0

Anyone familiar with the possibility to authenticate sudo command in /etc/pam.d/sudo with kerberos5 a.k.a with pam_krb5.so library?

1
  • I have working authentication with kerberos5 for https and all systems. Is this even possible to have setup where Kerberos ticket grants sudo rights to system? Commented Jan 11 at 7:56

1 Answer 1

0

SSSD comes with pam_sss_gss.so which supports this. Neither of the two variations of pam_krb5.so (Fedora and RRA) have such a feature, as far as I can see.

Additionally, MIT Kerberos comes with ksu which achieves more-or-less the same thing if you're looking for "unrestricted" sudo.

7
  • Thanks! Good to know. I am in winbind so have to see how I go about it. Commented Jan 11 at 16:28
  • @SamiHulkko: If all you need is passwordless sudo, then, ksu (or a customized version of ksu) might do the job. Commented Jan 12 at 13:49
  • Any way with certificate to achieve sudo auth? Commented Jan 12 at 18:26
  • Locally or via SSH? What kind of certificate? Commented Jan 12 at 19:25
  • Local self signed SSL certificate and login via ssh or console. Commented Jan 13 at 8:54

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.