# FYI deb11 users with apache2 + sso

**URL:** https://community.zammad.org/t/fyi-deb11-users-with-apache2-sso/8647
**Category:** Lobby
**Created:** [February 9, 2022, 9:56am UTC](https://community.zammad.org/t/fyi-deb11-users-with-apache2-sso/8647 "2022-02-09T09:56:00Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![dvnkln](https://community.zammad.org/user_avatar/community.zammad.org/dvnkln/32/2736_2.png) [@dvnkln](https://community.zammad.org/u/dvnkln)
#### Post date: [February 9, 2022, 9:56am UTC](https://community.zammad.org/t/fyi-deb11-users-with-apache2-sso/8647/1 "2022-02-09T09:56:00Z")

</div>

Hey there,

for anyone running `bullseye` who needed to backport the `libapache2-mod-auth-kerb` package from `sid`:  
I moved to `libapache2-mod-auth-gssapi` with (currently) no problems.

Since it doesn’t seem like they’re still putting a lot of work into that package ([libapache-mod-auth-kerb - Debian Package Tracker](https://tracker.debian.org/pkg/libapache-mod-auth-kerb)) this could be a “more secure” sso approach for now.

The process is pretty simple and can be done in even under 1 minute. You can try it on your own if you’d like to but keep in mind that this is probably in no way supported by zammad itself (and most of all not by me 🙂 ). If stuff goes downtown - you’re on your own.

> **Danger Zone**
>
> > **The following will only work if you're already running SSO via mod-auth-kerb**
> >
> > > **As already said: I'm sharing this As-Is. I simply can't provide any troubleshooting if needed**
> > >
> > > 1. Install the GSSAPI package: `apt install libapache2-mod-auth-gssapi`
> > > 
> > > 2. Edit the `<LocationMatch "/auth/sso">` part in your apache2 conf to look like this:
> > > 
> > > ```auto
> > > <LocationMatch "/auth/sso">
> > > SSLRequireSSL
> > > AuthType GSSAPI
> > > AuthName "Your Zammad"
> > > GssapiBasicAuth On
> > > GssapiCredStore keytab:/etc/zammad.keytab # wherever it is located on your end
> > > GssapiLocalName On
> > > require valid-user
> > >   
> > > RewriteEngine On
> > > RewriteCond %{LA-U:REMOTE_USER} (.+)
> > > RewriteRule . - [E=RU:%1,NS]
> > > RequestHeader set X-Forwarded-User "%{RU}e" env=RU
> > > </LocationMatch>
> > > 
> > > ```
> > > 
> > > 1. Restart the apache2 service: `systemctl restart apache2.service`
> > > 
> > > Now you should be done. You’re free to remove the old `libapache2-mod-auth-kerb` package now.

cheers

---

<div class="post-metadata">

### Author: ![Samb](https://community.zammad.org/user_avatar/community.zammad.org/samb/32/5300_2.png) [@Samb](https://community.zammad.org/u/Samb)
#### Post date: [February 9, 2022, 2:25pm UTC](https://community.zammad.org/t/fyi-deb11-users-with-apache2-sso/8647/2 "2022-02-09T14:25:58Z")

</div>

Yes, that’s the best route. I threw quite some time onto this topic and can confirm. Either you have to backport the deprecated package or use gssapi instead.

---

<div class="post-metadata">

### Author: ![system](https://community.zammad.org/uploads/default/original/1X/5c5afaea2d23f811dbec33cd4edb02fa29d3262f.png) [@system](https://community.zammad.org/u/system)
#### Post date: [March 23, 2022, 6:26am UTC](https://community.zammad.org/t/fyi-deb11-users-with-apache2-sso/8647/3 "2022-03-23T06:26:29Z")

</div>

This topic was automatically closed 41 days after the last reply. New replies are no longer allowed.
