特殊:Badtitle/NS100:Samba/Kerberos:修订间差异
小无编辑摘要 |
小无编辑摘要 |
||
(未显示同一用户的3个中间版本) | |||
第8行: | 第8行: | ||
* '''libpam-krb5:''' PAM module for MIT Kerberos. | * '''libpam-krb5:''' PAM module for MIT Kerberos. | ||
* '''krb5-config:''' Configuration files for Kerberos Version 5. | * '''krb5-config:''' Configuration files for Kerberos Version 5. | ||
* '''libkadm55:''' MIT Kerberos administration runtime libraries. | * '''libkadm55:''' MIT Kerberos administration runtime libraries. (No longer available in Karmic) | ||
All these packages are available from the Main repository. See [[UbuntuHelp:InstallingSoftware|InstallingSoftware]] for details on using repositories and package managers. | All these packages are available from the Main repository. See [[UbuntuHelp:InstallingSoftware|InstallingSoftware]] for details on using repositories and package managers. | ||
https://help.ubuntu.com/community/IconsPage?action=AttachFile&do=get&target=IconNote.png If you do not intend to acquire a Kerberos ticket at login, you need not install the libpam-krb5 package. | https://help.ubuntu.com/community/IconsPage?action=AttachFile&do=get&target=IconNote.png If you do not intend to acquire a Kerberos ticket at login, you need not install the libpam-krb5 package. | ||
== Configuration == | == Configuration == | ||
The following examples use '''example.com''' as the Active Directory Domain, and '''win2k3.example.com''' as the name of the Domain Controller. Change ''example.com'' and ''win2k3.example.com'' to reflect your AD Domain name and Domain Controller. | The following examples use '''example.com''' as the Active Directory Domain, and '''win2k3.example.com''' as the name of the Domain Controller. Change ''example.com'' and ''win2k3.example.com'' to reflect your AD Domain name and Domain Controller. | ||
NOTE: This appears to work to the point of passing the login test and ticket-retrieval described below with '''Windows 2008 Server with AD running in Native Mode'''. | |||
=== Pre-Kerberos Configuration === | === Pre-Kerberos Configuration === | ||
==== Confirm Connectivity ==== | ==== Confirm Connectivity ==== | ||
第23行: | 第24行: | ||
</nowiki></pre> | </nowiki></pre> | ||
The output of the ping response shows successful resolution of the FQDN to an IP Address, and the confirmation of connectivity between your Ubuntu workstation and the AD DC. | The output of the ping response shows successful resolution of the FQDN to an IP Address, and the confirmation of connectivity between your Ubuntu workstation and the AD DC. | ||
Connectivity failures when pinging the FQDN usually point to DNS server or client configuration errors. Make sure that your <code><nowiki>/etc/resolv.conf</nowiki></code> contains a pointer to your DNS server. See the [https://help.ubuntu.com/ | Connectivity failures when pinging the FQDN usually point to DNS server or client configuration errors. Make sure that your <code><nowiki>/etc/resolv.conf</nowiki></code> contains a pointer to your DNS server. See the [https://help.ubuntu.com/8.04/serverguide/C/network-configuration.html Network Configuration] for information on getting all your network settings correct. | ||
==== Time settings ==== | ==== Time settings ==== | ||
Time is essential for Kerberos, which is used for authentication in Active Directory networks. The easiest way to ensure correct time synchronization is to use a NTP Server. Every Active Directory Domain Controller is also an NTP server, so for best results, use the FQDN of an AD DC in Ubuntu's default '''ntpdate''' application, which syncs time at startup or on demand. | Time is essential for Kerberos, which is used for authentication in Active Directory networks. The easiest way to ensure correct time synchronization is to use a NTP Server. Every Active Directory Domain Controller is also an NTP server, so for best results, use the FQDN of an AD DC in Ubuntu's default '''ntpdate''' application, which syncs time at startup or on demand. | ||
NB: On Ubuntu 8.04 Desktop Edition, it appears that the time server program is '''ntp''' and may be installed using '''apt-get install ntp'''. The configuration file may be edited as described below. | |||
For Kubuntu 7.10 (and likely other versions as well) '''ntpdate''' does not pull the server name from any config files, instead it expects the NTP server as an argument on the command line. Therefore it is simplest to work with the options of adjust date and time of the GUI clock. Choose set date and time automatically, and then enter your AD DC as the NTP server. If it is reading from the config files then set things up in <code><nowiki>/etc/default/ntpdate</nowiki></code> as below. | For Kubuntu 7.10 (and likely other versions as well) '''ntpdate''' does not pull the server name from any config files, instead it expects the NTP server as an argument on the command line. Therefore it is simplest to work with the options of adjust date and time of the GUI clock. Choose set date and time automatically, and then enter your AD DC as the NTP server. If it is reading from the config files then set things up in <code><nowiki>/etc/default/ntpdate</nowiki></code> as below. | ||
file: <code><nowiki>/etc/default/ntpdate</nowiki></code> | file: <code><nowiki>/etc/default/ntpdate</nowiki></code> | ||
第36行: | 第38行: | ||
<pre><nowiki> | <pre><nowiki> | ||
sudo /etc/init.d/ntpdate restart | sudo /etc/init.d/ntpdate restart | ||
(May be "sudo /etc/init.d/ntp restart") | |||
* Synchronizing clock to win2k3.example.com... [ ok ] | * Synchronizing clock to win2k3.example.com... [ ok ] | ||
第98行: | 第101行: | ||
</nowiki></pre> | </nowiki></pre> | ||
At this point, your Kerberos installation and configuration is operating correctly. You can release your test ticket by issuing the '''kdestroy''' command. | At this point, your Kerberos installation and configuration is operating correctly. You can release your test ticket by issuing the '''kdestroy''' command. | ||
'''Note:''' this guide has been tested on Ubuntu 8.04 (Hardy Heron). | '''Note:''' this guide has been tested on Ubuntu 8.04 (Hardy Heron) and Ubuntu 9.10 (Karmic) | ||
---- | ---- | ||
[[category:UbuntuHelp]] | [[category:UbuntuHelp]] |
2010年5月20日 (四) 00:07的最新版本
文章出处: |
{{#if: | {{{2}}} | https://help.ubuntu.com/community/Samba/Kerberos }} |
点击翻译: |
English {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/af | • {{#if: UbuntuHelp:Samba/Kerberos|Afrikaans| [[::Samba/Kerberos/af|Afrikaans]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ar | • {{#if: UbuntuHelp:Samba/Kerberos|العربية| [[::Samba/Kerberos/ar|العربية]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/az | • {{#if: UbuntuHelp:Samba/Kerberos|azərbaycanca| [[::Samba/Kerberos/az|azərbaycanca]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/bcc | • {{#if: UbuntuHelp:Samba/Kerberos|جهلسری بلوچی| [[::Samba/Kerberos/bcc|جهلسری بلوچی]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/bg | • {{#if: UbuntuHelp:Samba/Kerberos|български| [[::Samba/Kerberos/bg|български]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/br | • {{#if: UbuntuHelp:Samba/Kerberos|brezhoneg| [[::Samba/Kerberos/br|brezhoneg]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ca | • {{#if: UbuntuHelp:Samba/Kerberos|català| [[::Samba/Kerberos/ca|català]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/cs | • {{#if: UbuntuHelp:Samba/Kerberos|čeština| [[::Samba/Kerberos/cs|čeština]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/de | • {{#if: UbuntuHelp:Samba/Kerberos|Deutsch| [[::Samba/Kerberos/de|Deutsch]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/el | • {{#if: UbuntuHelp:Samba/Kerberos|Ελληνικά| [[::Samba/Kerberos/el|Ελληνικά]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/es | • {{#if: UbuntuHelp:Samba/Kerberos|español| [[::Samba/Kerberos/es|español]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/fa | • {{#if: UbuntuHelp:Samba/Kerberos|فارسی| [[::Samba/Kerberos/fa|فارسی]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/fi | • {{#if: UbuntuHelp:Samba/Kerberos|suomi| [[::Samba/Kerberos/fi|suomi]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/fr | • {{#if: UbuntuHelp:Samba/Kerberos|français| [[::Samba/Kerberos/fr|français]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/gu | • {{#if: UbuntuHelp:Samba/Kerberos|ગુજરાતી| [[::Samba/Kerberos/gu|ગુજરાતી]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/he | • {{#if: UbuntuHelp:Samba/Kerberos|עברית| [[::Samba/Kerberos/he|עברית]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/hu | • {{#if: UbuntuHelp:Samba/Kerberos|magyar| [[::Samba/Kerberos/hu|magyar]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/id | • {{#if: UbuntuHelp:Samba/Kerberos|Bahasa Indonesia| [[::Samba/Kerberos/id|Bahasa Indonesia]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/it | • {{#if: UbuntuHelp:Samba/Kerberos|italiano| [[::Samba/Kerberos/it|italiano]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ja | • {{#if: UbuntuHelp:Samba/Kerberos|日本語| [[::Samba/Kerberos/ja|日本語]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ko | • {{#if: UbuntuHelp:Samba/Kerberos|한국어| [[::Samba/Kerberos/ko|한국어]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ksh | • {{#if: UbuntuHelp:Samba/Kerberos|Ripoarisch| [[::Samba/Kerberos/ksh|Ripoarisch]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/mr | • {{#if: UbuntuHelp:Samba/Kerberos|मराठी| [[::Samba/Kerberos/mr|मराठी]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ms | • {{#if: UbuntuHelp:Samba/Kerberos|Bahasa Melayu| [[::Samba/Kerberos/ms|Bahasa Melayu]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/nl | • {{#if: UbuntuHelp:Samba/Kerberos|Nederlands| [[::Samba/Kerberos/nl|Nederlands]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/no | • {{#if: UbuntuHelp:Samba/Kerberos|norsk| [[::Samba/Kerberos/no|norsk]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/oc | • {{#if: UbuntuHelp:Samba/Kerberos|occitan| [[::Samba/Kerberos/oc|occitan]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/pl | • {{#if: UbuntuHelp:Samba/Kerberos|polski| [[::Samba/Kerberos/pl|polski]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/pt | • {{#if: UbuntuHelp:Samba/Kerberos|português| [[::Samba/Kerberos/pt|português]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ro | • {{#if: UbuntuHelp:Samba/Kerberos|română| [[::Samba/Kerberos/ro|română]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/ru | • {{#if: UbuntuHelp:Samba/Kerberos|русский| [[::Samba/Kerberos/ru|русский]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/si | • {{#if: UbuntuHelp:Samba/Kerberos|සිංහල| [[::Samba/Kerberos/si|සිංහල]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/sq | • {{#if: UbuntuHelp:Samba/Kerberos|shqip| [[::Samba/Kerberos/sq|shqip]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/sr | • {{#if: UbuntuHelp:Samba/Kerberos|српски / srpski| [[::Samba/Kerberos/sr|српски / srpski]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/sv | • {{#if: UbuntuHelp:Samba/Kerberos|svenska| [[::Samba/Kerberos/sv|svenska]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/th | • {{#if: UbuntuHelp:Samba/Kerberos|ไทย| [[::Samba/Kerberos/th|ไทย]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/tr | • {{#if: UbuntuHelp:Samba/Kerberos|Türkçe| [[::Samba/Kerberos/tr|Türkçe]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/vi | • {{#if: UbuntuHelp:Samba/Kerberos|Tiếng Việt| [[::Samba/Kerberos/vi|Tiếng Việt]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/yue | • {{#if: UbuntuHelp:Samba/Kerberos|粵語| [[::Samba/Kerberos/yue|粵語]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/zh | • {{#if: UbuntuHelp:Samba/Kerberos|中文| [[::Samba/Kerberos/zh|中文]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/zh-hans | • {{#if: UbuntuHelp:Samba/Kerberos|中文(简体)| [[::Samba/Kerberos/zh-hans|中文(简体)]]}}|}} {{#ifexist: {{#if: UbuntuHelp:Samba/Kerberos | UbuntuHelp:Samba/Kerberos | {{#if: | :}}Samba/Kerberos}}/zh-hant | • {{#if: UbuntuHelp:Samba/Kerberos|中文(繁體)| [[::Samba/Kerberos/zh-hant|中文(繁體)]]}}|}} |
{{#ifeq:UbuntuHelp:Samba/Kerberos|:Samba/Kerberos|请不要直接编辑翻译本页,本页将定期与来源同步。}} |
{{#ifexist: :Samba/Kerberos/zh | | {{#ifexist: Samba/Kerberos/zh | | {{#ifeq: {{#titleparts:Samba/Kerberos|1|-1|}} | zh | | }} }} }} {{#ifeq: {{#titleparts:Samba/Kerberos|1|-1|}} | zh | | }}
Introduction
Kerberos is an authentication protocol using secret-key cryptography. There are several implementations of the Kerberos protocol used in both commercial and Open Source software. This guide will cover setting up Kerberos on a Ubuntu system with the intent of joining an Active Directory Domain.
Installation
There are several packages that provide Kerberos services and utilities:
- krb5-user: Basic programs to authenticate using MIT Kerberos.
- libpam-krb5: PAM module for MIT Kerberos.
- krb5-config: Configuration files for Kerberos Version 5.
- libkadm55: MIT Kerberos administration runtime libraries. (No longer available in Karmic)
All these packages are available from the Main repository. See InstallingSoftware for details on using repositories and package managers. If you do not intend to acquire a Kerberos ticket at login, you need not install the libpam-krb5 package.
Configuration
The following examples use example.com as the Active Directory Domain, and win2k3.example.com as the name of the Domain Controller. Change example.com and win2k3.example.com to reflect your AD Domain name and Domain Controller. NOTE: This appears to work to the point of passing the login test and ticket-retrieval described below with Windows 2008 Server with AD running in Native Mode.
