Re: Customizing Security

From: Bodo Eggert (7eggert_at_fsmtpd.7eggert.dyndns.org)
Date: 07/03/04

  • Next message: nospam55: "secure /etc/fstab"
    Date: Sat, 03 Jul 2004 02:50:55 +0200
    
    

    Tom Jordan <tjordan36@hotmail.com> wrote:

    > I was wondering if its possible to have users in a domain to
    > authenticate against an external datastore - ie. not active directory.

    Kerberos is supposed to do that.

    > The client has a centralized security system that they would like all
          ^
    I suppose as in 'customer', not as in 'the PC being controlled by the one
    to be authenticated'.

    > systems and servers to use.

    > Also, are there any potential disadvantages to do this?

    Single point of failure.

    -- 
    Anyone can speak Troll. All you have to do is point and grunt.
            -- Fred Weasley
    Friß, Spammer: Brandon2@ezwayhomeloan.com nWDgkuM@loveroads.com
    

  • Next message: nospam55: "secure /etc/fstab"

    Relevant Pages

    • Re: Active Directory bind to 3rd party LDAP for authentication
      ... Since LDAP is not an authentication protocol, it would be helpful to know ... If you can use Kerberos, ... It might be possible to get AD to authenticate ... >> I have a standalone Active Directory in a test domain. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Windows GSSAPI ssh connection via cross-realm authentication problems
      ... I think you misunderstand the role of Kerberos here. ... If the SSH service is in realm ... The non-Windows KDC needs to trust any user ... kdcadmin user's home directory and that one can authenticate just fine. ...
      (comp.protocols.kerberos)
    • Re: Kerberos machine authentication - apparent authentication fail
      ... >From what I can tell the kerberos failure shown in netdiag does not always ... mean that kerberos authentication is not being used. ... computer for logon events and the domain controller for account logon events ... > authenticate with K after initial failures. ...
      (microsoft.public.windows.server.security)
    • Re: How to setup authentication across domains within a forest?
      ... forest, regardless of their location. ... DCs for the domain ... Windows 2003 Server Deployment Guide (Active Directory ... >> authentication db and users authenticate to the ...
      (microsoft.public.windows.server.active_directory)
    • OpenSSH, Kerberos, GSSAPI, and windows clients
      ... My FreeBSD is happy authenticate from itself to itself via its own KDC. ... backport of Simon Wilkinson's gssapi patch. ... downloaded WinSCP 375 beta which claims to have SSH2/MIT Kerberos V ...
      (SSH)