Principal for Apache httpd vhost

Frank Gruellich frank.gruellich at
Tue Apr 28 13:04:08 EDT 2009


I have a Linux server which is named goofy (as in the output of hostname
command) with full qualified hostname (as indicated by
hostname -f on the server itself).  DNS has an A record pointing from to, including reverse lookup (dig
confirms this, even at other machines).  This server runs an Apache
httpd with several vhosts configured, one of them  This
is configured to use mod_auth_kerb for authentication.  A CNAME is pointing to

Which principal do I add to the KDC database and export to
mod_auth_kerb's keytab?  Howtos suggest to use the full qualified
hostname, eg. HTTP/ at EXAMPLE.COM.  However, browsers
have different opinions about that.  Firefox/Seamonkey (I guess all
Gecko based browsers) on Linux use HTTP/ at EXAMPLE.COM.
Safari on Apples Mac OSX requests HTTP/ at EXAMPLE.COM from
KDC.  Firefox on Mac OSX behaves like the Linux version.  I don't have
more browsers available right now, but I will test others.

What is the correct behavior and configuration?  Thanks for your help.

Kind regards,
Navteq (DE) GmbH
Frank Gruellich
Map24 Systems and Networks

Duesseldorfer Strasse 40a
65760 Eschborn

Phone:      +49 6196 77756-414
Fax:        +49 6196 77756-100

USt-ID-No.: DE 197947163
Managing Directors: Thomas Golob, Alexander Wiegand,
Hans Pieter Gieszen, Martin Robert Stockman

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 260 bytes
Desc: OpenPGP digital signature
Url :

More information about the Kerberos mailing list