From dc65b22fa372d28f99b10824a4801d24acfe9862 Mon Sep 17 00:00:00 2001 From: Bruce Momjian Date: Sat, 27 May 2000 03:42:32 +0000 Subject: [PATCH] Add README.kerbros --- doc/README.kerberos | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 doc/README.kerberos diff --git a/doc/README.kerberos b/doc/README.kerberos new file mode 100644 index 00000000000..8ad0e61ecbf --- /dev/null +++ b/doc/README.kerberos @@ -0,0 +1,21 @@ +Edit postgresql-7.0RC5/src/Makefile.global.in. Change PG_KRB_SRVTAB to +somewhere useful for you, and PG_KRB_SRVNAM to whatever you want your +postgres kerberos service called. + +make and install PostgreSQL. + +Generate the keytab (PG_KRB_SRVTAB): kadmin% ank -randkey +postgres/server.my.domain.org kadmin% ktadd -k krb5.keytab +postgres/server.my.domain.org + +Make sure the keytab is read-only to the postgres user. Make sure your +client binaries can see the new libraries. + +edit pg_hba.conf and change the authentication method to krb5. + +Everything should then work. If you use mod_auth_krb and mod_perl on +your web server, you can use AuthType KerberosV5SaveCredentials with a +mod_perl script. This gives secure database access over the web. No +extra passwords required. + +Mike Wyer