[29394] in Kerberos

home help back first fref pref prev next nref lref last post

Re: OpenLDAP to Kerberos, Take 2

daemon@ATHENA.MIT.EDU (Wes Modes)
Fri Feb 29 17:57:01 2008

Message-ID: <47C88A19.8070003@ucsc.edu>
Date: Fri, 29 Feb 2008 14:41:29 -0800
From: Wes Modes <wmodes@ucsc.edu>
MIME-Version: 1.0
To: Russ Allbery <rra@stanford.edu>
In-Reply-To: <87pruflbr1.fsf@windlord.stanford.edu>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu


>> But on an OpenLDAP list I got:
>>
>>     There is an ugly hack: having a userPassword field with
>>     "{SASL}<Kerberos principal>" in LDAP you can employ saslauthd's
>>     Kerberos backend. We use it as a crutch for a web application which
>>     can only authenticate against an LDAP directory
>>     
>
> And what that does is exactly what's described above: it causes slapd to
> take the username and password and do a kinit and ticket verification.
> (What it actually does is hand the username and password off to saslauthd,
> which then does that, but for your purposes it amounts to the same thing.)
>   
Where does one get more info on this ugly hack? 

What you described is precisely what I was hoping for.  However, I hoped 
it would be commonplace and elegant.  But ugly hacks have their place.

W.

-- 

Wes Modes
Server Administrator & Programmer Analyst
McHenry Library
Computing & Network Services
Information and Technology Services
459-5208
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post