Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Kerberos -
- [root@Cent-Pro ~]# cat /var/kerberos/krb5kdc/kdc.conf
- [kdcdefaults]
- kdc_ports = 88
- kdc_tcp_ports = 88
- [realms]
- EXAMPLE.EXAM = {
- master_key_type = aes256-cts
- default_principal_flags = +preauth
- acl_file = /var/kerberos/krb5kdc/kadm5.acl
- dict_file = /usr/share/dict/words
- admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
- supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
- }
- [root@Cent-Pro ~]# cat /var/kerberos/krb5kdc/kadm5.acl
- */admin@EXAMPLE.EXAM *
- root@Cent-Pro ~]# cat /etc/krb5.conf
- # Configuration snippets may be placed in this directory as well
- includedir /etc/krb5.conf.d/
- [logging]
- default = FILE:/var/log/krb5libs.log
- kdc = FILE:/var/log/krb5kdc.log
- admin_server = FILE:/var/log/kadmind.log
- [libdefaults]
- dns_lookup_realm = false
- ticket_lifetime = 24h
- renew_lifetime = 7d
- forwardable = true
- rdns = false
- default_realm = EXAMPLE.EXAM
- default_ccache_name = KEYRING:persistent:%{uid}
- [realms]
- EXAMPLE.COM = {
- kdc = Cent-Pro.example.exam
- admin_server = Cent-Pro.example.exam
- }
- [domain_realm]
- .example.exam = EXAMPLE.EXAM
- example.com = EXAMPLE.EXAM
- -------------------
- [root@CentOS-Server1 ~]# cat /etc/exports
- #/nfsshare CentOS-Client1.example.exam(rw)
- /nfsshare 10.10.100.0/24(rw,no_root_squash)
- /nfs_k_share CentOS-Client1.example.exam(rw,sec=krb5p,sync)
- The server and client machines are already autheticated and nfs directivess are present -
- [root@CentOS-Client1 ~]# klist -k
- Keytab name: FILE:/etc/krb5.keytab
- KVNO Principal
- ---- --------------------------------------------------------------------------
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Client1.example.exam@EXAMPLE.EXAM
- [root@CentOS-Client1 ~]#
- [root@CentOS-Server1 ~]# klist -k
- Keytab name: FILE:/etc/krb5.keytab
- KVNO Principal
- ---- --------------------------------------------------------------------------
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
- 3 nfs/CentOS-Server1.example.exam@EXAMPLE.EXAM
Add Comment
Please, Sign In to add comment