<ahref="https://en.wikipedia.org/wiki/Kerberos_(protocol)"class="urlextern"title="https://en.wikipedia.org/wiki/Kerberos_(protocol)"rel="nofollow">Kerberos</a> is a network authentication protocol used to authenticate users based on their desktop session.
In Manager, go in <code>General Parameters</code>><code>Authentication modules</code> and choose Kerberos for authentication. Then go to “Kerberos parameters” and configure the following parameters:
</p>
<ul>
<liclass="level1"><divclass="li"><strong>keytab file</strong> (required): the Kerberos keytab file</div>
<liclass="level1"><divclass="li"><strong>Use Ajax request</strong>: set to “enabled” if you want to use an Ajax request instead of a direct Kerberos attempt. <strong>This is required if you want to chain Kerberos in a <ahref="authcombination.html"class="wikilink1"title="documentation:2.0:authcombination">combination</a></strong></div>
<liclass="level1"><divclass="li"><strong>Use Web Server Kerberos module</strong>: set to “enabled” to use the Web Server module (for example Apache mod_auth_kerb) instead of Perl Kerberos code to validate Kerberos ticket</div>
</li>
<liclass="level1"><divclass="li"><strong>Remove domain in username</strong>: set to “enabled” to strip username value and remove the '@domain'.</div>
<liclass="level1"><divclass="li"> Due to a perl GSSAPI issue, you may need to copy the keytab in /etc/krb5.keytab which is the default location hardcoded in the library</div>
<liclass="level1"><divclass="li"> As Kerberos ticket is passed inside Authorization header, you may need to set CGIPassAuth on in Apache <em>(with old Apache, use <code>RewriteCond %{HTTP:Authorization}</code> followed by <code>RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]</code>)</em></div>
The Kerberos configuration is quite complex. You can find some configuration tips <ahref="kerberos.html"class="wikilink1"title="documentation:2.0:kerberos">on this page</a>.
<h3class="sectionedit6"id="web_server_kerberos_module">Web Server Kerberos module</h3>
<divclass="level3">
<p>
If you want to let Web Server Kerberos module validates the Kerberos ticket, set the according option to “enabled” and configure the portal virtual host to launch the module if “kerberos” GET parameter is in the request.