Jonathan Turner 9 лет назад
Родитель
Сommit
540456fd3c

+ 2 - 1
testenv/krb5kdc-vagrant/kdc-setup.sh

@@ -59,6 +59,7 @@ if [ ! -f /opt/krb5/data/principal ]; then
     for service in ${SPNs}
     do
       /usr/sbin/kadmin.local -q "add_principal -pw passwordvalue ${service}"
+      /usr/sbin/kadmin.local -q "cpw -pw passwordvalue ${service}"
       echo "Created principal for service $service"
     done
   fi
@@ -90,7 +91,7 @@ if [ ! -f /opt/krb5/data/principal ]; then
       done
       IFS=";"
       chown $permissions ${KEYTAB_DIR}/${keytabFileName}
-      chmod 440 ${KEYTAB_DIR}/${keytabFileName}
+      chmod 660 ${KEYTAB_DIR}/${keytabFileName}
     done
     IFS=$OLDIFS
   fi

+ 3 - 1
testenv/krbhttp-vagrant/bootstrap.sh

@@ -10,7 +10,8 @@ yum install -y \
    httpd \
    mod_auth_kerb \
    mod_ssl \
-   ntp
+   ntp \
+   krb5-workstation
 
 systemctl stop firewalld
 systemctl disable firewalld
@@ -31,6 +32,7 @@ mv /vagrant/httpd-krb5.conf /etc/httpd/conf.d/
 chcon system_u:object_r:httpd_config_t:s0 /etc/httpd/conf.d/*
 chcon system_u:object_r:httpd_config_t:s0 /vagrant/http.testtab
 chmod 644 /vagrant/http.testtab
+echo "<html>TEST.GOKRB5</html>" > /var/www/html/index.html
 
 systemctl restart httpd
 systemctl enable httpd

BIN
testenv/krbhttp-vagrant/http.testtab