> -----Original Message-----
> From: owner-u2-us...@listserver.u2ug.org 
> [mailto:owner-u2-us...@listserver.u2ug.org] On Behalf Of Norman Bauer
> Sent: Tuesday, January 27, 2009 4:25 PM
> To: u2-users@listserver.u2ug.org
> Subject: [U2] UV, Linux, and Active Directory
> 

[snip]

> How are you authenticating against AD on Linux?

Oops, forgot about kerberos in my previous reply.  You'll also need to
modify /etc/krb5.conf:

[logging]
 default = FILE:/var/log/krb5libs.log
 kdc = FILE:/var/log/krb5kdc.log
 admin_server = FILE:/var/log/kadmind.log

[libdefaults]
 default_realm =        OURDOMAIN.COM
 dns_lookup_realm = false
 dns_lookup_kdc = false
 ticket_lifetime = 24h
 forwardable = yes

[realms]
 OURDOMAIN.COM = {
  kdc = 111.222.33.44:88
  kdc = 111.222.33.55:88
  kdc = 111.222.33.66:88
  admin_server = pdc.ourdomain.com:749
  default_domain = ourdomain.com
 }

[domain_realm]
 .ourdomain.com = OURDOMAIN.COM
 ourdomain.com = OURDOMAIN.COM

[appdefaults]
 pam = {
   debug = false
   ticket_lifetime = 36000
   renew_lifetime = 36000
   forwardable = true
   krb4_convert = false
 }

-John
-------
u2-users mailing list
u2-users@listserver.u2ug.org
To unsubscribe please visit http://listserver.u2ug.org/

Reply via email to