Re: LDAP bind() versus Kerberos authentication (performance perspective)



"Nagendra G S" <nagendra.gs@xxxxxxxxx> writes:

Anyone have any information about the relative merits ( w.r.t performance )
of using Kerberos authentication instead of LDAP bind() for authentication
in a large environment ? (around 30 authns per second)

You'll have a hard time finding a server slow enough to have difficulty
doing that authentication load using Kerberos. Kerberos is significantly
more efficient for authentication than LDAP binds.

--
Russ Allbery (rra@xxxxxxxxxxxx) <http://www.eyrie.org/~eagle/>
.



Relevant Pages

  • Re: LDAP bind allowing old password for 1 hour
    ... My suggestion regarding Kerberos actually does apply to LDAP binds. ... you use Secure authentication in ADSI, it will use the Windows Negotiate ... If server information is specified for the domain controller when doing ... the LDAP bind, you must use a NetBIOS or DNS name for the domain controller ...
    (microsoft.public.windows.server.active_directory)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... until a user logon event. ... the Netdiag utility will show the Kerberos error in this scenario ... On these machines I ... me a plausible starting point to solve my Kerberos authentication problem. ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... I just wanted to let you know there is a known bug in netdiag that reports ... >> mean that kerberos authentication is not being used. ... Three machines are workstations and three are ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... I installed the Resource Kit. ... > mean that kerberos authentication is not being used. ... Three machines are workstations and three are ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... Kerberos result when I hardwired a laptop to a switch port. ... to authenticate with K on reboot AND authentication appears to take place ... > denied access until you can authenticate to a domain controller as a user. ... > You should have logging of account logon events enabled in Domain Controller ...
    (microsoft.public.windows.server.security)