Lantern Service Portal
Where I left off:
Apache proxy appears to be working. Next, I need to resolve the Next.js app errors (Prisma DB doesn't exist or something like that). Once that is complete, it would be worth trying to see if I can connect to the docker hosts from my regular browser
Objectives
Local Development
Dev Environment
References:
- https://help.hcl-software.com/unica/Campaign/en/12.1.1/Installation/Install/InstallnConfigure_MIT_Kerberos.html
- https://www.adaltas.com/en/2019/11/04/windows-krb5-client-spnego/
First Time Setup Instructions
- Install MIT Kerberos
- Copy the contents of
krb5/krb5.confintoC:\ProgramData\MIT\Kerberos5\krb5.ini - Set the system environment variable
KRB5CCNAME=C:\tmp\krb5cache(the folder should be created, but the file "krb5cache" should not already exist) - Run
which kinitandwhich klistto ensure that both are using MIT's commands (Windows and Java have commands that can take priority) - Configure hosts file to recognize Docker domain:
- Add the following lines to
C:/Windows/System32/drivers/etc/hosts. IP addresses may need to be changed to match your system.127.19.0.4 apache.dev.local 127.19.0.3 kdc.dev.local 127.19.0.2 nextjs-app.dev.local
- Add the following lines to
- Configure browser to use MIT Kerberos
Firefox:
- Set
network.negotiate-auth.trusted-uris = .dev.local - Set
network.negotiate-auth.delegation-uris = .dev.local - Set
network.auth.use-sspi = false
- Set
Continuing Setup Instructions
- Use Docker to spin up:
- A fake Kerberos KDC (
DEV.LOCALrealm). - Apache HTTPD with
mod_auth_kerbfor SSO. - A Next.js app served behind Apache.
- A fake Kerberos KDC (
- Authenticate with Kerberos:
Remember that these commands may not be the MIT Kerberos ones. Be sure to use fully qualified paths to these executables if necessary.
- Run
kinit -V testuser@DEV.LOCALand enter password "UserPass123" - Run
klistto verify that the ticket has been cached
- Run
- Visit
http://apache.dev.localin a browser
Auth Flow
- Apache handles the Kerberos login.
- Passes
REMOTE_USERto Next.js viaX-Remote-Userheader. - Uses the keytab for identity.
- Read
X-Remote-Userfrom the request headers. - Display logged-in user in the app.
Production Deployment
| Dev | Production (AD) |
|---|---|
| Simulated realm (DEV.LOCAL) | Real AD domain (e.g., CORP.COMPANY.COM) |
| Dockerized KDC | Real AD Domain Controller |
| Manually created keytab | Generated via ktpass and tied to AD account |
| Apache in Docker | IIS or Apache on Windows/Linux |
Description
Languages
TypeScript
92.6%
CSS
4.1%
JavaScript
2.5%
Shell
0.8%