4 ms·
FreeBSD, OpenSSH, Apache mod_kerb2 (and mod_auth_ldap for authorization), Active Directory. 1. install server 2. msktutil tool joins machine to domain (simple
by feld 9y ago
FreeBSD, OpenSSH, Apache mod_kerb2 (and mod_auth_ldap for authorization), Active Directory.
1. install server
2. msktutil tool joins machine to domain (simple tool; no dependencies) and now you have /etc/krb5.keytab file
3. minor configuration for base OS -- LDAP using keytab instead of bind user with static password, etc
4. webservers just need an HTTP principal keytab created (simple msktutil command, then extract it from the /etc/krb5.keytab file into a file apache can read/write)
5. I can ssh to every server without a password after running "kinit" on my macbook
6. it just works and it's reliable, time tested, and secure.