Mac OS X Server 1.x: About Kerberos on Mac OS X Server

This release note describes Mac OS X Server specific issues surrounding the Kerberos version 5.

This document was installed by Mac OS X Server in /System/Documentation/ReadMe. For a list of other release notes see article 30925: "Mac OS X Server: Release Notes"
Note: This article pertains to Mac OS X Server versions 1.x, which were released prior to May 2001.

Support for Kerberos v5 in Mac OS X Server

There is limited support for Kerberos version 5 in Mac OS X Server. Due to U.S. export restrictions, the Kerberos libraries are not available in the developer tookit, and Kerberos is not yet fully integrated into the system. The authentication and administration clients, however, are available: kinit, kadmin, and other utilities are built into the system. It is therefore possible to make use of kerberos-enabled software that you add into the system.

Login support using kerberos is available in the distribution. /usr/bin/login may be replaced with /usr/libexec/login.krb5, which will use kerberos to authenticate the login session and obtain the appropriate credentials for logged in users. Similar support is available for loginwindow from /System/Library/Authenticators/Kerberos.loginauthenticator. You may choose to enable its use via the "Custom Login Authenticator" option in the "Login Window" panel in Preferences.app while logged in as Administrator.

Kerberos-enabled versions of telnet and other network clients may be available to take advantage of kerberos authentication in a future release. Domestic users may get the full Kerberos distribution from M.I.T. via FTP at ftp://athena-dist.mit.edu/pub/kerberos/

Published Date: Feb 18, 2012