Pre-Kerberos Configuration
Confirm Connectivity
The first step to configuring an Ubuntu client for participation in an Active Directory (AD) network is to confirm network connectivity and name resolution for the Active Directory domain controller. An easy way to verify both of these is to ping the Fully Qualified Domain Name (FQDN) of the AD DC on your network.
ping win2k3.example.com PING win2k3.example.com (10.0.0.1) 56(84) bytes of data. 64 bytes from win2k3.lab.example.com (10.0.0.1): icmp_seq=1 ttl=128 time=0.176ms
The output of the ping response shows successful resolution of the FQDN to an IP Address, and the confirmation of connectivity between your Ubuntu workstation and the AD DC.
Connectivity failures when pinging the FQDN usually point to DNS server or client configuration errors. Make sure that your /etc/resolv.conf
contains a pointer to your DNS server. See the Network Configuration for information on getting all your network settings correct.
Time settings
Time is essential for Kerberos, which is used for authentication in Active Directory networks. The easiest way to ensure correct time synchronization is to use a NTP Server. Every Active Directory Domain Controller is also an NTP server, so for best results, use the FQDN of an AD DC in Ubuntu's default ntpdate application, which syncs time at startup or on demand.
NB: On Ubuntu 8.04 Desktop Edition, it appears that the time server program is ntp and may be installed using apt-get install ntp. The configuration file may be edited as described below.
For Kubuntu 7.10 (and likely other versions as well) ntpdate does not pull the server name from any config files, instead it expects the NTP server as an argument on the command line. Therefore it is simplest to work with the options of adjust date and time of the GUI clock. Choose set date and time automatically, and then enter your AD DC as the NTP server. If it is reading from the config files then set things up in /etc/default/ntpdate
as below.
file: /etc/default/ntpdate
# servers to check NTPSERVERS="win2k3.example.com" # additional options for ntpdate NTPOPTIONS="-u"
sudo /etc/init.d/ntpdate restart (May be "sudo /etc/init.d/ntp restart") * Synchronizing clock to win2k3.example.com... [ ok ]
FQDN
A valid FQDN is essential for Kerberos and Active Directory. Active Directory is heavily dependent upon DNS, and it is likely that your Active Directory Domain Controllers are also running the Microsoft DNS server package. Here, we will edit the local hosts file on your Ubuntu workstation to make sure that your FQDN is resolvable.
file: /etc/hosts
127.0.0.1 linuxwork.example.com localhost linuxwork
You can test your configurating by PINGING your own FQDN. The output should be similar to the PING output above, from the Network Connectivity test (of course, the FQDN will be your own, and the IP address will be 127.0.0.1).
krb5-config
If you choose to install the krb5-config package, the installation will present a prompt:
What are the Kerberos servers for your realm? win2k3.example.com What is the administrative server for your Kerberos realm? win2k3.example.com
These prompts should be answered according to the Active Directory Domain Controller in charge of your domain. The krb5-config process customizes the /etc/krb5.conf
file for your installation.
/etc/krb5.conf
Another way to configure Kerberos is to simply edit the /etc/krb5.conf
file by hand. This approach allows greater customization of the file, but lacks the automation of the krb5-config package. Both paths take you to the same destination.
[logging] default = FILE:/var/log/krb5.log [libdefaults] default_realm = EXAMPLE.COM kdc_timesync = 1 ccache_type = 4 forwardable = true proxiable = true [realms] EXAMPLE.COM = { kdc = win2k3.example.com admin_server = win2k3.example.com default_domain = EXAMPLE.COM } [domain_realm] .example.com = EXAMPLE.COM example.com = EXAMPLE.COM
Testing
The krb5-user package contains utilities to help test and authenticate to a Kerberos server. Request a Ticket-Granting Ticket (TGT) by issuing the kinit command, as shown (you can use any valid domain account, it doesn't have to be Administrator). Note that the domain name must be in UPPER CASE!!!. You can also omit the domain name (in upper case!) from the command if the "default_realm" directive is properly applied in the /etc/krb5.conf file.
kinit [email protected] Password for [email protected]: ****
Check if ticket request was valid using the klist command.
klist Ticket cache: FILE:/tmp/krb5cc_0 Default principal: [email protected] Valid starting Expires Service principal 01/21/05 10:28:51 01/21/05 20:27:43 krbtgt/[email protected] renew until 01/21/05 20:28:51
At this point, your Kerberos installation and configuration is operating correctly. You can release your test ticket by issuing the kdestroy command. Note: this guide has been tested on Ubuntu 8.04 (Hardy Heron) and Ubuntu 9.10 (Karmic)