[22703] in Kerberos

home help back first fref pref prev next nref lref last post

Samba 3 + Kerberized LDAP

daemon@ATHENA.MIT.EDU (Matt Joyce)
Wed Oct 20 16:08:46 2004

Message-ID: <4176C550.4070400@vtsystems.com>
Date: Wed, 20 Oct 2004 16:06:40 -0400
From: Matt Joyce <syslists@vtsystems.com>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Reply-To: syslists@vtsystems.com
Errors-To: kerberos-bounces@mit.edu

I really dunno where this question should be directed,  I've tried the 
LDAP and Samba mailing lists to no avail...

I want to get samba 3 to authenticate via ldap... but ldap is kerberized.

we have a few ideas...

1.  Keep a Samba Only Password / User account field in ldap... and use 
that to grab the kerberos ticket and store it in ldap and wherever else 
we need it.


2.  Give out keys to machines via dns... so that authentication via 
gssapi / ldap is done that way.


3.   Hope samba 3 has functionality to handle kerberos ticket grabbing 
so it can authenticate to ldap via gssapi for each person.

I am wondering which method is nearest to the mark.... 

Ideas?  thoughts?  lamentations?

-Matt
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post