Re: integrating ldap & krb5 for Apache auth -- which comes first?

This is a discussion on Re: integrating ldap & krb5 for Apache auth -- which comes first? within the Kerberos forums, part of the Protocols category; > (a) use mod_auth_ldap for auth, with ldap pointed at a krb5 keytab > containing authorized principals' credentials, > > or, > > (b) use mod_auth_krb5 for auth, with ldap ...

Go Back   Unix Linux Forum > Technologies & Tools > Protocols > Kerberos

FixUnix.com - Unix Linux Forums

Unix Content Register FAQ Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-22-2008, 03:34 AM
Default Re: integrating ldap & krb5 for Apache auth -- which comes first?

> (a) use mod_auth_ldap for auth, with ldap pointed at a krb5 keytab
> containing authorized principals' credentials,
>
> or,
>
> (b) use mod_auth_krb5 for auth, with ldap setup as krb5's backend db, e.g.,
> dbmodule:db_library = kldap


auth_ldap does not give you credential but password authentication,
and does not require a keytab.

auth_krb5 allows you password and credential (GSSAPI) auth. password
auth does not strictly require a keytab (you need do disable kdcverify
option or a similar one). GSSAPI auth is probably what you want, as
gives secure auth without SSL, and allows real single sign on. But you
need to configure the browsers. For IE, you must add the site to
"Intranet sites" (or something alike), and with firefox you need to go
through the about:config, searching for negotiate.

Hope this helps,

JaviP

P.S.: You don't strictly require ldap for this setup. Is at your
option to backend kerberos on LDAP, but if your next step is to use
ldap group membership for authorization, I didn't try that
Reply With Quote
Reply

Thread Tools


All times are GMT -5. The time now is 06:00 PM.

In an effort to better serve ads to our visitors, cookies are used on Fixunix.com. For more information, check out our Privacy Policy.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Ad Management by RedTyger