git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How do you script linux GIT client to pass kerberos credential to apache enabled GIT server?

From
Mantas Mikulėnas <grawity@gmail.com>
Date
Apr 4, 2017, 10:12 UTC
Message-ID
<7ab9e033-906f-f1ec-f89a-952346e98651@gmail.com>
In-Reply-To
<CAAqgmoP2uyd5_k-JDOBpBV8ay6BueUvKkwcWAZ_C1n4=4xpECg@mail.gmail.com>
On 2017-04-03 19:04, ken edward wrote:
Show 12 quoted lines
> Hello,
> 
> I have my git repositories behind an apache server configured with
> kerberos. Works fine if the user is logged in on their workstation.
> Apache gets the kerberos credential, and validates, and  then sends
> the GIT repo being requested.
> 
> BUT, I want to write a script on linux that will also pass the
> kerberos credential to the apache GIT server without having any
> manually intervention. Seems I would create a kerberos keytab for the
> principal and then use that to authenticate.... kinit supports
> authenticating from a keytab using the -k -t <keytab-path> options,

kinit works, but I think kstart [1] is commonly used for this as well; takes care of automatic ticket renewal.

ktutil should be able to create a keytab based on your password, but I've had mixed luck with that. Though still probably easier than creating a separate instance just for batch tasks...

[1]: https://www.eyrie.org/~eagle/software/kstart/
-- 
Mantas Mikulėnas <grawity@gmail.com>
Previous: Randall S. Becker
Message 3 of 3 in “How do you script linux GIT client to pass kerberos credential to apache enabled GIT server?”
  1. ken edwardApr 3, 2017
  2. Randall S. BeckerApr 3, 2017
  3. Mantas MikulėnasApr 4, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.