1 |
Georges Toth wrote: |
2 |
> Hi, |
3 |
> |
4 |
> Thanks for that description and links. |
5 |
> I guess I will play with SSO sometime soon :-). |
6 |
> |
7 |
> |
8 |
>> I have a system setup using OpenLDAP combined with Cyrus-SASL and Heimdal |
9 |
>> kerberos. I have tied samba into it, and will eventually setup samba-tng |
10 |
>> as an authentication head for samba. With samba, I may use NTLM |
11 |
>> authentication to include more options for SSO. |
12 |
>> |
13 |
>> The way my setup works is samba has access to use LDAP for accounting and |
14 |
>> simple binds (over SSL/TLS). Unfortunately, samba doesn't support kerberos |
15 |
>> based authentication "(yet)". In this setup, the users sign on to their |
16 |
>> desktop, and the same login is used to access network shares without prompt |
17 |
>> for another password (this happens by default on most windows desktops) |
18 |
>> using NTLM. |
19 |
>> |
20 |
>> Various applications using SPEGNO/GSSAPI can provide autologin |
21 |
>> functionality using this same login if we chose to implement something to |
22 |
>> that effect, but that depends entirely on the applications we might use. |
23 |
>> For example, IE and Firefox support SPEGNO/GSSAPI, so enabled web |
24 |
>> applications may use this to authenticate the client without additional |
25 |
>> credentials. Another example may be squid, as it provides NTLM |
26 |
>> authentication mechanisms. |
27 |
>> |
28 |
>> Even if kerberos or NTLM authentication isn't possible I can still |
29 |
>> integrate other services such as pam, Jabber, samba, AND Outlook |
30 |
>> addressbook into LDAP using SSL/TLS and simple binds. This makes my setup |
31 |
>> more of a flexible centralized authentication system, than simply an SSO |
32 |
>> server. In the end, it all comes down to what auth mechanisms the apps |
33 |
>> you're using support in your ability to perform SSO. |
34 |
>> |
35 |
>> I have referenced a lot of these links for my setup. With them, there |
36 |
>> should be enough information to create a setup truly exact to your needs: |
37 |
>> |
38 |
>> Centralized authentication howtos: |
39 |
>> http://www.openinput.com/auth-howto/ |
40 |
>> http://www.bayour.com/LDAPv3-HOWTO.html |
41 |
>> |
42 |
>> Samba (TNG) and authentication: |
43 |
>> http://www.mami.net/univr/tng-ldap/howto/ |
44 |
>> http://www.deschner.de/gd/dual_samba.html |
45 |
>> http://www.mami.net/univr/tng-ldap/howto/sambausermapping.html |
46 |
>> http://www.samba-tng.org/docs/tng-arch/tng-arch.html |
47 |
>> |
48 |
>> Other misc resources: |
49 |
>> http://acctsync.sourceforge.net/ |
50 |
>> http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html |
51 |
>> "Making the big boys play nice..." (one of my favorites) |
52 |
>> http://pgina.xpasystems.com/?page_id=3 |
53 |
>> |
54 |
>> |
55 |
>> In a sense, I have been trying to work toward SSO for a while. There are |
56 |
>> still many things that require a password on our network though. By |
57 |
>> centralizing authentication, I feel that I am one step closer. Anyway, I |
58 |
>> hope this helps. |
59 |
>> |
60 |
>> Regards, |
61 |
>> |
62 |
>> |
63 |
>> Robert Larson |
64 |
>> |
65 |
> |
66 |
> |
67 |
Many thanks for the links a great help. I will be experimenting with a |
68 |
few setups, if I manage something useful i'll let you know. |
69 |
|
70 |
Steve. |
71 |
-- |
72 |
gentoo-server@g.o mailing list |