[22790] in Kerberos
Re: LDAP gateway for Kerberos
daemon@ATHENA.MIT.EDU (Phil Dibowitz)
Sat Oct 30 00:32:11 2004
Date: Fri, 29 Oct 2004 21:30:41 -0700
From: Phil Dibowitz <phil@usc.edu>
To: kerberos@mit.edu
Message-ID: <20041030043041.GW22591@usc.edu>
Mail-Followup-To: kerberos@mit.edu
Mime-Version: 1.0
In-Reply-To: <1099109313.846383@yasure>
Content-Type: multipart/mixed; boundary="===============44978401911140442=="
Errors-To: kerberos-bounces@mit.edu
--===============44978401911140442==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="mhK8vdN8+8nwZZLt"
Content-Disposition: inline
--mhK8vdN8+8nwZZLt
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Sat, Oct 30, 2004 at 04:08:35AM +0000, Donn Cave wrote:
> Quoth halford2069@hotmail.com (talisman):
> | is there such a thing as a ldap gateway for kerberos i.e.
> |
> | the ldap gateway piece of software accepts ldap searches and returns
> | basic user info from kerberos, and accepts a bind and passes that
> | through to kerberos and returns success/failure back to the ldap
> | client?
>=20
> You can find an LDAP implementation that supports Kerberos
> authentication at http://www.openldap.org/ (plus Cyrus SASL),
> and I imagine there are others. Such an implementation would
> allow a client to use Kerberos credentials to authenticate
> during bind.
>=20
> The part about basic user info from Kerberos is not so obvious,
> inasmuch as, in general, there isn't any useful user info there.
> Some, maybe most, environments that use Kerberos also have a user
> database with all kinds of information, but if that's what you
> want, you'll have to ask about that (hypothetical) database.
Note that Notre Dame university (I think) wrote a plugin to grab password f=
rom
kerberos (or rather do authentication through kerberos) so that the Sun One
Messaging Server (or whatever its called these days) could run without the
passwords in LDAP.
I don't know if that helps you or not.
--=20
Phil Dibowitz
Systems Architect and Administrator
Enterprise Infrastructure / ISD / USC
UCC 174 - 213-821-5427
--mhK8vdN8+8nwZZLt
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQFBgxjx7lkZ1Iyv898RAv6nAKDY4nONvu3zMoPW9bS+ZGhCG56UXgCfVdPF
4PLdRjtwSHNpuNP5K8oqWBU=
=mka9
-----END PGP SIGNATURE-----
--mhK8vdN8+8nwZZLt--
--===============44978401911140442==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
--===============44978401911140442==--