Revision history for SingleSignOn


Revision [15642]

Last edited on 2015-05-22 11:04:08 by BrianKoontz
Additions:
<<{{color c="red" text="THIS PAGE IS DEPRECATED"}}
Please visit the current page [[SingleSignOn(FreeIPA)|here]].<<::c::
Deletions:
<<{{color c="red" text="DEPRECATED"}} Please visit the current page [[SingleSignOn(FreeIPA)|here]].<<::c::


Revision [15641]

Edited on 2015-05-22 11:03:51 by BrianKoontz
Additions:
<<{{color c="red" text="DEPRECATED"}} Please visit the current page [[SingleSignOn(FreeIPA)|here]].<<::c::
Deletions:
<<{{color c=red text="DEPRECATED"}} Please visit the current page [[SingleSignOn(FreeIPA)|here]].<<::c::


Revision [15640]

Edited on 2015-05-22 11:03:41 by BrianKoontz
Additions:
<<{{color c=red text="DEPRECATED"}} Please visit the current page [[SingleSignOn(FreeIPA)|here]].<<::c::


Revision [7579]

Edited on 2013-01-22 08:49:07 by MikeShultz [Added CommonWorkstationIssues link.]
Additions:
~- [[AdminEmail E-mail Management]]
~- [[CommonWorkstationIssues Common Issues]]>>
Deletions:
~- [[AdminEmail E-mail Management]]>>


Revision [6798]

Edited on 2012-08-30 08:58:15 by LuizLopes [added link to Email Admin.]
Additions:
>>===See Also===
~- [[AdminEmail E-mail Management]]>>


Revision [6744]

Edited on 2012-08-22 16:23:50 by LuizLopes [added link to Email Admin.]
Additions:
kadmin.local -q 'cpw -pw [password] [username]'
Deletions:
kadmin.local -q 'cpw -pw password pedro'


Revision [6236]

Edited on 2012-06-05 11:09:17 by LuizLopes [link to ubuntu's guide.]
Additions:
[[https://help.ubuntu.com/community/SingleSignOn Ubuntu Guide to SingleSignOn]]


Revision [6235]

Edited on 2012-06-05 09:59:43 by LuizLopes [Link to shared address book]
Additions:
Hook LDAP into other services (wiki, mantis).
[[http://www.brennan.id.au/20-Shared_Address_Book_LDAP.html Shared Address Book]]
Deletions:
Hook LDAP into other services (wiki, mantis).


Revision [6216]

Edited on 2012-05-29 10:05:22 by ClAd [Link to shared address book]
Additions:
To make any changes to ldap or kerberos, first get a ticket (either as ldapadmin or as a member in the ldap group tech) if needed:
Deletions:
To make any changes to ldap or kerberos, first get a ticket (either as ldapadmin or as a member in the ldap group tech).


Revision [6215]

Edited on 2012-05-29 10:04:34 by ClAd [edited adduser steps]
Additions:
To make any changes to ldap or kerberos, first get a ticket (either as ldapadmin or as a member in the ldap group tech).
This will add principal pedro with password of pedro to kerberos and needchange password flag set, as well as adding user pedro to ldap with group of users (gid 10100) and creating their home with contents from /etc/ldapscripts/skel.
To reset his password, in case he cannot login:
kadmin.local -q 'cpw -pw password pedro'
Then, finally, force the user to change their password on next login:
kadmin.local -q 'modprinc +needchange pedro'
The above query commands of cpw and modprinc can also be executed within kadmin.local.
Deletions:
Now, let's set his password. First, we need to authenticate to kerberos as ourselves:
Launch the local kadmin:
kadmin.local
Set the password:
cpw pedro
Then, finally, force the user to set their password on next login:
modprinc +needchange pedro


Revision [6214]

Edited on 2012-05-29 09:16:46 by MikeShultz [edited adduser steps]
Additions:
===Creating New Users===
To create new users, they must be added to LDAP, have their password set in Kerberos, be added to the necessary groups, and ideally be forced to change their passwords on login. We'll start by adding pedro:
Add the user to LDAP with the standard users group:
%%(language-ref)
ldapadduser pedro users
%%
Since he's a research intern, let's give him access to the research drive:
%%(language-ref)
ldapaddusertogroup pedro research
%%
Now, let's set his password. First, we need to authenticate to kerberos as ourselves:
%%(language-ref)
kinit mike
%%
Launch the local kadmin:
%%(language-ref)
kadmin.local
%%
Set the password:
%%(language-ref)
cpw pedro
%%
Then, finally, force the user to set their password on next login:
%%(language-ref)
modprinc +needchange pedro
%%
Now the user should be setup with full access to the research drive and be forced to change their password on first login.
===Misc. commands===
Deletions:
Misc. commands:


Revision [5852]

Edited on 2012-03-30 10:38:44 by ClAd [edited adduser steps]
Additions:
ktutil (keytab utility)
kdb5_util (kerberos database utility)
Deletions:
ktutil


Revision [5682]

Edited on 2012-02-10 10:02:47 by MikeShultz [added note to kinit]
Additions:
kinit - Use me to authenticate.
Deletions:
kinit


Revision [5086]

The oldest known version of this page was created on 2011-06-22 03:53:10 by ClAd [added note to kinit]
Valid XHTML :: Valid CSS: :: Powered by WikkaWiki