Pkinit support

Does MacOSX 10.6 support pkinit? If so what configuration needs to be done?

Mac OS X (10.6)

Posted on Oct 27, 2009 5:02 AM

Reply
4 replies

Dec 22, 2009 5:53 AM in response to K T

The Thursby solution is addon software. It is under my impression the MacOS specifically Snow Leopard had this builtin. But from my experience Apple claims that Kerberos is also builtin. However you don't get SSO (single-signon) in packages like Safari, screen lock, and AFP unless you use Mac's OpenDirectory and Kerberos or their competitors similiar product ActiveDirectory. My guess is unlike Linux, Mac went down the Microsoft path with SSO, and the only way for it to work is with their infrastructure. Too bad, Kerberos infrastructures have been around a long time, and some groups have been using it for years for SSO with enhancements for One Time Passcodes AND smartcards.

Thanks for your help.

Dec 22, 2009 6:30 AM in response to upsidedownmachin

Mac OS X apparently does support pkinit - it's used in the "Back to My Mac" feature, for instance - though from what I've read Apple wrote their own implementation and do not support the plugin architecture. I've not been able to find much on Apple's pkinit implementation, but perhaps this free on-line seminar from Apple would be of help:

http://seminars.apple.com/seminarsonline/sso/apple/index.html?s=301

Dec 22, 2009 7:53 AM in response to varjak paw

Actually I did watch the video and from that video confirmed that PKINIT was supported. However the video also talked about Kerberos and how Macs implementation uses Local KDCs (LKDC) and Macs OpenDirectory, which appears to provide an Enterprise realm like Kerberos service like Active Directory. He never did talk about cross realm trust between the LKDCs and how one would set that up.

My guess is Macs PKINIT requires Macs OpenDirectory for KDC certificates and user certificates. Its a shame that Apple keeps the details of their deployment of PKINIT a secret. At least Microsoft published its early deployment through an infromational RFC.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Pkinit support

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.