Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support access to Kerberos KDC over UNIX domain socket #7723

Open
abbra opened this issue Nov 27, 2024 · 0 comments
Open

Support access to Kerberos KDC over UNIX domain socket #7723

abbra opened this issue Nov 27, 2024 · 0 comments

Comments

@abbra
Copy link
Contributor

abbra commented Nov 27, 2024

MIT Kerberos PR krb5/krb5#1359 adds support to run KDC locally and only accessible over a UNIX domain socket. SSSD krb5 auth provider cannot currently accept UNIX domain socket path as an address of KDC.

You can use COPR asn/localkdc to test SSSD changes against. This COPR repository provides custom MIT Kerberos build (as well as Samba build to support IAKERB to work with local KDCs but this is unrelated to UNIX domain socket support) and localkdc package that allows easy setup of the local KDC. The latter currently requires SELinux permissive mode (just a warning, as we are working on the policy extensions).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant