Technische Universität Braunschweig
  • Study & Teaching
    • Beginning your Studies
      • Prospective Students
      • Degree Programmes
      • Application
      • Fit4TU
      • Why Braunschweig?
    • During your Studies
      • Fresher's Hub
      • Term Dates
      • Courses
      • Practical Information
      • Beratungsnavi
      • Additional Qualifications
      • Financing and Costs
      • Special Circumstances
      • Health and Well-being
      • Campus life
    • At the End of your Studies
      • Discontinuation and Credentials Certification
      • After graduation
      • Alumni*ae
    • For Teaching Staff
      • Strategy, Offers and Information
      • Learning Management System Stud.IP
    • Contact
      • Study Service Centre
      • Academic Advice Service
      • Student Office
      • Career Service
  • Research
    • Research Profile
      • Core Research Areas
      • Clusters of Excellence at TU Braunschweig
      • Research Projects
      • Research Centres
      • Professors‘ Research Profiles
    • Early Career Researchers
      • Support in the early stages of an academic career
      • PhD-Students
      • Postdocs
      • Junior research group leaders
      • Junior Professorship and Tenure-Track
      • Habilitation
      • Service Offers for Scientists
    • Research Data & Transparency
      • Transparency in Research
      • Research Data
      • Open Access Strategy
      • Digital Research Announcement
    • Research Funding
      • Research Funding Network
      • Research funding
    • Contact
      • Research Services
      • Academy for Graduates
  • International
    • International Students
      • Why Braunschweig?
      • Degree seeking students
      • Exchange Studies
      • TU Braunschweig Summer School
      • Refugees
      • International Student Support
    • Going Abroad
      • Studying abroad
      • Internships abroad
      • Teaching and research abroad
      • Working abroad
    • International Researchers
      • Welcome Support
      • PhD Studies
      • Service for host institutes
    • Language and intercultural competence training
      • Learning German
      • Learning Foreign Languages
      • Intercultural Communication
    • International Profile
      • Internationalisation
      • International Cooperations
      • Strategic Partnerships
      • International networks
    • International House
      • About us
      • Contact & Office Hours
      • News and Events
      • International Days
      • 5th Student Conference: Internationalisation of Higher Education
      • Newsletter, Podcast & Videos
      • Job Advertisements
  • TU Braunschweig
    • Our Profile
      • Aims & Values
      • Regulations and Guidelines
      • Alliances & Partners
      • The University Development Initiative 2030
      • Foundation University
      • Facts & Figures
      • Our History
    • Career
      • Working at TU Braunschweig
      • Vacancies
    • Economy & Business
      • Entrepreneurship
      • Friends & Supporters
    • General Public
      • Check-in for Students
      • The Student House
      • Access to the University Library
    • Media Services
      • Communications and Press Service
      • Services for media
      • Film and photo permits
      • Advices for scientists
      • Topics and stories
    • Contact
      • General Contact
      • Getting here
  • Organisation
    • Presidency & Administration
      • Executive Board
      • Designated Offices
      • Administration
      • Committees
    • Faculties
      • Carl-Friedrich-Gauß-Fakultät
      • Faculty of Life Sciences
      • Faculty of Architecture, Civil Engineering and Environmental Sciences
      • Faculty of Mechanical Engineering
      • Faculty of Electrical Engineering, Information Technology, Physics
      • Faculty of Humanities and Education
    • Institutes
      • Institutes from A to Z
    • Facilities
      • University Library
      • Gauß-IT-Zentrum
      • Professional and Personnel Development
      • International House
      • The Project House of the TU Braunschweig
      • Transfer Service
      • University Sports Center
      • Facilities from A to Z
    • Equal Opportunity Office
      • Equal Opportunity Office
      • Family
      • Diversity for Students
  • Search
  • Quicklinks
    • People Search
    • Webmail
    • cloud.TU Braunschweig
    • Messenger
    • Cafeteria
    • Courses
    • Stud.IP
    • Library Catalogue
    • IT Services
    • Information Portal (employees)
    • Link Collection
    • DE
    • EN
    • IBR YouTube
    • Facebook
    • Instagram
    • YouTube
    • LinkedIn
    • Mastodon
Menu
  • Organisation
  • Faculties
  • Carl-Friedrich-Gauß-Fakultät
  • Institutes
  • Institute of Operating Systems and Computer Networks
  • IBR Knowledge Base
Logo IBR
IBR Login
  • Institute of Operating Systems and Computer Networks
    • News
    • About us
      • Whole Team
      • Directions
      • Floor Plan
      • Projects
      • Publications
      • Software
      • News Archive
    • Connected and Mobile Systems
      • Team
      • Courses
      • Theses
      • Projects
      • Publications
      • Software
      • Datasets
    • Reliable System Software
      • Overview
      • Team
      • Teaching
      • Theses & Jobs
      • Research
      • Publications
    • Algorithms
      • Team
      • Courses
      • Theses
      • Projects
      • Publications
    • Microprocessor Lab
    • Education
      • Winter 2025/2026
      • Summer 2025
      • Theses
    • Services
      • Library
      • Mailinglists
      • Webmail
      • Knowledge Base
      • Wiki
      • Account Management
      • Services Status
    • Spin-Offs
      • Docoloc
      • bliq (formerly AIPARK)
      • Confidential Technologies
    • Research Cooperations
      • IST.hub

Kerberos @ IBR

AuthorFrank Steinberg
KeywordsKerberos krb5 MIT-Kerberos kerb GSSAPI
CategoriesSoftware

Parts of the authentication and authorization infrastructure are based on MIT Kerberos. Some services support already Kerberos based SSO. Other services will be upgraded to support Kerberos for more comfortable authentication and more secure data and credentials protection.

Obtaining Tickets

Most Linux Servers obtain a TGT when a user logs in on the console or via SSH (but only if no other implicit authentication like pubkey is used, so that the user is asked for a password).

You can explicitly request a ticket using kinit username@IBR.CS.TU-BS.DE. If you want to make the IBR realm your default, you might want to put this in your /etc/krb5.conf file:

[libdefaults]
        default_realm = IBR.CS.TU-BS.DE
        dns_lookup_kdc = true
        renewable = true
        forwardable = true
        proxiable = true
        ticket_lifetime = 7d
        renew_lifetime = 30d
      

Services

The following services already support Kerberos/GSSAPI authentication:

  • SMTP on mail.ibr.cs.tu-bs.de (Postfix MTA)
  • IMAP on mail.ibr.cs.tu-bs.de (Cyrus IMAP Server)
  • SIEVE on mail.ibr.cs.tu-bs.de (Cyrus Sieve Server)
  • LDAP on ldap.ibr.cs.tu-bs.de (OpenLDAP Server)
  • HTTPS on trac.ibr.cs.tu-bs.de (Trac)
  • HTTPS on git.ibr.cs.tu-bs.de (GITweb)
  • HTTPS on svn.ibr.cs.tu-bs.de (Subversion)
  • HTTPS on nagios.ibr.cs.tu-bs.de (Icinga)
  • HTTPS on cal.ibr.cs.tu-bs.de (CalDAV & CardDAV)
  • SSH on almost all Linux hosts
  • NFS (testing phase on bierator.ibr.cs.tu-bs.de)
  • IPP?

Among other services, the IBR web server www.ibr.cs.tu-bs.de does NOT YET support Kerberos authentication.

Potential problems: NFS with crontabs or "offline" jobs

One major change will affect NFSv4 with Kerberos authentication, which is used on most IBR Linux workstions (but not on most Linux servers): Since Kerberos is based on "tickets" with a limited lifetime, Kerberos based services will stop working when a ticket times out before being renewed or before the session ends normally or when a ticket is removed while the Kerberos-based service keeps being used. Since the default ticket lifetime at IBR is currently 7 days, a ticket lifetime expiration will hardly cause any trouble. But you should take special care in case of cronjobs, simulations, and other "offline" jobs.

Cronjobs should be managed on the host cron.ibr.cs.tu-bs.de, which does not use Kerberos for NFS. Simulations and other "offline" jobs could be run on IBR servers, which also do not use Kerberos-based NFS authentication. You can check, which NFS version and authentication is used for home directories: mount | grep home. If the options contain "vers=3" you should not expect any problems. If the options contain "sec=krb5*" you should take care:

If you need to run jobs on workstations or other hosts that use Kerberos-based NFS authentication, then you could request an explicit credentials cache, which will not be removed upon logout:

kinit -F -c /tmp/krb5cc_`id -u`_specialuse

You can look at this ticket's lifetime with:

klist -c /tmp/krb5cc_`id -u`_specialuse

And you can renew the ticket regularly for 7 days during an overall period of up to 30 days with:

kinit -R -c /tmp/krb5cc_`id -u`_specialuse


last changed 2022-03-01, 14:31 by Frank Steinberg

For All Visitors

Vacancies of TU Braunschweig
Career Service' Job Exchange 
Merchandising

For Students

Term Dates
Courses
Degree Programmes
Information for Freshman
TUCard

Internal Tools

Glossary (GER-EN)
Change your Personal Data

Contact

Technische Universität Braunschweig
Universitätsplatz 2
38106 Braunschweig

P. O. Box: 38092 Braunschweig
GERMANY

Phone: +49 (0) 531 391-0

Getting here

© Technische Universität Braunschweig
Imprint Privacy Accessibility