*BSD News Article 62033


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!harbinger.cc.monash.edu.au!nntp.coast.net!howland.reston.ans.net!newsfeed.internetmci.com!vixen.cso.uiuc.edu!newsrelay.iastate.edu!news.iastate.edu!te135-1
From: shad@iastate.edu (Marcus I. Ryan)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: Allowing login only if Kerberos authenticates
Date: Tue, 13 Feb 96 23:56:04 GMT
Organization: Iowa State University
Lines: 24
Message-ID: <4fr8en$lle@news.iastate.edu>
NNTP-Posting-Host: te135-1.cce.iastate.edu
Summary: how to make login kerberos dependant
Keywords: kerberos login
X-Newsreader: News Xpress Version 1.0 Beta #4

I have recently upgraded my FreeBSD WWW Server.  The Computer Committee that 
controls that WWW server now wants me to give out user accounts.  I would like 
to use the existing Kerberos system here at ISU (Project Vincent - based on 
Project Athena) to do login authentication.  It appears that login does 
realize Kerberos is running, and does try to get Kerberos tickets.  If I get 
my tickets it says nothing.  If I don't, it tells me it couldn't get my 
tickets, and finishes logging me in.  I want it to kick me out if it can't 
authenticate me through Kerberos.  Is there something already set up for this 
that I'm not seeing, or will it require editing the source code for the login 
program?

Thanks.

P.S. Does anyone know of an AFS port for FreeBSD or where I might find the 
source code?


---------------------------------------------------------------
Marcus I. Ryan          |*The joy of engineering is finding a
Asst. SysAdmin, CCE Labs| straight line on a double-logarithmic
Iowa State University   | scale
shad@iastate.edu        |--------------------------------------
(515) 294-0715          | http://www.public.iastate.edu/~shad
---------------------------------------------------------------