ZCS Administrator Guide 7.2.1
ZCS Administrator Guide 7.2.1
Open Source Edition

Working with Zimbra Proxy > Configuring Zimbra Proxy for Kerberos Authentication

Configuring Zimbra Proxy for Kerberos Authentication
If you use the Kerberos5 authenticating mechanism, use the following steps to configure IMAP and POP proxy.
To set the default Kerberos domain for authentication, on each proxy node, set the zimbraReverseProxyDefaultRealm server attribute to the realm name corresponding to the proxy server. For example, enter as:
zmprov ms [DNS name.isp.net] zimbraReverseProxyDefaultRealm [ISP.NET]
Each proxy IP address where email clients connect must be configured for GSSAPI authentication by the mail server. On each proxy node for each of the proxy IP addresses, enter the following command:
zmprov mcf +zimbraReverseProxyAdminIPAddress [IP address]
zmprov ms [proxyexample.net] zimbraReverseProxyImapSaslGssapiEnabled TRUE
zmprov ms proxyl.isp.net zimbraReverseProxyPop3SaslGssapiEnabled TRUE
zmproxyctl restart
Copyright © 2012 VMware Inc.