Authentification kerberos systeme
Aller à la navigation
Aller à la recherche
| Fiche express | |
|---|---|
| Domaine | Authentification centralisée |
| Objectif | Rattacher une machine Linux à un AD Windows |
| Contexte | RHEL 7 — LDAP + Kerberos, realmd / IPA |
| Voir aussi | Kerberos · Wbinfo · Authentification kerberos NFS |
Il est possible de brancher l'authentification Linux sur un annuaire Active Directory (ou un serveur IPA) afin que les utilisateurs du domaine puissent ouvrir une session sur la machine Linux. L'annuaire fournit l'identité (LDAP) et l'authentification (Kerberos).
Authentification via LDAP + Kerberos
yum install sshd authconfig-gtk krb5-workstation
system-config-authentication # onglet Identity & Authentication
Dans l'interface :
- User Account Database = LDAP
- Activer TLS
- Authentication Method = Kerberos password
- Décocher « use DNS »
- Renseigner le REALM (nom de domaine Kerberos, généralement en majuscules)
Rattachement via realmd / IPA
IPA (Identity, Policy and Auditing) et realmd simplifient la jonction au
domaine :
yum install ipa-client-install
yum install realmd
realm discover domain.tld.com
realm join domain.tld.com
realm permit --realm domain.tld.com --all
Autoriser des utilisateurs précis plutôt que tout le domaine :
realm permit --realm domain.tld.com 'DOMAIN\itchy' 'DOMAIN\scratchy'
Utiliser des noms courts au lieu des FQDN
Pour ne plus avoir à saisir le nom complet (user@domain.tld.com) à la connexion,
désactiver l'usage des noms pleinement qualifiés dans la configuration SSSD :
vi /etc/sssd/sssd.conf
# use_fully_qualified_names = False
Voir aussi
- Kerberos — protocole d'authentification et configuration côté Linux
- Wbinfo — interrogation de l'AD via winbind
- Authentification kerberos NFS — exports NFS protégés par Kerberos