Re: Kerberos OpenLDAP Frontend





Jonathan Javier Cordoba Gonzalez wrote:
Ok Douglas....

It means that we need to have two databases??

I think they could be the same, or at least on the same servers,
but then you are mixing the authentication with the authorization.
But your authentication realm maybe enterprise wide, where as you
authorization domain may be departmental. i.e. home directories,
user names, uids, may be local.

Also keep in mind that only the KDC needs access to its data
where as the authorization data can be read by almost any host.


A KDC with passwords and LDAP
with profile information?

Thanks

Jonathan Córdoba
Certified Ethical Hacker (CEH)
GIAC Certified Forensics Analyst (GCFA)
CompTIA Security+ Certified Professional
Ing. Seguridad Universidad de los Andes
Dirección de Tecnologías de Información (D.T.I.)
Bogotá - Colombia


-----Original Message-----
From: Douglas E. Engert [mailto:deengert@xxxxxxx] Sent: Martes, 25 de Septiembre de 2007 09:40 a.m.
To: Jonathan Javier Cordoba Gonzalez
Subject: Re: Kerberos OpenLDAP Frontend



Jonathan Javier Cordoba Gonzalez wrote:
Hi Douglas,

I actually try to use the LDAP to store the KDC data... I guess that it
means more performance and administrative...

That I have not tried. We are using AD as the KDCs. with OpenLDAP
for the nss-ldap.


Jonathan Córdoba
Certified Ethical Hacker (CEH)
GIAC Certified Forensics Analyst (GCFA)
CompTIA Security+ Certified Professional
Ing. Seguridad Universidad de los Andes
Dirección de Tecnologías de Información (D.T.I.)
Bogotá - Colombia


-----Original Message-----
From: Douglas E. Engert [mailto:deengert@xxxxxxx] Sent: Martes, 25 de Septiembre de 2007 08:56 a.m.
To: Jonathan Javier Cordoba Gonzalez
Cc: kerberos@xxxxxxx
Subject: Re: Kerberos OpenLDAP Frontend



Jonathan Javier Cordoba Gonzalez wrote:
Hi,



I’m confuse about the openldap frontend…



Anybody have a guide, tutorial or a step-by-step procedure in order to
make
the connection, create the initial LDAP DB and how it works??



I don’t understand the sequence when a user wants authenticate…
You may be confusing the LDAP used by the KDC to store it data,
and an LDAP used by something like nss-ldap that stores what
would have been found on /etc/passwd or NIS.
So kinit and pam_krb5 can do the authentication as they always have,
to the KDC, then when kinit or pam_krb5 calls getpwnam this calls
the nss-ldap routines via /etc/nsswitch.conf.





Thanks a lot.



Jonathan Córdoba

Certified Ethical Hacker (CEH)

GIAC Certified Forensics Analyst (GCFA)

CompTIA Security+ Certified Professional

Ing. Seguridad Universidad de los Andes

Dirección de Tecnologías de Información (D.T.I.)

Bogotá - Colombia



________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos




--

Douglas E. Engert <DEEngert@xxxxxxx>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
.



Relevant Pages

  • asp.net vulnerability
    ... From: Windows NTBugtraq Mailing List ... More details on ASP.NET vulnerability ... There has been some confusion with the ASP.NET forms authentication issue ... authorization issue, not an authentication issue. ...
    (microsoft.public.sharepoint.portalserver)
  • Re: application pool custom identity
    ... Kerberos becomes a possibility when the web server is in a Domain, ... The problem happens when the browser/server selects Kerberos authentication, ... LocalSystem credentials will work for Kerberos; custom AppPool Identity ... Authorization. ...
    (microsoft.public.inetserver.iis)
  • Re: ASP.NET Authentication exception case
    ... It doesn't seem to like the authorization tag underneath the location tag ... This section sets the authentication policies of the application. ... <!-- SESSION STATE SETTINGS ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Brackets across includes
    ... I am trying to create a user authentication system, ... separate the authentication code into include files. ... separate concepts and should be implemented as separate procedures. ... Authorization could be ...
    (comp.lang.php)
  • Re: ADAM - SSO and provisioning considerations
    ... ADAM and "custom" security principals and gives you ... for authentication, where you might ship some default providers (ADAM LDAP ... be used to link up to the authorization store. ... > customer's identity store is a non-MS directory, ...
    (microsoft.public.windows.server.active_directory)