How to use Kerberos, Active Directory, or other Identity Management system for authentication in the CUPS Web Interface

Solution Verified - Updated -

Issue

  • We migrated our CUPS server (Red Hat 6.10) from DSEE LDAP to Red Hat IDM and it broke authentication for users on the CUPS web page. They CAN log into the server via SSH, but they are not able to get into the cups web gui menus.
  • We would like to be able to use our Active Directory or Kerberos accounts to authenticate to the CUPS Web UI.
  • Is there a way to tie our IDM accounts into CUPS natively? Right now it uses local account by default.
  • We added an Active Directory group to required_membership in pam_winbind.conf, and confirmed users in that group can ssh to the host. Using those credentials when accessing via a browser (https://test:631/admin) doesn't allow users in that group to log in.

Environment

  • Red Hat Enterprise Linux (RHEL), 6, 7, and 8
  • Common Unix Printing System (CUPS)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content