ZCS Administrator's Guide Network Edition 6.0.8
Table of Contents Previous Next Index


Working with Zimbra Proxy : Configuring Zimbra Proxy for Kerberos Authentication

Configuring Zimbra Proxy for Kerberos Authentication
If you use the Kerberos5 authenticating mechanism, use the following steps to configure IMAP and POP proxy.
Note: Make sure that your Kerberos5 authentication mechanism is correctly configured before you do this. See the Kerberos5 Authentication Mechanism.
1.
To set the default Kerberos domain for authentication, on each proxy node, set the zimbraReverseProxyDefaultRealm server attribute to the realm name corresponding to the proxy server. For example, enter as:
zmprov ms [DNS name.isp.net] zimbraReverseProxyDefaultRealm [ISP.NET]
2.
Each proxy IP address where email clients connect must be configured for GSSAPI authentication by the mail server. On each proxy node for each of the proxy IP addresses, enter the following command:
zmprov mcf +zimbraReverseProxyAdminIPAddress [IP address]
3.
zmprov ms [proxyexample.net] zimbraReverseProxyImapSaslGssapiEnabled TRUE
zmprov ms proxyl.isp.net zimbraReverseProxyPop3SaslGssapiEnabled TRUE
4.
zmproxyctl stop
zmproxyctl start

Working with Zimbra Proxy : Configuring Zimbra Proxy for Kerberos Authentication

Table of Contents Previous Next Index
ZCS Administrator's Guide Network Edition 6.0.8
Copyright © 2010 Zimbra Inc.