From owner-freebsd-questions@freebsd.org Fri Jul 17 10:05:10 2015 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 50D779A214B for ; Fri, 17 Jul 2015 10:05:10 +0000 (UTC) (envelope-from raimund.sacherer@logitravel.com) Received: from formentor.toolfactory.net (pina.toolfactory.net [213.97.158.39]) by mx1.freebsd.org (Postfix) with ESMTP id EC797117F for ; Fri, 17 Jul 2015 10:05:09 +0000 (UTC) (envelope-from raimund.sacherer@logitravel.com) Received: from localhost (localhost.localdomain [127.0.0.1]) by formentor.toolfactory.net (Postfix) with ESMTP id BECCF17819E; Fri, 17 Jul 2015 12:05:00 +0200 (CEST) Received: from formentor.toolfactory.net ([127.0.0.1]) by localhost (formentor.toolfactory.net [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id 3DS3kQL4a8OO; Fri, 17 Jul 2015 12:04:59 +0200 (CEST) Received: from localhost (localhost.localdomain [127.0.0.1]) by formentor.toolfactory.net (Postfix) with ESMTP id D1965178194; Fri, 17 Jul 2015 12:04:59 +0200 (CEST) X-Virus-Scanned: amavisd-new at logpmzimmta01v.toolfactory.net Received: from formentor.toolfactory.net ([127.0.0.1]) by localhost (formentor.toolfactory.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id k-HSRzO6nSZB; Fri, 17 Jul 2015 12:04:59 +0200 (CEST) Received: from xorrigo.toolfactory.net (xorrigo.toolfactory.net [192.168.2.210]) by formentor.toolfactory.net (Postfix) with ESMTP id B876B177FDE; Fri, 17 Jul 2015 12:04:59 +0200 (CEST) Date: Fri, 17 Jul 2015 12:04:58 +0200 (CEST) From: Raimund Sacherer Reply-To: Raimund Sacherer To: Greg Groth Cc: freebsd-questions@freebsd.org Message-ID: <1705342318.38348913.1437127498114.JavaMail.zimbra@logitravel.com> In-Reply-To: <4582000dcfad2dc26ca4076d2024f23f@mail.gregs-garage.com> References: <75d664eeb361264e9b4560a89b1a32bf@mail.gregs-garage.com> <1383995814.37100404.1437030764957.JavaMail.zimbra@logitravel.com> <4582000dcfad2dc26ca4076d2024f23f@mail.gregs-garage.com> Subject: Re: Kerberos MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Originating-IP: [192.168.2.213] X-Mailer: Zimbra 8.0.8_GA_6184 (ZimbraWebClient - SAF7 (Mac)/8.0.8_GA_6184) Thread-Topic: Kerberos Thread-Index: kX0MPBfWxeNDDZV2XZWOcsVSMP9YKQ== X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 17 Jul 2015 10:05:10 -0000 Hello Greg, on a first glance I can't see anything really out of order, if it helps, I use(d) this pages to setup kerberos and apache auth: http://www.grolmsnet.de/kerbtut/ http://blog.scottlowe.org/2006/08/10/kerberos-based-sso-with-apache/ The account you create for the service principal has to be a user account, it does not work with a machine account. If you authenticate without the key tab, just a user from the ad (create a user and test a kinit user@EXAMPLE.COM, later klist). Check if a simple user authentication works in the first place. Hope that this will help you in any way, Best Ray