Jonathan Turner 9 年之前
父節點
當前提交
540456fd3c
共有 3 個文件被更改,包括 5 次插入2 次删除
  1. 2 1
      testenv/krb5kdc-vagrant/kdc-setup.sh
  2. 3 1
      testenv/krbhttp-vagrant/bootstrap.sh
  3. 二進制
      testenv/krbhttp-vagrant/http.testtab

+ 2 - 1
testenv/krb5kdc-vagrant/kdc-setup.sh

@@ -59,6 +59,7 @@ if [ ! -f /opt/krb5/data/principal ]; then
     for service in ${SPNs}
     do
       /usr/sbin/kadmin.local -q "add_principal -pw passwordvalue ${service}"
+      /usr/sbin/kadmin.local -q "cpw -pw passwordvalue ${service}"
       echo "Created principal for service $service"
     done
   fi
@@ -90,7 +91,7 @@ if [ ! -f /opt/krb5/data/principal ]; then
       done
       IFS=";"
       chown $permissions ${KEYTAB_DIR}/${keytabFileName}
-      chmod 440 ${KEYTAB_DIR}/${keytabFileName}
+      chmod 660 ${KEYTAB_DIR}/${keytabFileName}
     done
     IFS=$OLDIFS
   fi

+ 3 - 1
testenv/krbhttp-vagrant/bootstrap.sh

@@ -10,7 +10,8 @@ yum install -y \
    httpd \
    mod_auth_kerb \
    mod_ssl \
-   ntp
+   ntp \
+   krb5-workstation
 
 systemctl stop firewalld
 systemctl disable firewalld
@@ -31,6 +32,7 @@ mv /vagrant/httpd-krb5.conf /etc/httpd/conf.d/
 chcon system_u:object_r:httpd_config_t:s0 /etc/httpd/conf.d/*
 chcon system_u:object_r:httpd_config_t:s0 /vagrant/http.testtab
 chmod 644 /vagrant/http.testtab
+echo "<html>TEST.GOKRB5</html>" > /var/www/html/index.html
 
 systemctl restart httpd
 systemctl enable httpd

二進制
testenv/krbhttp-vagrant/http.testtab