not logged in | [Login]
Always use radiusd -X
when debugging!
The rlm_krb5 FreeRADIUS module enables the use of Kerberos 5.
The rlm_krb5 module, by default, presumes you have the MIT Kerberos 5 distribution. Notes from that distribution:
On linux, you may have to change:
deplibs_test_method="pass_all"
in ../libtool
Otherwise, it complains if the krb5 libs aren't shared.
If you are using the Heimdal Kerberos 5 distribution, pass a --enable-heimdal-krb5 to the configure line. With Heimdal, you'll need to have a radius/your.hostname.example.org key in your keytab (which needs to be readable by the user running the RADIUS server).
You can configure the module with the following parameters:
krb5 {
# principal that is used by rlm_krb5 service_principal = radius/some.host.com }
Make sure the keytab is readable by the user that is used to run radiusd and that your authorization configuration really uses rlm_krb5 to do the authentication. You will need to add the following to the 'authenticate' section of your radiusd.conf file:
Auth-Type Kerberos { krb5 }
Last edited by Alan T. DeKok, 2011-07-13 22:15:12
Sponsored by Network RADIUS