11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

24.4 Starting Open Directory and Kerberos settingsKerberos functionality can be tested by checking the/Library/Preferences/edu.mit.Kerberos file. The following parameters should beincluded:# WARNING This file is automatically created by KERBEROS# do not make changes to this file;# autogenerated from : /KERBEROS/company.com# generation_id : 0[libdefaults]default_realm = COMPANY.COMticket_lifetime = 600dns_fallback = no[realms]COMPANY.CZ = {kdc = server.company.com. :88admin_server = server.company.com.}Using the kinit utility, it is possible to test whether <strong>Kerio</strong> MailServer is able to authenticateagainst Kerberos. Simply open the prompt line and use the following command:kinit -S host/KMS_hostname@KERBEROS_REALM username@REALMfor example:kinit -S host/mail.company.com@COMPANY.COMIf the query was processed correctly, you will be asked to enter password for the particularuser. Otherwise, an error will be reported.When the previous steps are followed successfully, set authentication in <strong>Kerio</strong> MailServer onthe Advanced tab under Configuration → Domains, (see chapter 7.7).24.4 Starting Open Directory and Kerberos settingsIn Open Directory, it is possible to authenticate users against the password server (refer tochapter 7.6) or the Kerberos server (for details, see chapter 24). As mentioned in chapter 7.6,authentication against the password server does not require any additional settings, whileKerberos authentication might be quite difficult to configure. This chapter therefore focuseson correct setting of the authentication against the Kerberos server in Open Directory.After Mac OS X Server’s startup, make sure that both the Open Directory service and theKerberos server are running. This can be done in the Server Admin application (Applications→ Server → Server Admin).The welcome dialog of Server Admin consists of two basic sections. The left one includesa list of hosts and services which are running at these hosts. This section also includes thehost where the Open Directory service is supposed to be started. If the service is alreadyrunning, it is bold and marked with a green symbol (see figure 24.12).281

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!