aug 2004 15:03:00 +0200
From: Lukas Kubin <kubin@opf.slu.cz>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
I'm planning to build an web interface for administering our
Kerberos/OpenAFS/LDAP accounts.
How should I pass credentials to the web service? I can use the
mod_auth_kerb module for Apache. Then some wrapper script will call
kadmin command. When I want kadmin not to ask for password everytime it
is called, I'll have to create an administrator's keytab stored on the
webserver. That way appear not to be secure.
What solution do people use for authorizing various UI clients for
access to Kerberos database?
Is there some freely available tool for administering K5 (possibly with
LDAP and OpenAFS support) accounts?
Thank you.
lukas
--
Lukas Kubin
phone: +420596398275
email: kubin@opf.slu.cz
Information centre
The School of Business Administration in Karvina
Silesian University in Opava
Czech Republic
http://www.opf.slu.cz
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos