################################################################################
#
# Apache2 GSSAPI authentication file.
#
# The GSSAPI authentication file contains configuration options that allow
# authentication against the KIT.EDU AD DCs. It can be included from within a
# <Directory> but not from a .htaccess file. A common setup would be:
#
#   AuthName		"My private homepage"
#   Include		/etc/apache2/include/auth_gssapi
#   GssapiCredStore	keytab:/var/www/<VHost>/conf/http.keytab
#   Require		valid-user

<IfModule mod_auth_gssapi.c>
<IfModule mod_authnz_ldap.c>
AuthType		GSSAPI
#KrbVerifyKDC		On
# Do we need both?
#KrbLocalUserMapping	On
##KrbAppendRealm		Off
# https://github.com/gssapi/mod_auth_gssapi
GssapiBasicAuth		On
GssapiLocalName		On
# Can't use AD for LDAP authorization, too, because groups aren't unrolled :-(
Include			/etc/apache2/include/ldap
</IfModule>
</IfModule>
