Kerberos/SPNEGO Config For One-Shot
Description
Configures the Kerberos settings for One-Shot authentication via SPNEGO.
May be used by
Properties
Keytab File (
keytabFile) Description
The path of the Kerberos keytab file that should be used for Kerberos SPNEGO identity assertion.
Attributes
File/Path
Mandatory
Service Principal (
servicePrincipal) Description
The Kerberos Service Principal Name (SPN) associated with Airlock IAM. It is usually in the form HTTP/<FQDN> or * to allow all SPNs present in the keytab file.
Optionally, the realm can be specified if there's no default realm in the kerberos configuration file or if the SPN is associated with a different realm/domain (see example values).
Optionally, the realm can be specified if there's no default realm in the kerberos configuration file or if the SPN is associated with a different realm/domain (see example values).
Attributes
String
Mandatory
Example
HTTP/login.ergon.ch
Example
HTTP/login.ergon.ch@REALM
Example
*
Enable Debugging (
enableDebugging) Description
Enable/Disable Kerberos debug logs.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: Kerberos
id: Kerberos-xxxxxx
displayName:
comment:
properties:
enableDebugging: false
keytabFile:
servicePrincipal: