[CentOS] Services supporting Kerberos and/or TLS client certificate authentication

Mon Mar 23 14:17:45 UTC 2015
Jonathan Billings <billings at negate.org>

On Mon, Mar 23, 2015 at 10:34:49AM +0100, Andrew Holway wrote:
>
> Hello,
> 
> We're starting to use FreeIPA in house (which is awesome btw) which means
> that Kerberos and TLS client certificate authentication is suddenly quite
> easy. Im looking for a list of common Linux services with data on how one
> can Authenticate/Authorise for these services.

Do you want to use Kerberos to authenticate user/passwords?  Or are
you looking to use the user's existing kerberos ticket to authenticate
services? 

> * httpd support TLS client certificate authentication and Kerberos

You can use mod_auth_kerb for httpd with any client that supports the
Negotiate authentication method.  There's also tools to let it use
SASL to perform plain text password authentication, but I'm not
familiar with it.

> * dovecot supports Kerberos and ...

Dovecot supports GSSAPI authentication as well as using SASL.
Sendmail and Postfix too.

Sorry, not sure about rabbitmq.
-- 
Jonathan Billings <billings at negate.org>