[27603] in Kerberos
service principal management with Active Directory KDC
daemon@ATHENA.MIT.EDU (Rohit Kumar Mehta)
Tue Apr 3 10:18:07 2007
Message-ID: <46126205.5070509@engr.uconn.edu>
Date: Tue, 03 Apr 2007 10:17:41 -0400
From: Rohit Kumar Mehta <rohitm@engr.uconn.edu>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Hi we want to use our Active Directory KDC to manage service principals
for nfs and ssh for quite a few Linux and Solaris machines, and would
prefer to automate generating the service principals and installing them
on the clients. I was thinking that one way to approach this problem
could be by installing Cygwin SSH daemon on the Active Directory server.
Are there any downsides to this?
The other way I think is to set up a cross-realm trust with an MIT KDC
and have one MIT kerberos realm for service principals, and use the
Active Directory for authenticating our user accounts. I haven't tried
doing this yet, but imagine it's not too hard.
If anyone has any thoughts or ideas about this, I'd be happy to hear
them. Thanks!
Rohit
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos