[Freeipa-devel] Kerberos implementation issues

Pete Zaitcev zaitcev at redhat.com
Wed Jun 22 18:06:43 UTC 2011


On Wed, 22 Jun 2011 11:13:45 +0200
Sumit Bose <sbose at redhat.com> wrote:

> For a web service you typically do not want to use the host principal
> but create one for the specific service
> HTTP/fully.qualified.domain.name at YOUR.KERBEROS.REALM with ipa
> service-add.
> 
> If you don't have freeIPA but a plain KDC you have to use the kadmin
> utility to create the principals (and their keys).

Understood, thanks a lot.

I have my local FreeIPA instance where I can do that, without filing
a helpdesk ticket.

-- Pete




More information about the Freeipa-devel mailing list