[24978] in Kerberos

home help back first fref pref prev next nref lref last post

Re: that interop mess: ldap, samba, kerberos

daemon@ATHENA.MIT.EDU (Turbo Fredriksson)
Mon Nov 21 02:26:01 2005

To: kerberos@mit.edu
From: Turbo Fredriksson <turbo@bayour.com>
Date: Mon, 21 Nov 2005 08:20:34 +0100
In-Reply-To: <1132428065.762368.257530@g43g2000cwa.googlegroups.com>
	(rektide@gmail.com's message of "19 Nov 2005 11:21:05 -0800")
Message-ID: <87d5kupiv1.fsf@pumba.bayour.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Errors-To: kerberos-bounces@mit.edu

Quoting "rektide" <rektide@gmail.com>:

> Is it still mainly all about having {KERBEROS}name@REALM.COM in
> userPassword?

Nowadays it's {SASL}, not {KERBEROS}.

> I noticed Turbo's guide never gives LDAP a keytab entry.  His setup
> didnt require LDAP to do any writing to kerberos, so it was
> unnecessary.  Is this still the case?

Since I've separated AUTHENTICATION and AUTHORIZATION, there's no need
for an LDAP/slapd keytab...

Passwords is in Kerberos (AUTHENTICATION) and information is in LDAP
(AUTHORIZATION). I didn't want to put the passwords in the LDAP backend,
because that would create a circular dependency which I didn't want (I
have to many of those anyway :).

> Of note, I do plan on running the KX509 / KCA setup off this at some
> point in the not too distant future.  I'm running Heimdal and OpenLDAP
> 2.3.

Only Heimdal can have it's password database in LDAP. I'm still running
MIT Kerberos V and have no intention to change. The MIT version works
fine for me.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post