TECHZEN Zenoss User Community ARCHIVE  

Zenoss 5.2.3 appliance and Kerberos auth for winrm monitoring.

Subject: Zenoss 5.2.3 appliance and Kerberos auth for winrm monitoring.
Author: Justin Bezuhly
Posted: 2017-10-30 19:27

Figured I post since I can't get a clear understanding of how to get the Kerberos auth working WinRM monitoring. A few questions to help clear things up:

1) Does the zenoss ova machine need to be domain joined for the kerberos auth to work?
2) Do I have to manually edit the kerb5.conf or is this accomplished by changing the configuration properties on devices?
3) What container runs the kerberos commands? Zope?


Subject: RE: Zenoss 5.2.3 appliance and Kerberos auth for winrm monitoring.
Author: Jane Curry
Posted: 2017-10-31 05:55

Have you seen this post - Windows ZenPack - Kerberos settings config file   ?

My understanding is that you should not need to manually touch krb.conf - it should be created and updated as necessary, when you change relevant zProperties for devices.  You can add other krb.conf file parameters using your own extension file - see the append above.

As to containers, the krb.conf should be automatically sent to each container that needs it - that is certainly the zenpython container (as that runs the winrm performance collection), the zenmodeler container (as that runs the winrm plugins) and the zope container also has it but I don't have a definitive answer as to why.  May also appear in other containers (zminion which runs stuff directly from the GUI??).

Cheers,
Jane

------------------------------
Jane Curry
Skills 1st United Kingdom
jane.curry@skills-1st.co.uk
------------------------------


< Previous
Zenoss Core 6.0.0 deploy error
  Next
Server Exception
>