I'm trying to run an apache virtualhost, on a machine currently running Red Hat Enterprise Linux release 8.5 (Ootpa), with Kerberos authentication using the new GSSAPI module (replacement of mod_auth_kerb).

I also configured LDAP directives to authenticate my users through an LDAP thanks to mod_ldap.

My krb5.conf :

 default = FILE:/var/log/krb5libs.log
 kdc = FILE:/var/log/krb5kdc.log
 admin_server = FILE:/var/log/kadmind.log

 default_realm = MY.DOMAIN
 dns_lookup_realm = false
 dns_lookup_kdc = false
 ticket_lifetime = 24h
 forwardable = yes

  kdc = ADserver.my.domain
  a_server = ADserver.my.domain
  default_domain = my.domain

 .kerberos.server = MY.DOMAIN
 .my.domain = MY.DOMAIN

 pam = {
 debug = false
 ticket_lifetime = 36000
 renew_lifetime = 36000
 forwardable = true
 krb4_convert = false

I created a user on which is assigned a keytab. My user is called "usersso"

SPN info :

C:\Users\me>setspn -L usersso
Registered ServicePrincipalNames for CN=UserSso,OU=Users,DC=MY,DC=DOMAIN:

C:\Users\me>setspn -Q HTTP/myserver.my.domain
Checking domain DC=MY,DC=DOMAIN

Existing SPN found!

I sent my keytab to my apache server :

[root@myserver conf.d]# klist -ek /etc/httpd/usersso.keytab
Keytab name: FILE:/etc/httpd/usersso.keytab
KVNO Principal
---- --------------------------------------------------------------------------
   4 HTTP/myserver.my.domain@MY.DOMAIN (aes256-cts-hmac-sha1-96)

Keytab tests :

[root@myserver httpd]# kinit -V -kt /etc/httpd/usersso.keytab -p HTTP/myserver.my.domain@MY.DOMAIN
Using default cache: /tmp/krb5cc_0
Using principal: HTTP/myserver.my.domain@MY.DOMAIN
Using keytab: /etc/httpd/usersso.keytab
Authenticated to Kerberos v5

[root@myserver httpd]# klist -Af
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: HTTP/myserver.my.domain@MY.DOMAIN

Valid starting       Expires              Service principal
16/06/2022 13:03:23  16/06/2022 23:03:23  krbtgt/MY.DOMAIN@MY.DOMAIN
        renew until 17/06/2022 13:03:23, Flags: FPRIA

Keytab looks like OK.

Then now my virtualhost configuration :

    ServerName              myserver.my.domain

    ErrorLog             /var/log/httpd/myserver.my.domain_error.log
    TransferLog          /var/log/httpd/myserver.my.domain_access.log
    LogLevel             debug

    <Location />
      AuthType GSSAPI
      AuthName "GSSAPI Single Sign On Login"
      GssapiBasicAuth On
      GssapiBasicAuthMech krb5
      GssapiAllowedMech krb5
      GssapiCredStore keytab:/etc/httpd/usersso.keytab
      GssapiLocalName On
      BrowserMatch Windows gssapi-no-negotiate

      AuthLDAPURL ldap://ldapserver:10400/ou=users,o=enterprise,dc=city,dc=fr?uid?sub?(objectclass=person)
      AuthLDAPGroupAttribute member
      AuthLDAPBindDN "cn=apache,ou=users,o=enterprise,dc=city,dc=fr"
      AuthLDAPBindPassword "XXXX"
      AuthzSendForbiddenOnFailure On

      Require ldap-group cn=group_to_authenticate_users,ou=Groupe,ou=Profil,o=enterprise,dc=city,dc=fr

# tag::TLSClient[]
    SSLProxyEngine on
    SSLProxyProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
    SSLProxyCipherSuite HIGH:!aNULL:!MD5
    SSLProxyCheckPeerCN off
    SSLProxyCheckPeerName off
    SSLProxyCheckPeerExpire off
    SSLProxyVerifyDepth 10
    SSLOCSPEnable off
# end::TLSClient[]

    ProxyPass               / https://anotherserver:443/
    ProxyPassReverse        / https://anotherserver:443/


When I try to access my virtualhost, I am not directly sent to anotherserver but I have an authentication window prompt that appears on my Google Chrome browser (which means Kerberos authentication doesn't work properly)

Access_log says : - - [16/Jun/2022:11:53:21 +0200] "GET / HTTP/1.1" 401 381

Error log says :

[Thu Jun 16 12:49:42.867213 2022] [authz_core:debug] [pid 8154:tid 139726585538304] mod_authz_core.c(820): [client] AH01626: authorization result of Require ldap-group cn=group_to_authenticate_users,ou=Groupe,ou=Profil,o=enterprise,dc=city,dc=fr: denied (no authenticated user yet)
[Thu Jun 16 12:49:42.867231 2022] [authz_core:debug] [pid 8154:tid 139726585538304] mod_authz_core.c(820): [client] AH01626: authorization result of <RequireAny>: denied (no authenticated user yet)
[Thu Jun 16 12:49:42.867256 2022] [auth_gssapi:debug] [pid 8154:tid 139726585538304] mod_auth_gssapi.c(901): [client] URI: /, no main, no prev
[Thu Jun 16 12:49:42.867273 2022] [auth_gssapi:info] [pid 8154:tid 139726585538304] [client] NO AUTH DATA Client did not send any authentication headers

And finally, if i enter my credentials through the prompt credentials chrome browser, I'm successfully authenticate with my LDAP group and I can access to my anotherserver but the SSO thanks to Kerberos GSSAPI doesn't work, I still have to enter my credentials manually .. :(

curL result : The WWW-authenticate : Negotiate response header is présent:

curl -k -L http://myserver.my.domain/ -v
*   Trying
* Connected to myserver.my.domain ( port 80 (#0)
> GET / HTTP/1.1
> Host: myserver.my.domain
> User-Agent: curl/7.65.0
> Accept: */*
* Mark bundle as not supporting multiuse
< HTTP/1.1 401 Unauthorized
< Date: Thu, 16 Jun 2022 10:57:31 GMT
< Server: Apache/2.4.37 (Red Hat Enterprise Linux) OpenSSL/1.1.1k mod_auth_gssapi/1.6.1
< WWW-Authenticate: Negotiate
< WWW-Authenticate: Basic realm="GSSAPI Single Sign On Login"
< Content-Length: 381
< Content-Type: text/html; charset=iso-8859-1
<title>401 Unauthorized</title>
<p>This server could not verify that you
are authorized to access the document
requested.  Either you supplied the wrong
credentials (e.g., bad password), or your
browser doesn't understand how to supply
the credentials required.</p>
* Connection #0 to host myserver.my.domain left intact

Can somebody help me about this issue ?

Thanks !


I finally found the solution !

  • I removed "BrowserMatch Windows gssapi-no-negotiate" to my apache conf,
  • And stop+disable the gssproxy service because i'm still unable to work with in RHEL8.6
  • And then don't forget to change Environment=GSS_USE_PROXY to 0 to avoid "gss_localname() input error" in apache error logs.
  • 11
  • 2

0 Answers0