Patches for Kerberos with Active Directory

Parsons, Aron parsonsa at bit-sys.com
Mon Jan 7 21:40:37 UTC 2013


Active Directory uses non-standard Kerberos principal names (e.g., HOSTNAME$) instead of the more common host/hostname at REALM.  SPN queries fail (e.g., "Server not found in Kerberos database") when you don't use the HOSTNAME$ version, even when the proper service principals are added to the system.

These two patches allow Koji to be configured to play nicely in an Active Directory environment when using Kerberos.

/aron
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-add-a-fallback-to-an-unformatted-version-of-host_pri.patch
Type: application/octet-stream
Size: 1164 bytes
Desc: 0001-add-a-fallback-to-an-unformatted-version-of-host_pri.patch
URL: <http://lists.fedoraproject.org/pipermail/buildsys/attachments/20130107/69cbbb23/attachment.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0002-allow-the-hub-server-principal-to-be-defined.patch
Type: application/octet-stream
Size: 2988 bytes
Desc: 0002-allow-the-hub-server-principal-to-be-defined.patch
URL: <http://lists.fedoraproject.org/pipermail/buildsys/attachments/20130107/69cbbb23/attachment-0001.obj>


More information about the buildsys mailing list