rlm_krb5
Synopsis
The krb5 module implements support for Kerberos authentication.
Processing Sections
authenticate
When listed in the authenticate section, the krb5 module
authenticates to the Kerberos DC, using the User-Name and
User-Password from the request.
In order to use Kerberos authentication, the administrator must
manually set control:Auth-Type := krb5.
- Return codes
-
failThe module was unable to connect to the Kerberos DC. -
invalidThe request does not contain aUser-Nameor aUser-Passwordattribute. -
rejectThe user’s password is incorrect. -
userlockThe user’s account is locked. -
notfoundThe user’s account was not found. -
okThe user was successfully authenticated.
Expansions
None.
Directives
- Syntax
-
keytab = filename
- Default
-
none
- Description
-
The full path to the Kerberos Keytab file.
- Syntax
-
service_principal = string
- Default
-
none
- Description
-
The name of the service principle. Typically the host name of the Kerberos server.
- Syntax
-
pool { … } - Description
-
A sub-section that manages connections to the Kerberos DC. See the pool documentation for more information.