[rt-users] RT 3.8: questions on Kerberos, LDAP, and guest account setup

Kevin Falcone falcone at bestpractical.com
Fri Jun 10 08:51:25 EDT 2011


On Thu, Jun 09, 2011 at 09:57:49PM +0700, Ivan Shmakov wrote:
> 	I was able to successfully configure RT and Apache to use
> 	Kerberos for authentication, roughly as shown below.  However,
> 	now I'm somewhat concerned about the lack of authentication in
> 	rt-mailgate(1) (Debian Bug#615890 [1].)  Somehow, I feel that
> 	this issue could be resolved easily, and wonder if anyone's
> 	interested?

We'd certainly consider patches

> 	Also, I wonder, is it possible to make RT refer to LDAP for
> 	certain information (like: login name, real name, e-mail, etc.)
> 	about its users?  It could easily become a painful experience to
> 	either synchronize the RT user database with LDAP, or to
> 	maintain the informations in both of the places simultaneously.

Sounds like you want RT-Extension-LDAPImport

> 	Additionally, I have set up an Unprivileged “guest” account.
> 	However, this configuration results in the user being presented
> 	with a somewhat “limited” Web interface (in particular, it lacks
> 	the Search facility.)  Should I make this account Privileged
> 	instead, or is there another easy way of setting up a
> 	“read-only” account with the Search facility being active?

If you want the advanced search, you want a Privileged user.
Unprivileged users are only going to see tickets that they're the
Requestor of.

-kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.bestpractical.com/pipermail/rt-users/attachments/20110610/e2a58ea7/attachment.sig>


More information about the rt-users mailing list