[22790] in Kerberos

home help back first fref pref prev next nref lref last post

Re: LDAP gateway for Kerberos

daemon@ATHENA.MIT.EDU (Phil Dibowitz)
Sat Oct 30 00:32:11 2004

Date: Fri, 29 Oct 2004 21:30:41 -0700
From: Phil Dibowitz <phil@usc.edu>
To: kerberos@mit.edu
Message-ID: <20041030043041.GW22591@usc.edu>
Mail-Followup-To: kerberos@mit.edu
Mime-Version: 1.0
In-Reply-To: <1099109313.846383@yasure>
Content-Type: multipart/mixed; boundary="===============44978401911140442=="
Errors-To: kerberos-bounces@mit.edu


--===============44978401911140442==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="mhK8vdN8+8nwZZLt"
Content-Disposition: inline


--mhK8vdN8+8nwZZLt
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Oct 30, 2004 at 04:08:35AM +0000, Donn Cave wrote:
> Quoth halford2069@hotmail.com (talisman):
> | is there such a thing as a ldap gateway for kerberos i.e.
> |
> | the ldap gateway piece of software accepts ldap searches and returns
> | basic user info from kerberos, and accepts a bind and passes that
> | through to kerberos and returns success/failure back to the ldap
> | client?
>=20
> You can find an LDAP implementation that supports Kerberos
> authentication at http://www.openldap.org/ (plus Cyrus SASL),
> and I imagine there are others.  Such an implementation would
> allow a client to use Kerberos credentials to authenticate
> during bind.
>=20
> The part about basic user info from Kerberos is not so obvious,
> inasmuch as, in general, there isn't any useful user info there.
> Some, maybe most, environments that use Kerberos also have a user
> database with all kinds of information, but if that's what you
> want, you'll have to ask about that (hypothetical) database.

Note that Notre Dame university (I think) wrote a plugin to grab password f=
rom
kerberos (or rather do authentication through kerberos) so that the Sun One
Messaging Server (or whatever its called these days) could run without the
passwords in LDAP.

I don't know if that helps you or not.

--=20
Phil Dibowitz
Systems Architect and Administrator
Enterprise Infrastructure / ISD / USC
UCC 174 - 213-821-5427


--mhK8vdN8+8nwZZLt
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFBgxjx7lkZ1Iyv898RAv6nAKDY4nONvu3zMoPW9bS+ZGhCG56UXgCfVdPF
4PLdRjtwSHNpuNP5K8oqWBU=
=mka9
-----END PGP SIGNATURE-----

--mhK8vdN8+8nwZZLt--

--===============44978401911140442==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============44978401911140442==--

home help back first fref pref prev next nref lref last post