11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 24 Kerberos Authenticationfor example:kinit -S host/mail.company.com@COMPANY.COM jsmithIf the query was processed correctly, you will be asked to enter password for the particularuser. Otherwise, an error will be reported.Authentication against Open Directory<strong>Kerio</strong> MailServer can either be installed on the server with the Apple Open Directory directoryservice or on another server.If <strong>Kerio</strong> MailServer is installed on the same server as Open Directory, it is not necessary to performany additional configuration besides installation of the <strong>Kerio</strong> Open Directory Extensionsinstallation. If it is installed on another computer, external authentication through Kerberosto Open Directory must be set.<strong>Kerio</strong> MailServer can be installed on servers with Mac OS X 10.3 and higher. The settings aresimilar for both versions. The following description applies to configuration on Mac OS X 10.4,any discrepancies will be mentioned.External authentication is configured with a special application, Directory Access. The applicationcan be found under Applications → Utilities → Directory Access. This applicationis used to create the special edu.mit.Kerberos authentication file which is located under/Library/Preferences. The following settings must be performed to make the authenticationwork properly:1. Start the Directory Access application.2. On the Services tab, check the LDAPv3 item (see figure 24.9).3. On the Services tab, use the mouse pointer to park the DAPv3 item and click on Configure.4. In the next dialog, click New.5. This will open a dialog box where IP address and name of the server can be specified. EnterIP address or DNS name of the server where the Apple Open Directory service is running.Once the server is specified, click on the Manual button (not necessary in the Mac OS X10.3 version) and enter a name in the Configuration name text box (this item is used forreference only).6. Save the configuration and select Open Directory Server in the LDAP Mappings menu.7. Once Open Directory Server is selected, the dialog for specification of the search suffixis opened (Search Base Suffix). The suffix must be entered as shown in the example infigure 24.10:od.company.com → dc=od,dc=company,dc=com276

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!