# Where is Doc to configure Git + Apache + kerberos for Project level access in repo?

3 messages from 2016-12-02 to 2016-12-05. Participants: ken edward, Jeff King, brian m. carlson.
Thread: https://gitlist.dev/t/44591

## ken edward, 2016-12-02 18:15

Subject: Where is Doc to configure Git + Apache + kerberos for Project level access in repo?
Message-ID: <CAAqgmoNG4vOqLnOqmrUvwTNJpqGBckfN-y=Fc99TrvjPhz7h0w@mail.gmail.com>
URL: https://gitlist.dev/e/CAAqgmoNG4vOqLnOqmrUvwTNJpqGBckfN-y%3DFc99TrvjPhz7h0w%40mail.gmail.com

```
Where is Doc to configure Git + Apache + kerberos for Project level
access in repo?

```

## Jeff King, 2016-12-02 22:21

Subject: Re: Where is Doc to configure Git + Apache + kerberos for Project level access in repo?
Message-ID: <20161202222153.3j5i5rsacybwexg6@sigill.intra.peff.net>
URL: https://gitlist.dev/e/20161202222153.3j5i5rsacybwexg6%40sigill.intra.peff.net
In-Reply-To: <CAAqgmoNG4vOqLnOqmrUvwTNJpqGBckfN-y=Fc99TrvjPhz7h0w@mail.gmail.com>

```
On Fri, Dec 02, 2016 at 01:15:02PM -0500, ken edward wrote:

> Where is Doc to configure Git + Apache + kerberos for Project level
> access in repo?

I don't know about Kerberos, but all of the documentation in git for
configuring Apache is found in "git help http-backend".

-Peff

```

## brian m. carlson, 2016-12-05 02:31

Subject: Re: Where is Doc to configure Git + Apache + kerberos for Project level access in repo?
Message-ID: <20161205023159.gzkqtfg3e63odtgt@genre.crustytoothpaste.net>
URL: https://gitlist.dev/e/20161205023159.gzkqtfg3e63odtgt%40genre.crustytoothpaste.net
In-Reply-To: <20161202222153.3j5i5rsacybwexg6@sigill.intra.peff.net>

```
On Fri, Dec 02, 2016 at 05:21:53PM -0500, Jeff King wrote:
> On Fri, Dec 02, 2016 at 01:15:02PM -0500, ken edward wrote:
> 
> > Where is Doc to configure Git + Apache + kerberos for Project level
> > access in repo?
> 
> I don't know about Kerberos, but all of the documentation in git for
> configuring Apache is found in "git help http-backend".

If you want to use Kerberos for authentication, it's really as simple as
just using "AuthType Kerberos" instead of "AuthType Basic", plus
whatever Kerberos parameters you want.

This is what my configuration looks like, but obviously you'll want to
modify it a bit:

  AuthType Kerberos
  AuthName "Kerberos Login"
  KrbMethodNegotiate on
  KrbMethodK5Passwd off
  KrbAuthRealms CRUSTYTOOTHPASTE.NET
  Krb5Keytab /etc/krb5.apache.keytab

You may also want to set http.emptyAuth on the client side.
-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | https://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: https://keybase.io/bk2204

```
