Re: AD, pam and Kerberos?



For the multi-realm setup with the Active Directory only you can look at
the samba winbindd.
It do the same thing as nss_ldap/pam_krb5 and also can be easily
configured on "DOMAIN+Username" user names.

regards,
Konstantin.

JK (Jesper Agerbo Krogh) wrote:
Hi All.

We have a setup with several Active Directory domains that individually
trusts
each other. Each domain translates into each own Kerberos REALM as far
as I'm understanding the systems.

But prinicipals are unique across the realms. Thus if jk@realm1 exixts,
then
It doesn't exist in the other realms.

I'd like to use kerberos for the password lookup in the Linux system
using pam. This
Works fine with one "realm" but since the system only looks up users in
the "default realm" I cannot validate users from the other realms.

(This is pam for login on Linux Server/Workstations)

Is it possible to get a "multi"-realm setup like this to work? Any
pointers?

It would be nice to be able to specify a map to the kerberos client:

Jk = jk@realm1
Test = test@realm2

Or something like that.

Jesper

________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos


________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos

.



Relevant Pages

  • Re: Windows 2008 Trust To MIT Kerberos Server
    ... Windows then obtains a service ticket from the MIT realm with the forwarded and forwardable flags set ... With that TGT from the MIT realm, Windows is now able to obtain an LDAP service ticket from Active Directory ... I'm not a Kerberos expert like some, but I'm fairly sure this is a pretty accurate representation of how this process works. ... I have setup a trust between an Active Directory Domain and a MIT Kerberos Domain. ...
    (microsoft.public.windows.server.active_directory)
  • active directory auth against MIT via AD-LDAP
    ... one can set up Active Directory to authenticate against a MIT kerberos ... altsecurityidentities field - then one sees the MIT Kerb realm in the Active ... trust when I am connecting to the active directory ldap interface? ...
    (comp.protocols.kerberos)
  • active directory auth against MIT via AD-LDAP
    ... one can set up Active Directory to authenticate against a MIT kerberos ... altsecurityidentities field - then one sees the MIT Kerb realm in the Active ... trust when I am connecting to the active directory ldap interface? ...
    (comp.protocols.kerberos)
  • RE: Server not found in Kerberos database error on ldapsearch
    ... Realm: EXAMPLE.COM ... So what kind of setup do you think is good for such tests? ... I should setup a VPN-gate that is able to authenticate ... on Kerberos, authorization on LDAP-groups. ...
    (comp.protocols.kerberos)
  • AD, pam and Kerberos?
    ... We have a setup with several Active Directory domains that individually ... Each domain translates into each own Kerberos REALM as far ... I'd like to use kerberos for the password lookup in the Linux system ...
    (comp.protocols.kerberos)