[24987] in Kerberos

home help back first fref pref prev next nref lref last post

Re: that interop mess: ldap, samba, kerberos

daemon@ATHENA.MIT.EDU (Turbo Fredriksson)
Tue Nov 22 11:36:26 2005

To: kerberos@mit.edu
From: Turbo Fredriksson <turbo@bayour.com>
Date: Tue, 22 Nov 2005 17:30:54 +0100
In-Reply-To: <Pine.GSO.4.64.0511221049290.22586@hinault.bath.ac.uk> (Dennis
 Davis's message of "Tue, 22 Nov 2005 11:01:40 +0000 (GMT)")
Message-ID: <87wtj0d4qp.fsf@pumba.bayour.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Errors-To: kerberos-bounces@mit.edu

Quoting Dennis Davis <D.H.Davis@bath.ac.uk>:

> On Tue, 22 Nov 2005, Sam Hartman wrote:
>
>> From: Sam Hartman <hartmans@mit.edu>
>> To: Turbo Fredriksson <turbo@bayour.com>
>> Cc: kerberos@mit.edu
>> Date: Tue, 22 Nov 2005 05:38:58 -0500
>> Subject: Re: that interop mess: ldap, samba, kerberos
>> 
>> >>>>> "Turbo" == Turbo Fredriksson <turbo@bayour.com> writes:
>> 
>>     Turbo> Eh... What? From what I know, slapd don't have any means of
>>     Turbo> specifying a keytab so even if you create one, slapd won't
>>     Turbo> use it...
>> 
>> Well, slapd may be buggy.  I'd like to think that saslauthd isn't
>> buggy in this way.
>> Cmu folks?
>
> saslauthd certainly isn't buggy in this way.  The Zanarotti, or
> screensaver, attack is avoided.  We make extensive use of saslauthd
> here and the KerberosV logs clearly show a ticket-granting ticket
> (krbtgt/BATH.AC.UK@BATH.AC.UK) being acquired and then used to
> acquire host/{hostname}@BATH.AC.UK credentials.  The saslauthd code
> caters for both the Heimdal and MIT Kerberos libraries.

That's not a keytab, that's a (service) principal, right!?
Two different but related things... ?

A '{host,ldap}/<FQDN>@<REALM>' (service) principal IS created and
explained in my book, so are we talking about the same thing, but
using different 'language'?

Am I missing something obvious here?

> But I suspect that it may well be using saslauthd.

If you're using {SASL}, then yes - you're using saslauthd. The old
(now unsupported/depricated) way of doing things was using {KERBEROS}.
And that used some internal magic that I'm not sure/don't remember
how exactly it worked.

>From what I know, the only way to tie OpenLDAP to kerberos is by
using '{SASL}<principal>@<REALM>' in the userPassword attribute...
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post