[38911] in Kerberos
Re: Integration of Duo with MIT Kerberos?
daemon@ATHENA.MIT.EDU (hedrick@rutgers.edu)
Thu Apr 29 09:39:27 2021
From: hedrick@rutgers.edu
In-Reply-To: <CAEamvFBfFkbFcXDdgLOgJM5hjfoYtwQNG=uDHHs0RDU_fDUfng@mail.gmail.com>
Date: Thu, 29 Apr 2021 09:37:00 -0400
Message-ID: <504DEF47-C53A-412B-B5AA-053DBBEBB0A5@rutgers.edu>
To: Ben Poliakoff <benp@reed.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Rutgers uses DUO. I did a test integration using the IPA Radius support, which I believe is also in MIT Kerberos. Point it at a Radius server that supports DUO.
> On Apr 26, 2021, at 2:36 PM, Ben Poliakoff <benp@reed.edu> wrote:
>
> I see this question came up 6 years ago on this list:
>
> https://kerberos.mit.narkive.com/uFhWlsZR/information-request-duo-integration-for-kinit
>
> On that thread there was some talk about MIT's implementation, possible
> eventual open sourcing of said implementation and/or creating a
> newer/cleaner implementation using SPAKE-2.
>
> Did anything ever come if this? We'd certainly love to be able to
> selectively integrate second factors such as Duo with our MIT krb5 KDCs.
>
> Ben
>
> --
> Ben Poliakoff
> Associate Director
> Technology Infrastructure Services
> Reed College
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos