3 ms·
All of our linux/freebsd boxes on our network at work must be hooked up to kerberos. most of the day I don't have to type my password for anything HTTP/SSH unle
by feld 9y ago
All of our linux/freebsd boxes on our network at work must be hooked up to kerberos. most of the day I don't have to type my password for anything HTTP/SSH unless it's for sudo.
- vog 9y agoInteresting! Why did your company choose Kerberos over, say, SSL/SMIME certificates? (Honest question, because I had the impression that typically, companies base their PKI on SMIME certificates, because it is easier to setup than an OpenPGP based PKI, and because these certs are supported by most email clients out of the box, in addition to HTTPS and SSH.)
- lstamour 9y agoCan't say either way, but after spending a few minutes Googling S/MIME support, it seems completely incompatible with most web browsers and web email services. The only exception appears to be Office 365 with Internet Explorer on Windows? While end-to-end encryption of emails is nice, I'm not sure the benefits outweigh the drawbacks, unless required by regulation. It'd be nice if more webmail providers and browser makers supported S/MIME, especially considering new privacy rules in the EU...
- gerdesj 9y agoI'm only chiming in here because we do the same. We have an AD! Bizarrely it is actually rather easy to use despite the nightmare of rubbish docs on t'internets. We use winbindd (SSSD is another well respected option - must try it) and the algorithmic idmap backend which guarantees the same uid/gid on all Linux boxes. winbindd also sorts out Kerberos keytabs for the machine itself ("join the domain") and logged in used via winbind's NSS and PAM add ons. Finally, winbind can cache logins for offline logins which is nice for say this laptop that I am using right now. All browsers that I use (IE, Chrom{e|ium}, Firefox) support GSSAPI. Apache, IIS, nginx support GSSAPI. OpenSSH and PuTTY support GSSAPI. There is a lot of support for it out there. Oh and of course Squid for all your proxy needs and HAProxy works as expected (I use it to front Exchange to get PCI DSS compliance even for Exchange 2010 - but that is more a TLS thing). Evolution EWS works through that lot using Kerberos for auth for the full Exchange client experience, including calendaring, without needing Outlook. Kerb is for auth whereas SSL is for encryption. I think you may be confusing use cases a bit. To be fair all that stuff can be a bit confusing and there is a lot of overlap. SSL can be used for identity proof (often proof by assertion) and so can Kerberos (proof by faith in the rest of your realm)
- TheDauthi 9y agoSSSD has been really, REALLY good to my group... except during initial setup. The logging failed me several times in trying to track down problems. The biggest one was when one of the our sysadmins had mistyped "default". Everything appeared to be connecting, getting data from LDAP... and then SSSD would crash with an empty log file. It worked fine on all of our other machines with the incorrect spelling. The versions of Debian and SSSD were the same. I assume some library was different, but I never found it. I eventually noticed the typo, fixed it, and everything started working. That was a couple of years ago. After those initial debugging hurdles, it has "just worked" through upgrades and major software changes. I'm probably jinxing it by praising it. I'm now expecting SSH to stop working on every machine.
- jabl 9y agoTrust me, setting up sssd with debug logging etc. is like the second coming of Jebus compared to ye olde school way of doing it with pam_krb5 + nss_ldap..
- e12e 9y agoHow do you integrate kerberos sso and http? Is there web browser support? The last time I looked at this, I could get sso to work with apache on the server side and windows (internet explorer) clients - but for anything else I don't think I got ticket forwarding etc to work? (Granted this is a long while back). I'd love to hear a few keywords about your stack (heimdal/mit, web server(s), directory server(s) etc)?
- gerdesj 9y agoHave a look at the Arch and Gentoo wikis both have a lot of notes. I wrote this: https://wiki.gentoo.org/wiki/Kerberos_Windows_Interoperability https://wiki.gentoo.org/wiki/Kerberos_Windows_Interoperabili... It is a little out of date (I keep the latest set of notes on our corp wiki) but will get you most of the way there. The notes on the Arch wiki also have some quite up to date notes on using pam_mount and getting mount.cifs working with Kerberos (ie I've read the docs and experimented, so you don't have to) winbindd in Samba 4.x is really rather good and will happily manage the Kerberos side of things for you for a minimal setup cost. If you find yourself following a howto that starts whittering on about using setspn.exe on a DC then run away! I recently noticed that SSSD is available on rather a lot of Linux distros and is well respected. Must have a look. As I mentioned in another thread there is a lot of support for SSO with Kerberos/GSSAPI in nearly everything you can get your paws on. Even Nagstamon can do it! Chrome on Windows - Group Policy, Chrome or Chromium on Linux - policies in a JSON file in a certain location, Firefox - about:config - you can send out FF settings with a file (can't remember the name), IE - Group Policy. PuTTY for ssh. OpenSSH client and server. Squid. Apache, nginx, IIS all do it. I login to this laptop using my AD username and password. If the wifi is a bit slow and winbindd can't get to the domain then it uses a cached (cryptographically hashed) version of my password to allow me in or not. When it finds the DC (VPN or LAN) then it is able to fix up my Kerberos ticket cache on my behalf. I know for a fact (by direct experience) that this all works on Gentoo, Arch and Ubuntu (Xenial and Trusty). Any Unix-alike distro that can run mitkrb or heimdal and Samba 4 should be able to do all of this.
- noinsight 9y ago> winbindd ... I recently noticed that SSSD is available on rather a lot of Linux distros and is well respected. Must have a look. Yeah definitely ditch winbindd and use SSSD. SSSD makes doing this really easy and works really well.