Firewall Wizards mailing list archives

LDAP and Kerberos?


From: Christopher Hicks <chicks () chicks net>
Date: Fri, 17 Sep 2004 19:18:06 -0400 (EDT)

We've been having a discussion here recently about priorities for deploying LDAP authentication across a few Linux boxen and associated web applications spread from coast to coast. One of the folks involved is a fan of Kerberos and feels that in addition to the already-agreed-upon LDAP over SSL that we should have Kerberos handle the authentication to give single sign-on capabilities. This sounds nice in theory, but I'm wary to slow down moving to LDAP authentication. The web apps don't support Kerberos so we know we're going to authenticate those across LDAP.

Does anyone have any experiences with doing LDAP and Kerberos together?

Can anyone make a better case for why going with Kerberos is worth the trouble?

--
</chris>

There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies.
 -- C.A.R. Hoare

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: