Feature #11936
closed
Support kerberized SSH as an alternative to keys
Added by Stephen Benjamin about 9 years ago.
Updated over 6 years ago.
Description
It'd be relatively easy for the proxy to use the existing krb5 infrastructure (used by GSS-TSIG DNS updates and Realm) as an optional alternative to SSH keys.
- Tracker changed from Bug to Feature
It would be useful to be able to assign the keytab to each job invocation / and provide a default keytab per template.
- Bugzilla link set to 1386266
- Target version set to 1.13.1
Assigning for iteration 14 although it will probably skip to iteration 15. It seems https://github.com/cbeer/net-ssh-kerberos should be relatively straight forward to use. The majority of the work (I hope) should be around packaging, testing and documentation.
- Status changed from New to Ready For Testing
- Assignee set to Adam Ruzicka
- Pull request https://github.com/theforeman/foreman_remote_execution/pull/250 added
- Related to Bug #19918: Allow enabling kerberos auth for REX added
- Pull request https://github.com/theforeman/smart_proxy_remote_execution_ssh/pull/33 added
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
- Translation missing: en.field_release set to 280
Also available in: Atom
PDF