[Freeipa-users] Configuring Client SSH Access Problem

Michael Kang wxiluo at gmail.com
Tue Dec 8 04:35:18 UTC 2009


Dear all,

I had setup a FreeIPA server and a FreeIPA client. After using the
*ktutil*command to import the keytab, using the following command on
another machine
to test the configuration. This still need passwd.

IPA Server:

> kinit admin
> ipa-addservice host/ipaclient.example.com
> ipa-getkeytab -s ipaserver.example.com -p host/ipaclient.example.com -k
> /tmp/krb5.keytab
> scp /tmp/krb5.keytab root at ipaclient.example.com:/tmp/krb5.keytab
>

IPA client:

> # ktutil
> ktutil: read_kt /tmp/krb5.keytab
> ktutil: write_kt /etc/krb5/krb5.keytab
> ktutil: q
>
ssh admin@*ipaserver*.example.com (This don't need passwd.)

PC or Mac:
ssh admin@*ipaclient*.example.com (This still need passwd.)

What should I do?

Best Regards,
Michael Kang
-- 
Michael Kang(康上明学)
There is a giant asleep within every man. When the giant awakens,miracles
happen.

Personal blog: http://ufusion.org - United Fusion
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20091208/fa72f6c1/attachment.htm>


More information about the Freeipa-users mailing list