You can configure Firefox to use Kerberos for Single Sign-on. The following instructions will guide you in configuring your web browser
to send your Kerberos credentials to the appropriate Key Distribution Center which enables Single Sign-on.
1. In the address bar of Firefox, type about:config to display the list of current configuration options.
2. In the Filter field, type negotiate to restrict the list of options.
3. Double-click the network.negotiate-auth.trusted-uris entry to display the Enter string value dialog box.
4. Enter the name of the domain against which you want to authenticate, for example, .example.com.
You are all set.
Automatic Configuration of older versions
You can configure older versions of Firefox (up to version 14) using signed code. Use Firefox configuration page for newer versions.
1. Import CA certificate. Make sure you checked all three checkboxes.
2. Click on "Configure Browser" button below.
Chrome
You can configure Chrome to use Kerberos for Single Sign-on. The following instructions will guide you in configuring your web browser to send your Kerberos credentials to the appropriate Key Distribution Center which enables Single Sign-on.
Import CA Certificate
Download the CA certificate. Alternatively, if the host is also an IdM client, you can find the certificate in /etc/ipa/ca.crt.
Click the menu button with the Customize and control Google Chrome tooltip, which is by default in the top right-hand corner of Chrome, and click Settings.
Click Show advanced settings to display more options, and then click the Manage certificates button located under the HTTPS/SSL heading.
In the Authorities tab, click the Import button at the bottom.
Select the CA certificate file that you downloaded in the first step.
Enable SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) to Use Kerberos Authentication
in Chrome
Make sure you have the necessary directory created by running:
Create a new /etc/opt/chrome/policies/managed/mydomain.json file with write privileges limited to the system administrator or root, and include the following line: