GT-2658 - Active Directory via Kerberos authentication

This commit is contained in:
dev747368
2019-09-03 17:38:51 -04:00
parent a62730477e
commit 841e75ad8d
8 changed files with 215 additions and 38 deletions

View File

@@ -21,8 +21,7 @@ then
echo "Login failed: username has 'bad' in it: $NAME" 1>&2
exit 100
else
echo "OK"
echo "Login successful" 1>&2
fi
echo "Returning from script" 1>&2

View File

@@ -6,7 +6,8 @@
auth {
net.sf.jpam.jaas.JpamLoginModule required
// the serviceName parameter controls which PAM service Ghidra will try to authenticate against
// The serviceName parameter controls which PAM service Ghidra will try to authenticate against.
// This corresponds to a file called /etc/pam.d/<serviceName>
serviceName="system-auth"
;
};

View File

@@ -16,7 +16,7 @@
auth {
com.sun.security.auth.module.LdapLoginModule REQUIRED
userProvider="ldaps://<your_active_directory_ldap_server_hostname>:3269"
authIdentity="{USERNAME}@<your_active_directory_domain_name>"
authIdentity="{USERNAME}@<your_active_directory_domain_name.tld>"
userFilter="(sAMAccountName={USERNAME})"
debug=true;
};

View File

@@ -115,6 +115,7 @@ ghidra.repositories.dir=./repositories
# 0 - Private user password
# 2 - PKI Authentication
# 4 - JAAS Authentication
# 5 - Active Directory via Kerberos. Requires -d<active_directory_domainname.tld>
# -anonymous : enables anonymous repository access (see svrREADME.html for details)
# -ssh : enables SSH authentication for headless clients
# -e<days> : specifies default password expiration time in days (-a0 mode only, default is 1-day)