[27603] in Kerberos

home help back first fref pref prev next nref lref last post

service principal management with Active Directory KDC

daemon@ATHENA.MIT.EDU (Rohit Kumar Mehta)
Tue Apr 3 10:18:07 2007

Message-ID: <46126205.5070509@engr.uconn.edu>
Date: Tue, 03 Apr 2007 10:17:41 -0400
From: Rohit Kumar Mehta <rohitm@engr.uconn.edu>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu


Hi we want to use our Active Directory KDC to manage service principals 
for nfs and ssh for quite a few Linux and Solaris machines, and would 
prefer to automate generating the service principals and installing them 
on the clients. I was thinking that one way to approach this problem 
could be by installing Cygwin SSH daemon on the Active Directory server.
Are there any downsides to this?

The other way I think is to set up a cross-realm trust with an MIT KDC 
and have one MIT kerberos realm for service principals, and use the 
Active Directory for authenticating our user accounts.  I haven't tried 
doing this yet, but imagine it's not too hard.

If anyone has any thoughts or ideas about this, I'd be happy to hear 
them.  Thanks!

Rohit
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post